1.5
低危

06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81

06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe

分析耗时

135s

最近分析

381天前

文件大小

117.2KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN BACKDOOR WABOT
鹰眼引擎
DACN 0.15
FACILE 1.00
IMCLNet 0.76
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Baidu Win32.Backdoor.Wabot.a 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200328 2013.8.14.323
McAfee W32/Wabot 20200326 6.0.6.653
Tencent Trojan.Win32.Wabot.a 20200328 1.0.0.1
行为判定
动态指标
在文件系统上创建可执行文件 (18 个事件)
file C:\Windows\System32\DC++ Share\wmpenc.exe
file C:\Windows\System32\DC++ Share\ieinstal.exe
file C:\Windows\System32\xdccPrograms\install.exe
file C:\Windows\System32\DC++ Share\iexplore.exe
file C:\Windows\System32\DC++ Share\setup_wm.exe.exe
file C:\Windows\System32\xdccPrograms\ConvertInkStore.exe
file C:\Windows\System32\DC++ Share\msinfo32.exe
file C:\Windows\System32\xdccPrograms\inject-x64.exe
file C:\Windows\System32\DC++ Share\PDIALOG.exe
file C:\Windows\System32\DC++ Share\wab.exe
file C:\Windows\System32\DC++ Share\wmprph.exe
file C:\Windows\System32\DC++ Share\DVDMaker.exe
file C:\Windows\System32\DC++ Share\wmpconfig.exe
file C:\Windows\System32\DC++ Share\ShapeCollector.exe
file C:\Windows\System32\DC++ Share\wmplayer.exe
file C:\Windows\System32\DC++ Share\wordpad.exe
file C:\Windows\System32\DC++ Share\ielowutil.exe
file C:\Windows\System32\DC++ Share\wabmig.exe
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
在 Windows 启动时自我安装以实现自动运行 (1 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\shell reg_value Explorer.exe sIRC4.exe
文件已被 VirusTotal 上 66 个反病毒引擎识别为恶意 (50 out of 66 个事件)
ALYac Trojan.Agent.DQQD
APEX Malicious
AVG Win32:Delf-VJY [Trj]
Acronis suspicious
Ad-Aware Trojan.Agent.DQQD
AhnLab-V3 Worm/Win32.IRCBot.R3689
Antiy-AVL Trojan[Backdoor]/Win32.Wabot.a
Arcabit Trojan.Agent.DQQD
Avira TR/Dldr.Delphi.Gen
Baidu Win32.Backdoor.Wabot.a
BitDefender Trojan.Agent.DQQD
BitDefenderTheta AI:Packer.9B207B1521
Bkav W32.BackdoorWabot.Trojan
CAT-QuickHeal Trojan.Wabot.A8
CMC Backdoor.Win32.Wabot!O
ClamAV Win.Trojan.Wabot-6113548-0
Comodo Backdoor.Win32.Wabot.A@4knk5y
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.470546
Cylance Unsafe
Cyren W32/Backdoor.PJEB-4161
DrWeb Trojan.MulDrop6.64369
ESET-NOD32 Win32/Delf.NRF
Emsisoft Trojan.Agent.DQQD (B)
Endgame malicious (high confidence)
F-Prot W32/Wabot.A
F-Secure Trojan.TR/Dldr.Delphi.Gen
FireEye Generic.mg.82715bc470546aa3
Fortinet W32/Wabot.A!tr
GData Win32.Backdoor.Wabot.A
Ikarus P2P-Worm.Win32.Delf
Invincea heuristic
Jiangmin Backdoor/Wabot.z
K7AntiVirus Trojan ( 0055c5c91 )
K7GW Trojan ( 0055c5c91 )
Kaspersky Backdoor.Win32.Wabot.a
MAX malware (ai score=85)
Malwarebytes Backdoor.Wabot
MaxSecure Backdoor.W32.Wabot.A
McAfee W32/Wabot
McAfee-GW-Edition BehavesLike.Win32.Wabot.cc
MicroWorld-eScan Trojan.Agent.DQQD
Microsoft Backdoor:Win32/Wabot.A
NANO-Antivirus Trojan.Win32.Wabot.dmukv
Panda Backdoor Program
Qihoo-360 HEUR/QVM05.1.2E61.Malware.Gen
Rising Worm.Chilly!1.661C (RDMK:cmRtazpp41iGF9uQVgv1mmw03stn)
SUPERAntiSpyware Backdoor.Wabot/Variant
Sangfor Malware
SentinelOne DFI - Malicious PE
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:40:53

PE Imphash

5662cfcdfd9da29cb429e7528d5af81e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x0000c984 0x0000ca00 6.572458888267131
DATA 0x0000e000 0x00000a1c 0x00000c00 4.533685500040435
BSS 0x0000f000 0x00001111 0x00000000 0.0
.idata 0x00011000 0x0000083e 0x00000a00 4.169474579751151
.tls 0x00012000 0x00000008 0x00000000 0.0
.rdata 0x00013000 0x00000018 0x00000200 0.2108262677871819
.reloc 0x00014000 0x00000710 0x00000800 6.25716095476406
.rsrc 0x00015000 0x00000abc 0x00000c00 4.795355344371777

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000158e8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x000158e8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x000158e8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_RCDATA 0x00015a20 0x00000078 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x00015a20 0x00000078 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x00015a98 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library kernel32.dll:
0x4110d8 VirtualFree
0x4110dc VirtualAlloc
0x4110e0 LocalFree
0x4110e4 LocalAlloc
0x4110e8 GetCurrentThreadId
0x4110ec GetStartupInfoA
0x4110f0 GetModuleFileNameA
0x4110f4 GetLastError
0x4110f8 GetCommandLineA
0x4110fc FreeLibrary
0x411100 ExitProcess
0x411104 CreateThread
0x411108 WriteFile
0x411110 SetFilePointer
0x411114 SetEndOfFile
0x411118 RtlUnwind
0x41111c ReadFile
0x411120 RaiseException
0x411124 GetStdHandle
0x411128 GetFileSize
0x41112c GetSystemTime
0x411130 GetFileType
0x411134 CreateFileA
0x411138 CloseHandle
Library user32.dll:
0x411140 GetKeyboardType
0x411144 MessageBoxA
0x411148 CharNextA
Library advapi32.dll:
0x411150 RegQueryValueExA
0x411154 RegOpenKeyExA
0x411158 RegCloseKey
Library oleaut32.dll:
0x411160 SysFreeString
Library kernel32.dll:
0x411168 TlsSetValue
0x41116c TlsGetValue
0x411170 LocalAlloc
0x411174 GetModuleHandleA
Library advapi32.dll:
0x41117c RegQueryValueExA
0x411180 RegOpenKeyExA
0x411184 RegCloseKey
Library kernel32.dll:
0x411190 WinExec
0x411194 UpdateResourceA
0x411198 Sleep
0x41119c SetFilePointer
0x4111a0 ReadFile
0x4111a4 GetSystemDirectoryA
0x4111a8 GetLastError
0x4111ac GetFileAttributesA
0x4111b0 FindNextFileA
0x4111b4 FindFirstFileA
0x4111b8 FindClose
0x4111c4 ExitProcess
0x4111c8 EndUpdateResourceA
0x4111cc DeleteFileA
0x4111d0 CreateThread
0x4111d4 CreateMutexA
0x4111d8 CreateFileA
0x4111dc CreateDirectoryA
0x4111e0 CopyFileA
0x4111e4 CloseHandle
Library user32.dll:
0x4111f0 SetTimer
0x4111f4 GetMessageA
0x4111f8 DispatchMessageA
0x4111fc CharUpperBuffA
Library wsock32.dll:
0x411204 WSACleanup
0x411208 WSAStartup
0x41120c gethostbyname
0x411210 socket
0x411214 send
0x411218 select
0x41121c recv
0x411220 ntohs
0x411224 listen
0x411228 inet_ntoa
0x41122c inet_addr
0x411230 htons
0x411234 htonl
0x411238 getsockname
0x41123c connect
0x411240 closesocket
0x411244 bind
0x411248 accept

L!This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
StringX
TObject%8
;u3YZ]_^[
SVWUL$
]_^[SVWUL$
uZ]_^[
YZ]_^[
_^[U3Uh
d2d"h@
d2d"=5@
u3ZYYd
#_^[SVWU
SVW<$L$
uSVWU@
]_^[USVW
d1d!=5@
2E3ZYYd
E_^[YY]
UQSVW3@
3Uh6"@
d1d!=5@
E3ZYYd
E_^[Y]
YZ]_^[
d2d"=5@
}3ZYYd
E_^[Y]
$PRQ$"
_^SVWU
< v;"u
3C<"u1S@
>3Q<"u8S
< w]_^[
Ek<1fU
Ht Ht.g
6Huv=L
VI3E?E3s
3EE_^[Y]
f=r/f=w)f%f=u
f=v)f=w#j
RPCHPt$
-CGL$
SVWPtl11
-tb+t_$t_xtZXtU0u
FxtHXtCt
~ExC[)A
FuY12_^[
PRQYZXt5x
@~d@PQ@
YXYX
uM3UhU3@
EP3ZYYd
f%fUf?f
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
Iu9u_^[
PRQQTj
YZXtpH
S1VWUd
SPRQT$(j
Zd$,1Yd
t=HtN`
r6t0R=
t/=t&,*&"
3UhB:@
USVW$@
d2d";~
P'v_^[]
aSVWt@
^v]_^[
QRZX1Yd
PVSY_^[]
PQiZXSVW
ISVWRP1L
JZ_^[X$
thtkFW)w
9uXJt
8uAJt
t8JIt2S
PHXHI|
St-Xt&J|
t0JN|*9}&~")9~
tVSVWU
t@t1SVW
1Z)_^[
@+u<E@
USVWE(@
d0d ]ES
u_^[YY]
UQE3UhF@
d2d"E@
t3ZYYd
%3ZYYd
U3UhH@
U3UhH@
3U3UhAJ@
P~SD$
U3UhK@
U3UhK@
U3UhL@
TFileNameL@
TSearchRecX
U3UhdM@
EEb3Uh
tC&EPU
U3ZYYd
U3QQQQQEE3UhN@
d0d EM
EPU3EPtKh
EcPh0O@
system.ini
Explorer.exe
UEEEz3Uh.P@
d0d U,
EP3ZYYd
IuQSEE3UhpR@
tjtfhR@
t-u)hR@
u-t)hR@
" -a -r "
" a -idp -inul -c- -m5 "
software\microsoft\windows\currentversion\app paths\winzip32.exe
software\microsoft\windows\currentversion\app paths\WinRAR.exe
C:\rar.bat
C:\zip.bat
PHuES3
E.E&3UhT@
EPEPEP?
a3ZYYd
IuSVWEE3UhX@
d0d UEJ
U3YEU.Ef
EU\EUQE;}>%
EnSEcPd
to3Uh2X@
EP3ZYYd
IuQSVWEE
3Uhh\@
U3UhY@
d0d G3ZYYd
$UFuh\@
VUEL@t}0EUm3E
EZPE~h
=3_^[]
abcdefghijklmnopqrstuvwxyz-_.1234567890
IuQMSVWMUEEEE
+3Uha@
d0d 3Uha@
d0d EU|
u?8.t4uha@
u|U|ttx
yupUkp0hwhlj
uXUXPPT
uLUrL7D~DHq
-u@U@8+8<
u4U4,,0
u(Uy(6 $x
3Uh"d@
d0d 3Uhc@
d0d EE
8.teChTd@
N3ZYYd
_y_^[]
NOTICE
:to get this, type !xdcc_get
bytes)
uTC,PSC
EE>3Uhe@
d0d SU
E3ZYYd
EE3Uhf@
d0d SUf@
PRIVMSG
UdSVW3
dhEE3UhSh@
d0d 8lPh
d2d"EP
s3ZYYd
c3ZYYd
ZE.H_^[]
BFKu_^[
USEE"3Uhh@
d0d UE3ZYYd
U3QQQQQQQQS3Uh
| v;}
N|7 vU+A
M3Uhj@
U3ZYYd
EE3UhPk@
EPE!PS63ZYYd
E1K[Y]
3UhYl@
\DC++ Share
\xdccPrograms
EE33Uh?m@
d0d EUFUTm@
a~&EPUTm@
EZSUTm@
U3ZYYd
f\[YY]
EE3Uhm@
d0d EEPEePt,P3
EU3ZYYd
U3UhQn@
TWarBotUj
SV3Uho@
EPSE/Eo@
03ZYYd
IuQSVWd3Uhs@
`U\E\U\
EPSEPcfC
PfEEU:E
X/XUX8
3EU,t@
~&EPU,t@
EZU,t@
\uh8t@
L3LP P
PcPhlt@
EIHhlt@
DE0Dhxt@
\E>EPj
EPtPEP
SfPV j
EPzVt3ZYYd
PRIVMSG #hellothere :
&%->=
PRIVMSG
DCC SEND
IuMSVU
EN3Uhy@
d0d EUaE
EEPUy@
;~iEPUy@
EEU8EPU
EZWEPU
EZ1EPU
EEPUy@
EZEUUy@
:3ZYYd
PING :
type !list for my list
!list
 for my list
!xdcc_get
#helloThere
#helloThere,
JOIN #HelloThere
LIST >4,<10000
U3QQQQSE
3Uh,|@
YUuhp|@
?Uuh||@
G3ZYYd
PRIVMSG
ACTION
!list
 for my list
SVWE3Uh@
E3ZYYd
NICK [xdcc]
NICK [mp3]
NICK [rar]
NICK [zip]
NICK [share]
NfrSF3
Pzu _^[
31ff%3vcc%%112c23J33c22322332crc3cr233J2fJffJv%1[J33JccJccfcc2fc2JfJ223rrcrrJ2cc3f2r3r233Jcf2rf3ffJfrJrr3f2]fr[2rvJ23%1JJJc1fc22%J[rr]ff2rr2%ff32f2J23r323223J2rc333cc2fJJ3JJ2ccrfrJr2r3JJrcfc322f3cr3rcJ33f33rcrrrcf3cfrffJ2cff2r22fJJf3rr33rJ2f3cJJc33r3crrcf33cJJrffr2fJ2f22fc3ffrrJ32cJf
]2]3r]31111rfr2crcJ3[%%]]vJf3233Jr22fJrvvv[v[Jc3Jc3rcccrfJ3ccfffJ3c32Jfrc2ffr3cJ222JcfrJrJ322r2ff3Jr2JJcffcc3vJ]c2[2%Jv%2]rf2J213]3[v2]33[2[J32c2r33rrf2c2cff23rJJf22cf3crJc2fJJrcc33c2fccJ332rJJcrrffJr2ffrcJ3frJc23frcr22c2rcJc2cJcff2c3cfrJrf2rfr2c232cff3332fJ2r2c2cfJ23f3J3f333J22r2f33
J]"^^"^^^^^""""""""""""""""""""""""""""""""""""""""^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^"=~\=yw$="^^"^^^"jCzyw6=^"^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^=
ff^ ."k^"=!24G;. .. .!nzL4OJ"~~.. . .=
]J^ . .!sG!7{^!s8G=.. .^68Vs2!;.;*}.. =
f1" ............. ._Inzoz6$295. ..^lkcv".."";"L. .=
1c^ . ,!%6***O8Izy. .!j_". .;w=;]. . =
ff^ . . . . . . . . . . .. .. . ... . . .. . .. .^|uuzw94V9=. .. :"=^,..uS?^. . . . .. . . . . . . . . ... . . . . . . . . . =
Jf^ .. . . . . . . . . . . . . . . . . .. .. . .. .. . .}6T6$i!+~,.. ~O4u{!!je^. . . . . .. . . . . . . . . . . . . . . . . . . ... . . . ... . . =
22^ ... . . . . . . . . . . . . .......... . . .. ... ... ...... . .6Ic35I=. . . ...^v}ca$l^. . . . . . . .. . . .. ... ...... . .. .. .. ... . . . ....:... . ......,.... .. . =
fJ^ . ....:..... ...... ........... . . . .:,!!<-!==!"... . . ...:...:..:..,. . .^!\, ..,,..:.,.. . . ..:,^^.... .. . .....:.... ... ....,:..,., ..\((?>(==^:. . . . ......,,.:.. ,."!!.. . . . ...^"~?(|^ .... . .. =
cJ^ .."J4nTn5TaL<.;"clJws2:. ..."=i?2ai<,.. . . ..^~%yehY3CAh5Ti~|~. . . ^11J3399T16c;..^)JL5o.^]ff2t??]3+=. .^?t{$]t=~|]t. .isfanzCC%". . .rsyz4LVYT9C~. ..^j5*hPDPe0TmaT1~;. .54wjtffi%J!. ."+jjwc%i]=^. ..;!?2t+mFDK=;(zs?;... =
r2^ .=gYDFSQUgDj-GkK5oVhFJ!. "!9m*JaPa?. . .;!Jau$UFU*a*n$y1VOb~.. . =UG0LskShqpU"^n5gpq8.=ATIIn2*m*U... "J6n3)!!=pd. .;*PpdUk}v+t^ . ..bZAgFPDUonPb.. . .!GZQPPms%+tij6DQ9=. .%UszufL4s4mj..)5m58T9&f! .:tnS$_!+&PDDl"IpDg=";. =
fJ^ .tXeT0kVqDF]xDqhs04GmZ^.]wTTCrkFV2[^ . ..^7Tr}":.....8CcVwu%"". ..=ZkasJ[%rOm&"{nZqff}\.=Vu1]rOk]zTk ..."royC3wDQx8 .+%bQDFFFh}". . .x8VYhhgg4oTk .:-az0{"... :wkkOpPP*T;. . (tv0gPUpAGbc"+kyw69*&mUG0&G.. .. ,~I&Qi. ....=21UPmTP2 . =
3J^ .+#d04kO5VUL#AFFL8&YOFFc=sanCv*qZac_,. . .|c3V~, . iVuIrsY5y... .=OC23c3cfI54"k4V?(69t.)g9I$JVUi!t[ . .."CCTyL*Zhe4....6!obQFUDD8i. .. :xasaePQUkSPx. . ~Fprn^ ..SFPPDbGz&$". .iyuJeFk5O4Ta$5w|i1oC8*4eG*O:. . .jcTh- ..,J=3gDOddh.. =
32^ .tWx50GGs$Ca"^=*h4xhyXWAx^-JII*gW52C^. .^ny$~:... . "9sC%]uGnb5v... ~8kkny6u$$2+~It^.:^^^.?Ume4zsbn~<l. .^+zJkhqDSkG.. .Sc?c5qDPFX1:. . :hOzfOxL8dWKg. ..=khb7. .. .9PDPQJ4GY%,. .%ghTkxOru]7wxu^.;|JnT*T&8Oh{.. .Ja$"... . . )+%mF8Feh~,. =
cc^ .+#h%l[6okkL..!x0*Zq5Zqde. "VsJ*XXpJ$" . !n37.... . ;++cj1+iyACi^.. ~CCuw9LOY4Vo[i, . .?d532taFULy8 .. ."jJ$5gqpDmIs ...Dp5rrsDDFX. .wVXQ6VKWKK#d .)qPU ...}WA*njyZkXF! ..}bFPpkx611axI!.. /%aOmmr!ti6... ,vn\. .=3w&pO*LG^. =
ff^ :tbuy6o0ZQW(..>x&ZAeDnbAs. ^sTrg#SAI+. +7". .. . ^$iilvr+&m]i" ~a9kk*G88TCc|... . .=LCJ2nSd&uT ..!ltfdZZFk]|s....WFV3nvlwdF$. .4OPdVdQQFpxT.. ~be!. .. . .[e55T5eFVFb!. .tQpQqPGzrT&G, ..<nfnn8$+i%w^. !^... . . +ombY&q9,^. =
rr^ . ?gxPSZFqFZ) .<AZUdVDC9bz "&f$qXPb6zf. ..... . . :tT6}JIck5t%|. )p*&890VcCy~ . .(shI+2FFxyi . /r9pAFQp$j!Y... #FD4s!/}*Pf, . .*pO*hO8nTf+. . .... . .. .lxUhLQDdLQq7. .=$khAQS8T*4j ...:=a!i+35*8oT=. . .. . .|o]IyZFA[Ve" =
Jr^ .iDSFgpqZxh= .!QdQSTXk$&T "e%veDFPzz1 .. .... .. :~VqCtju8z2Y) ..)8k8522%$5mc; .(aO7+IsxQFV=. ."$dddDeY$vQ. .eFQD5%kPh3>. .YZeqQPZU06uz. . . . .. . .)65OgDFAqUPu. .tTw$*Ud8Oa). .~xc!|jkaTs6!. .... .. .. .|Off4PVT8Fb^ =
c1^ =ZggAA*auv!..=SgQPwUn2r. "#V$TQPQss% . . ,";^;.. .t*dk3++*T6V= |YnC)"tI4*0+... .i82]ww6aPpx6 ...<8AqFhsu9uF . *PS#q1+!~<. . ,4QDqdDpDxw5b.. . . "!"\^...=?78xPdkUPA.. .[Gk0c]TLm&2_. .?0o$u[TLCzw). . . . ;^"";...+dmsYGO&DF*^ =
21^ ..)ggAO0n11]~ !*SbP8LI]t.."Kh6IdPUna] . . .."${C}:...|y4$a[=sTV*| . =3ti~!1GepG+. .. .ib$fC3CSDQF ..!eFDUnuIC5W.. nUFXSfvttCi: .. :ygPQGSDSh*gb . ..ia4h]^..|i$mVd*CAUDu.. .lhYeZVTs5&!.. .=u96zI6$n=.. . ...?s*n|...iPbq*Y8pA*n;. =
c%^ ..=OLCa&YIn8= ."J4L86yG4k+ "DWQxDQSsIs . ..!}=oZicz{3{"rOdbA*DnyCC~ ?8kL8Oonzc2t. .=*o|"^~lZPgK . .!qDQarvuCJ2L . .ITPW#uooont... .%qPbLJSpmUPh. ...!YZYG&aDOsg2swY9ZTrD5Lu. .iDx&bFdDPPz~ . .!3Cft"!t$8J!. .. "sT*GFDXKWWS]QqQxq0hPXq^. =
3[^ ..?PFamG&LpF( .!Gxh*nyr3&J. "KFDUUFFonV. . ;|3o3o8c+~"\~~7Cnbgx8C333! |G0O4mGkVnu+.. .=Y**TYGTmeFW ...!DUO1yzys8xx . IfsxFuow6y+, .|FZPL2rTmQWS. -xakmdUe8!!nPe9e&o?iT]ao. .jQZY6TGbZgnl . ..\IVhm7=z9)... ./wfJc}]w==0hUbQm400*&Qd^ =
f1^ . ,?SZ*n5cQAQi .!ASdegZ4*4} ."epQQmAFy*0. .=smS5yLa<; :!y0VAGko]ftJ? ?pp4VGV40GG{ .!asO4gDq44dX.. !q&6&bQXFQpP . 3u4qo&5yC(, .. .~dbph1cYKXG.. }p*0Tm*qg.. "pSaey/^_r0Uw. ..+UQh7)[y&dZ{ . .?na*kG{Cz%C!.. ;o9v%jJur=,.^)ObOuY*aOSFU^ =
f]^ ..=4OpT%2FgPi "VdUdUDDbUw .^5ZFDY#WzV* .*WK#qnQp". ~pbZx9T61vi~ =*GOGOGmL4Lt. .1oa&ApFe4gK . \hxpSFPFSWQq ..sncsAkCIC+. :=FAPh[1ikWA6. ,2DKQaUpYx. .&Z8A$^.>6qPz. .[AFps9aa88k{. .<L8*G89wu$$=. ..)051vCY6!.. ,tYy3kUk&ppQ^. =
r3^ . . .tQnQbywY4Y~ .!o&&AAAdFPs "U$%8#&Y9xb. .uPPLurVXF+.. ."d*YIf5*[[G&=. !raazIas&4*7.. . . .?U2aWxsDF*P . ..!ePDQDQFDOu]. OIo2u+uT447. .!sPWdl+7n[Ia. .)GWWgO$LG {ggqo++1PFS.. .=dAUdy4Y&&g{ . ./CyIC]]r$&i. .!$GT+c*wmL). . =1[khQb*nDg^ =
c2^ . ,tXGt5VTfaO= .>h5L&hgUQn.."XGzoae8*Xg .!F5(~)IYWPv: "mw5h&2r**= =yJO5J]vf96(.. . ..(D8~thFC1nOP . .ppdhLsCui1$....69nVwfuzr. ..\$#Xx]$Tynw%..=mhKQPV06CJ .+hhxivcyFpU. ..)VqdZVx$fLZl ..,t6OwC7f6ws(. :IxxT[Ynnw~. ^=TdpqQUYxZ^ =
Jf^ :.. .,tKxi6%ausm= .!psGf]5kYe5,."XgDhJqSmF&. "Zi?!!vTKgj.. ^G5Vab08$wk*( )L$r1uII6zt.. .)dUT%LPWJv4Q . ..^J$cuttt[fkm. 22*kwaYT647.. ./3pPhwm9o5k$..i#hbbqw$IC(. .7Z&9|w?iPbg$ . >+5hSg6urIZv ;c8mw2[2JV[/.."&Z*zfwma9a= . ,iUdPFdDs(o" =
Jf^ ;^:,..|ZFiJ1LarV=../Ys52|0aJct:;"bFx8&48xFb :ppTnYV%LXUI. . "P095d&&$5k4t .|8Or1C9TyG8i. .. =g&[yqXeVkg. . .;=Ja[$u35*Y. ci$Cn*948Lt: . .~&phT55$5G6..=Aoosa[{]u~ (9*0wy=?nUQI.. ^6sVb4?1$TQ7 .!OYz$3%iTSf=..~S4GC+cT98x?. .^nAFDQFPG;!; =
f2^ .=!/;:|SD{w$L*fI-..!ezLJ!nY49=.;"FFSO4mbdY0..XXUTT4O0PPn, "bctx*m*Ta48t. =O84$oosoG4+. . . .!}~;^!hPbaqD . ..!aTf$%L&[kmk. . ${IITmT69i:. .:!IaZez3Iw6YT..(zosTa&Ta49 !vom84Vx*5V3. .=DVGeS(Iyq1. =o6f]uw5DUI)..(U8Vvlr&sQW|. ~PQF4DQUP^:. =
fJ^ ^tTnt?2mOszzqSc:^^!hmk6]i99Oo.;_Xb*50Lxd01;"TebbeV0smD]:...^u(rU0O9GLYm)...)8kV*z$cwG*%.,,.:.,:,.jKZJ~")gQFFa...,.(SQPDhV6rJ$Y....cICY&TC6C9j;,,,.^(3rzm]2Ircx8:~0Yq08m8G4hL:.:.tCCw6r(t4eZ+....[AQ&7inmwcU}.... ~m2fc9VUdg3~. =OYme8L9Tnf". ..(&0kT*Qbg), ....... =
fr" v5Zm9r*a5IqZ&^C"<eV0+CkZaTl.;<Lry04as9t13?wQDDSForn0n:^.^^uI8e0JtxGLm)...)L0Lk*T[f**],;^;^;;^^.7XDAholoDPK5..^^:>0PQPQWqrfcY:,^.rw$50O4O5n+^^^^^;t6u3sIo91c89;!zSe48*8GGAn^;^^!=$TVOTt7sa! ^^^vFq2=!sh0+01..:. ^^!12cY&40f!..=qqAew949&o!....{pV84TQDZn!...,..^^^.. . =
2r" >58qpLnIaJegh!s^!6u+=f&As0s^;!CJ4O5{Jwayu"?lQDPF*)7*a^;^;^3TO8n^5x*m|..,=0mLG84TCy4},^;;^.";^.+KDAqSGaDbPa.^^;^-wkbPSDU*ocL.^;.20zswVzys6i^^:;^;fa$fy$m8itvr^;{LG**8maaa;^;^^+ysm4q4YT".^^^%g$"ifIs0+a+::^. ..^iII45Om$!..?pxU8tTP*x0!...,|ksb&wdQAUv^.,:,;^^^; .. =
rc" rmGqA*If1mbU{n;_yur5f6bJ!!Im5$]aGV9".!"feQZZ}5n^^;^"s6bkt^.?Tk*t^,.(yaG*O*4nn&l;^;^^^_^;,=k*FdpAgZQPk^^^;^/%0nhpFKS0]5:;^;C4CuJI3$+^;^^;;zo9su8m(=%[^^iY5$$nu1f9"""^|5I6Ls*Skz[";^^^{6!.iY5y6iCt.;^..^!t6&L&VPkC_..)pUxT+kDOGk=...:taGZs1VDSQ^:^.;^^;;^^ . =
J3" :/yhxxGGf6*Sh0!!a+7J9L*8*G8m$65TTzuwu^^~n]$epqDxa6"^^^!YG*91?".^}O+^^^tuifnYLzmnIi^"^;^Ii^"^jg*~?+{%zmxg^"""^(rtjrwzo0*&^^^;^vzaLsmG*&sj"^^"~Js[C*J*a6CL&5/^==3uJv~OmxT"""^fxO8e6+ze+(3^^"^]e0naYeqT=T];^;;:?U84a$AFLJnj.^"dx4IkWP*45);^^^(ZFLzzIhPDq<;^^",.,^"":.. =
fc" . ?r8OVphC8pbk~!]1!?2]CC$wIL$wI6Cwc$Y*""+xDWFU4hgV]""""!ffomKXS=;!&7""^(ryT24Ooh6u1^""^=a?"""%n7=t{71a*Q^"^""to^=t2GOa5i^""^^}xAmGG4Vnft"!""lmCC4f9II50*f~"!t6$rii*m0w<";_CYoTmT+=o%!J^"""%VSgAP0xZuo7^;"";)en%C0Dbu{h%^"\o7tIqDpzsTt^""^lQ4Tk8cfVdU!^"";. . ;"",. =
3J" +Cl&mLhzomxs~+%""$01J]9Cj$uCk8onTuc""=ubFFPqbLG>""^=aJCxDFXejt9{"""{k4]n53mnT{"""!fJ!""+OkGeZFSaaYS""^;"iO^^i+3owV!"""""jh8k8kos9cc!!_ifiwCTuICz58a](!!+$11[&kG8f!!"!5*8*m&u"=1|%!";.=$0h8U&hG&ni;"""^tT2+aqF0}$q1^"^>i]fVZOn4U7"""^9&&fwaJ[CLO!^"^.....^^";. =
Jr" .j6(fOqVGoTe3"!fv_^lw%%kC+i1%CuG*Y09a=!!iSQZFbXSkz<"^!tG%jQPDDQhw9t"""jXdr1]1LTO%!-!=4J!/!!CSQPPQFOk44x!()"^+e"./)tI*&"!!"--|mY4YyC$163]+1Oat}JIwC$C8s52tv!!(%]uT8mGm2!_<+*8I5gky"=i=i!":.-!}y0wuoswk7"""";)fuJ0PDTcLD];"^"vS$0ATaZPl!">+mTC]zT5$Tkai_";,.^^!\.^". =
2f" .^"""!!7ffji~ti1rannxs1lcaaVnau=t]uC$n9oT5wwzI}8?$aw{nwY0s3DGtPboI&*eDhs5}!!-]0rr1]Csh4zO3_[g8(~|(=c8a6y6$z9[$S(Uh4~rh[=ijt}s{!!!!!!!}fjtI9o$*t3C*y="Tl|fut+j9c$x5?t=%&O88**J[?!8&m=7m9v}%j~_^"|zy^"+[jsv)iui>!\~~vxOs6Y*pDPPI!!!_~&nzO$*QKb612VmSSgpqYs*een~;"!1dGv++{i?~"^,. =
v3" .!$$Is40&hpbZgbp&k2c]In*&OCzOG8T0v+[5J3Cf6w$r3Ifz2bj|Is0hV4gU0S4=AWg+1ne9TZ]=!>tj7tj5sok3Aj=*gx!)=|}24T&O5Ow+t*Dtqn%]aPqZsGd0C?!<!!=!=~1Cf$f}0k+fYJ?!+wfs&6i=+31LpT?=tJw8LGkatv9iJ}+1=?utn5="_+cY9!+f56sUo!ir?-=!|tnZksY*a4qD*1=!!!!t300aGmL4VhgGkPbQpdoGxkYxl+c0bm}3azyi^;. =
22" ,>6L48eA0meG*GmLm4*i[Iyw$+&m***r1Jizw3[I198Yw1[+{jfFjj[YSQVkUx31i=Z#XJ&Gxs5Fp2t!iTsu%T0YO%spJuS8a~=iJOGV4Y84yf!]ZF)Tmt5APPq0mbS}~!!!()=||+lo828Dn|lt!=(&dSA2%v]f4eT!tvvJYVm2?"[$t$]n5C6$tvCm5t!y5)+f4h*s*G{7[?!=(=+fYuTmknozTrt~_)i+iCgVaGx*YOn$]4AUPDVo4QIUAJsxDQ9}JICaI{>.. . =
J%".^|Aqx*8epO0hV8meGG6stCCC*u%]8yGs$!)=i86c2]t1Oz*v!!"!yFClil8AgU05a!)~9KD$==))kX&~!<!=|=t~~)=~=TS%8gL]{IsV84V*kkf{="?tt?+hCi1w0m4eLY?!!=/~i?===|+5wgDsit==;!lUdU4it+2tIkST(1cccuVI^^!Iwv+%Ogg*0z*G0iuu[t$Z0&s1zhc=|=-==|)?+{+iiti=!=tii1v%t3dmzUqgp837}25s9u(ihU%69{SDUg[3no3i!^. . . =
[f" .;\(lCL*xU4&syCo0YaTV7$Clru6+)ttitnk9$o4&Jfu9o]i~=zWei|l2aC]7tt((?ipDe{~=%KXw~=~~((==?==~=}V&20OwaVLem4V5f%lt|~=}j+ti2%"-{f&Irv+=~~~(|?lt+iti1xSQril+vuLUqxuu+1ll]8pbn}JI3ftt~+]vuwj3{~)t$n0Ts5kC$oIzTI3{=!sFx2=(!"ii|=9[=)t{{7?(t]%r3{jYp5{55o3i|)|}3[[7+]PF{czkqghJ~(=_^;...... ..=
J2" . .!([mm*8oIYT8&ssSbT}}vtuwoCc4cqULv3s6w+(nWQ!tFZAL}+t+++=$WFh+|*FWu=!|=?tti)=i?=nmmyw88m8m&8i|?+}7j)tv7v+)}l}it7]i!tlt~+ts1tiA[+ii5PDg7j+IddAqkizQtff1CSqh5InJ2j]l8F43o8=: "2%[I$%1ooy8zf+(nQDd++=^+it]g%ii=|{+tJ+iju[lyggyj]j}t=\!!=1r{ot2FXvaDPASt^.,;^!()+++("^..=
2v- .==Ch*V8eiv8a8*8wASgkj+ta6oJvLv4DFswIo+9KFr^!zgAFdt=|?|t8QDt!hDZ%)(=i7tt+(!(i=[9*&*Gm4O8nl!i7%}7t+t111t>7v7j+Tli/)]v=!j6&f]iDsi[j8QQPt+7*SPqA!wFftJcyZdPsJC]j+caSPL%$ao!.,?2[vuGti[+$w*88ksIzSPpl1t!+7sDv++t=+ttntt]%t7Gxbf+uTn5T5ojj[]L(%Ue3dFPGt^,!t{aGxpxge8w+"^)
J[/ tc4qkG*5uG4GVUp[0*xPY!3Tmw++nreZPZwu$${IWQw"tjmFdKD&v>^!!IDpI=PXQ{(=i][}+i}yn*TI9Tw9u]TyoIl+}+i{t"+tIu7^t$I%i0$!^tc%!tLAn%%}De}{2xgFU~1*ADeQg}+6pz=$5sUUD6I2c7%3sAK*+z&IJ^:^1r9w*m+=t]lIf9mw*6&uZgD[ji/"(T4F1ttl}[1+*1|=j16eAh%{9TaTG4s9yari*lIPhGbFSw!"=0AZZZdgpSUzt". =
J3- . ^CY8*8T2|*8GahhxC={CVn2n4mt!!s9r6mKKenoIc{eF4+c6G0OFXPqVt=/"hgxnQQ&6$%7}]3(+2mxgUG9u$f20kY*&V0o6t=yt9$67^![cltmO!=Co9xPx[%uzQPh2jDFbm1GSASni=tfceerjw5DgD5oyfruu$6r|!Iz&6j=|$TV8af(tcJ$lt$osCcuT3gqZG+7+"}hPe1rfljII1S5%j%2xQQmjtoknYY8&4ekOeTVgUQQSZLa0hpZgUbd8yt!". . =
Jf/ ..=TG0r!;(Gm45b8mh.,;/+w0To;!^$w52{DKDFQ3u73Ae2JQF!IQZPDQD=IAqDDPp#4u1t[n7!uxFU8mivCfnJO*0Gm86C4O3nrl?(]$uilqg{IVFUULuo2iyIQQ05PDA0FgFDj...6n[VD0{vOAFZ]7uJk2$5^.^f5*$(80*Go9t~"y*$L*{756I}t==YpPQo=+t4A#012171+jDU0cz4bPUv2j2mT94FFQ0&V&TkLZQk4ZFSDPDPPPhs|";. . =
JJ> . .:&oLV*&":;]dG*CqmVh,..,!nGz3.!"a9ou)Y#PFFkcv%FZzyKWt.!L#DgFFgG%&pDPQWPTav=7IufeSq8kG2f2oGL29nV*&Jw$IGaJ5vlT$CIjCUb3f5DQUm1[57/%3xP4VDQh4qPPA^ ..O%bDsikeAF=/+yAJJyy",;3$$][V56y6!!~+yw2xO9fykfi%?zPPps}i+hDAarfucIt+APkCzOgPh]59362apgDDwoa6xUYSUYpPFSFZFG5%=^ . .. ..=
23\ .^ckG*gC.."w0Om7bGk8^..,taw5!."^u9as~+xPpPFntcPZO0PD\..!LdDFQDAsrGDqF#4uy+^=TAbg&8fo6viuaV4w[1uCLnJafu*5vCCzznIvurQpwzebdF3vss1i7tYQgYPPeAQQxl. .^TIttVxLisFAe!:i&PLu90i^^}J[fCocI^;~aLzzrdbGsvI9%{{JQQpktt{FUP6JIrJ%ortAPAz$bQp8]Y8}oVhSFpa}$C$0AZqLLkqZFeGni!;.. . . . . =
r2\ .;t$sV*0f(..^tGm&e~8V8G".,>2J1|!>|?%TTz(^>{shFxLC8PxghO?~!\=1[SbAxhTLeg*ouf)!|9*e0ortjsa{]Two4Yf2ura]{al5n$TasIcjc45QYOxPQe+!20n5$GwoeZxegZh$+~!=ilJOn6YZxn&hdG~l8gZ*iin9[=]3JC>rwIt:"%GLT5zebgV5cc{~8Zde[%0QQZ]6TzIo7nGZ85DDF8wTuxFQAGy?^>|I0Aekk8x84&nIJC2(".. . .. =
Jr\ ._Ca4&4%. .=mhmG4^3G8m=,.(aemmSKXFdPDbA&j]&hpDF[nTww8ksAFqAFPAFFbGA4q4FUc)!tt|t{6)!&xC?c4YTsV1iC$saC$$ouz*Lmw!;;(D{aqOUDQx57IZDFFVwKeaSAxYOG15GZFPPpQQgbbWPdhOsiQgZx=,;tmozuwwo~azkz"iCTG4wuL[r*xAAeIc~tQpqorpQZZTJJ9J3l}CCYAFkFDqmY$IxDQD*sgz_[xXWbpkYeDADAPQhf2f7". .. . =
2c_ .^+8TnTz . ^[dm0GJ;7OGm|..={CLAhKFdAZFPQQbQqxS*pFl3kdPUQUQdFQDDAUUWkkmZDFd[;.:,;+8y]LG+!ukZma**3[J[IOsuCI50*9[".^~b[apbQPZO44bFpQdPTPUmpgzCoUxPQFbSAggPUZQWPesskCoUDdv...!w*ns96u?wTY[=rGTy]|s9uTdSQFxyvt!kbFVJbPQaPC7%7fsLYbFD*DQb9waYPQPd8pb*+hPAqDPa&Ad&pQbDbAd8c(;: .. =
rJ< .!n8ayt;. "JL0*mf,t&Gm!::+^|rGXQSDQPQAAZQFFUY5IYqWWDpApFbbbUUPPFI+v&O0DF3.. ."sD1+*kk!!u&Z8$zm4oI+Jys$uzaoCIv!(=tba4bZdApqpqbUDSQDPwpUD0k*DUDPDDhFFADdPFqpn6*U8cVbpDi;"!+wL8sz89i6z$u240LY==LaJ4qAdDh3v"2ADgngQF1WO+%ueQdV2WPDeDge{9xdQqgO0XZYzI*SPZD55D&GmPFFpUQPb5_^.. . . =
c3- ."~~-;. .)0m4YT~.>$&G),;"...;<1$G*dQQQpgASGYVeeAbKFgpFPqgeSx4T3tVTYheTkx3....temi*hef;^7kmhn)Y8Gaf3Iww$JJ6uc$CfcCe*xZd*eUDDPDdPx8z+%nLhhe4hPphSA*O4aOmO5u6hhZg06hPAh$nVLxo4k4wwwcwr9y6ms4!;"9o5J7USASpOr+tDDDOFpG=FJrOSXxnJfdPDZdQ6ugFqZ0+"iKQhl+8DqxFh3PFexGheSdZSPg85)^.... =
cJ> . . &GYm5!...-uk=:... . ...:(2C=""~!(=i]lvzYyzj)_~t)>"%dZZZFDhDd{[=: ^j!,(UZ0+..<688d~!+ra8Gowu]=|ITnYz$]2dgO8wGwv}!^"!%rC?,iFqbcIhXPFFx\,,.."inFDxd*35UxanaVmwsmyo9$v=iifa9jw6T{..^owoT%tlkpQZd5uxDFqQ8!"yDDQF40PXx0dDZq51mDPZi;.,^ion5pFpJ5DA%sUFb3/;"9SSDUdZWK+>. . =
J3- . . .VVom]^. .^7a<: . . <[3^ .;^-ir80&Vk5T!.."";,.sDSDpUFPhQb(!+! ^"..+UG4~ ^C8*8+"t58*8o6fu3cJv=!?ticTghSV0GJti;;^yak="xPDF4?}gFFFPTi"^. ,"$DYpG5k&kAd&6a*&e*6$uII+7+I$?%soy!. ;$56yf^.|GApbF4yqPbDs/!pDXFg=2xQbVUQLkYahdgd)=?tlv3ossan!OQPu|pDDD{^.^!iaZPeXgxy/ . =
2v! :0kw8!. .!s". . .. ,tJ:..^|}eZq&LbUaei..^...!QQpDqbgP8QWt.^^.;...%mL4^ .^JmmYJ::!I*9o[icz$+;;!1eDSS0GkQ4mx$t"^yhY!jPPdDD]=+QQPPPd8+. ..~smbxVmnxDpg*1[c4Tmoo$uf{+~""CaVt. ,1yC?..;!sQpUO}eDVDJ!wDPQP*;^isPZUd44LeSdQYaOhgUASd*G5t"agDC"7UQSA],..."(nbpeex". =
3v! ^k5*k:.. .;[^. ."(:=j0SFggZeFUUzIx;..._vGPDge8DQFIQPe".. . .^z*$~. ..t**h$;"i06$y9$$Jzz$?~LbKDPmfzhepUQZh*sGYu_PQKKgbg6=thDPUPWF=!i$VeeVoI7tt~";:::^!?iwo91?)?lyz3t~"^"tu$$[?=!"~LxZDVGAxxtupPe5i".:^=Gxebk4LheAAqbPPPFPZPZQk$)n&xC.^?eDDP) ..,^"~(|{=;.=
3%! "5ws{. ..^^. . ..^!wUFhPFpGhFPYGDV^J+./&QPpUa/^gDQG"5DX+ . ,i$!... "dGZC5G0$!kTC6yIIV62zUQFFQ1tqQ8qUFDZPShpptcFQq$PPA:,.^eDQKPpJ"\|IqGDFPFAPh|.. ;nkO4L3{aI$r[c$G*8mm[=LeUDSqZADSpPbYa9Y$VQFJ+!^;^+VqhVV*0OsyGFUUb&5ksvjl==!^:hFQa .!FDK*.. . . ... ..=
3v! 6s6! :^. . .;+TAQpDqF9chbDowDx,!]"$DUbFG!:;DQby:tUZt . .;2t,.. . ^hAO3Yko~"2kzwo6o3aGuC&KK8YSu)yFpSOTbSQPhT0oG#KViFQg^ ..~seWQDbt,^tyCFAPQQpDq<^"(}%=C!!5ouii(JT4mmLat$uexPPDAPppPQ4m&8shqDs4ay6=^<+ZAee*0utjl{i?!><"""".^<";SDPI . ;qWWx^ ... .. . =
3%! .!T43, . .^ . ;=pSpQdZe+cZDZlJDq,.")FdDpDv.:!PQUt.^}x+. . ./J! .. :kVsa]!;)ayCIu*mCtry3UKP9kD6!ipQbn|vbAZDgdsxQK6!QDD(. :"=9dQUS!.++7#dd*ADQPWe7^.^;,t^^o8mc(.^!=++]2tCCIz4QPbgQQFdphV8ObQQFFDpAGr="iap4xVori!^;,....:,. ."^.hSF[. .y#KA. .. . =
2%! .=V]^. : .^lmUgpgG5=,^GbAS"JgW^:iYeASgV;.;jAZs"..^~( .;~_, .. . .z3Iy^:..ukT7+2Y&o^^i8KK8$qp4\"eFPh~^"~9GZg5PDXs!mqP. .;|zmmj^!;+DPPs|rLPDWDn^...".,20wz=....:::;JC/"~(lu6Tx8SeUAeDPPFdUPphk+"t7(FPQpxn[!;. . ...ZD#i >fSD[^.. ... =
Jr! .|;.. . . .^wb*p0nJ!...-yqD*=.!gq"1edPz!....|ZQ;. . ^^...;. . }4qz. .:Ym5!.^{0o3^jb43PDS^."LFQK+. ;:^_gKC7&taFF=. ..^!",?S9qb(.."C&PPA6\.:..:i;!x8=... . "$C; .vOZDxzPP1=4Qx~:... . ^;:(FDAL5UQdk?;.. . .nXP" . ;wh7^. . . =
fJ! ^=. ...^jqx&a(!;. .vgFSi^.^wd!kdgw\.. .thg!. . ..:;. .. )08z ^&*T^ .!T6o!5h!!23FPU!..+QdX9;. :..;e&!_~=+hX+. ...;,^^~u?2Xy;..^!tyDxI; . .!.^3dI". . .:=2:. ."qU#pi3QAC^^=mz^ . .^.,\DFg47LpDPO+".. .A*; . ..=qI". . =
JJ! ."_. . ,;=v{t~"... ^Vbh0". :tauqgn!. .. ,tQ&^... .. . . ."n*{ ..^G9J; :;wyuc6+,.!lDUAt^.!eFK8>. ...;h|...:"yX]^. .^ ..~+;?gQ=.. .."J*q=. .."..<JOt. . ."+. .;6dQUt!4p)t"...)!. ..;, .>gp#Z=t*DQFh1; . . .re%, ;0L!. . =
f2! .,: . ..,:,:..... . .~PFm!. .^vC)":.. .^3Q!... . . . .+&t >m9=.. ,7Gr:. ,!PQP%t.;ieKgf". ^),.. ."P0. ..;;. ^^.;zWu^. . ..:^";. .:...^29;. .. .". ;CxeC";1x|^;".. :^. .^"...^]aDW|,+&PQD).. .jz". . ..!i|, =
3r! .. . . . .. ..IZP|.. .:"!". . .^9e; .. .. . .^{~ .=Ti^. ~a2z^ . ."SPh+%".^iXAg{. ^;. ,nx<. . . ... .=#Z!. . .. . . ^!^ . . . .=F8=: .8t:. ;^.. .;^:. "^igDl .!nDAI^.. . =_. . . . ;!; .. =
cc! . .. .. .^kI-... ...". . .."+^.. . . . . . . ^^ ..(!:. .,{aw! . ^SKI,:"; .uPPG^. . . .. .!G>. . . .. . :$x).. . .. . .. :. . . . ..!~^. .". ."". ... . ^.^1b: ..^"C", . ". . .. .:.. =
fr! . .. .. . ../9<: . .. . . . "".. . . .. . .;;. .(^.. .!y6~. .;pK%...^../0qq^ . . . . ^7!. . . ."o(. . . . . .. .. . . ^",. . ...^!.. . . . ..!oo. .. ."+(;. ;. . . . . =
c[! . .^>"... . .^. ..: :!.. .:ow~ :hF=. . .~8p~. . .<>. ^!. . ... .^. ,!r, .:^^, .. =
r3! . ^^... . .. . . . ,; ....{9~. ..&V^ :|$7,. . ,;... . .;... . .). . ... . =
13! . . . ... ^=~.. .}!. . ,i^ .. . . . . . ; . .. . . =
J2 ....... ... . .. . . . ... . ... . ^/. |;. .. .. . "^ . . . ... . .; . .=
crt??()iii++++it++ttt+iiititi+itt+++|?()(|?|)(?(?()??(|)((?|)||)))(|?()?)()()?)?()|))|?)?|)|)|||||)(?|?=?====()?======)l====|})============+==================================================================================================||=)=========================================i
e3ZYYd
sIRC4.exe
C:\marijuana.txt
uk.undernet.org
Runtime error at 00000000
0123456789ABCDEF
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetCurrentThreadId
GetStartupInfoA
GetModuleFileNameA
GetLastError
GetCommandLineA
FreeLibrary
ExitProcess
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
CreateFileA
CloseHandle
user32.dll
GetKeyboardType
MessageBoxA
CharNextA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll
WritePrivateProfileStringA
WinExec
UpdateResourceA
SetFilePointer
ReadFile
GetSystemDirectoryA
GetLastError
GetFileAttributesA
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitProcess
EndUpdateResourceA
DeleteFileA
CreateThread
CreateMutexA
CreateFileA
CreateDirectoryA
CopyFileA
CloseHandle
BeginUpdateResourceA
user32.dll
SetTimer
GetMessageA
DispatchMessageA
CharUpperBuffA
wsock32.dll
WSACleanup
WSAStartup
gethostbyname
socket
select
listen
inet_ntoa
inet_addr
getsockname
connect
closesocket
accept
0,080<0@0D0H0L0P0T0b0j0r0z00000000000000000
1"1*121^1f1n1v1~11111110272
33E444
5X5555567
8/8:8E8M8W8a8k888888888888
9 9&93999S9Z9d9n9x9999999999
:2:J:R::::
;5;_<l<<<<<<<<<<
=#=|==
>'>,>2>>>>>
?!?G?S?[?????
0#0,03080>0Q0Z0x0~00000000
1*1J1b1111111
2$2,2222222
3!3+31393?3E3L3V33%4C4O4W44444
5+5D5]5n55557
8/9X9_9f96:K:~:::0;7;f;
=$=5=>=T?[?l?x???
U1]1f11222
313G3^3s33'5555555
6.6:6N6X6k6666
7A7H7j777'9O9V9n99999
:c:v:::::::::::
;4;?;\;f;;;;;;;;;;;
<#<E<Y<<<<<
1U5^5i5n5v555&6-6?6]6f6r6y666666
7"7)7-7G7P7Y7j7t7~77777777
8,8=8N8Z8_8d8k8r8|8888888888
9&9.969>9f9n9v9~99999999999999999
:#:/:<:N:;;;;;;;;
<"<*<2<:<B<J<R<Z<b<j<r<z<<<<<<<<<<<
=$=.=8=B=M=_=r======5>}>>>>>>>v??
0l0{000000
1$191X1q111111
212I23g4444A5s5{5555555
6'666E6T6c6r6677z8C9V9g9w9999
:Z:M;;;;;0<Q<
=)=7=W=g=== >s>>
1A111222
3M3U3`3|33
4555)686\66677]7776888 9>9i9999::
;C;;;;
<2<D<<<<
=-=p==3>?>L>^>d>p>>>>>>>>>>>>>>>>>>>
? ?-?5?<?U?Z?d?s??????
0q1111111182R2k23444
5I5V5v555
636Z6o6666666
7R7o777777
8-8M8e8o8v8}88888888
9+9J9y992;:;];;;;;;;;
<<\================
> >+>6>A>L>W>b>|>>>>>>>>>>>
?%?0?J?U?`?k?v????????????
400111
2,212@2N2222222
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8h8s8}88888888888888
,000409999
WinSock
System
SysInit
KWindows
UTypes
3Messages
iconchanger
sDeclares
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
~8s[?a,
,DUq,:@
32%5qf<3
;)LO-?
~7^}89B
WihB@cQDS1
;. Z2r
M#]Fb
?<J&W2*
l0<FS+}?!l
dpBBfO
(F^ vJ<!
HRprGN
}X50ciT:NAR!kG
cubw0*!Kd
#:E7~O~L5Js
?"N3E8P
S12ET.6
0HKCa1v!
iyd@sH>
-x:|d2|?
AIP;qdJZ6
"p~4CpuE
t=LUAZF@l
'&SY_ i]>
#}m{8TXl
LC#N7zu}k[p\
mAh4ypG?oky
x'x?#;
Nnht!Za9-
{_}`RJ@p?
vmdI%0\Q
LDeRZd?
`CDF*8P
0YxNVS{|NJoB
ZhWugIg
Q0N+XP&I?
4?`aY5DD
O'p7j^h0AZ9`hFTT(o
![3x|.
p}0M638_*Kt
jX&C>}
l))<b7uzP
FL.iS9S@N
)}`wA-Mj
:LbOyYe
Ye=J!B19
$"H5v)
96%&#b#9k
g5f`Y`=?%x
:~?o!v
>M!>|\
cB.,9BBJ8O;;
aWh?uB
]WH1tuGA
TZTsU16U
Hcbiqw0
{dS/ocW
J:-g[IH
'ST.tINO3a<H
uT<[D$
Z[GAwX
VZ/uAVX
+:lDcj0[
q6G(JZw
-Obp86
r]TeG\\
Ih6bv#
Ibu,P-
,FyRQ'
uNwWQf^l
)pL ;<W
sFE]I;
kq=V|,i
:y1]pM
#q@ -([zU
*_7=y|*.D^_u^
+9t\pY
Lsg67-
Aw\#meYd#F>
oww,,u{!H
!C.~My5UR
UpOTyn75
No5-^8
3,7b^k)
@^w'1zZ=3l?^P.d
>k'dqu!o[aT_
d>]I{
qA9xX'
UZtSkWY!
)+6X;[
+?Zt"b<<|_
CzrZ;7J
!M"};kRjK&
{\v>iAQ
e!_C.z
xq&eO_G
%@9^1k
om5U1HCkfQ]ug[
| ]Ftup!I
;~X&3<zG(xNnV{rCVwJf
swL8y}
@*?34O&-41
s=3yQrl
TZ..qy%.
EoibFL
~pzqnC
c-YdqfW
o}W0zO
Lq1A(s
rk/G;7[
tr6jFd
JKkOQ,\
`Ae*JHIf?IyNq}cM
qUZhA$
&C2gCopp7rc
RO_t{X
9hXJyN
mr7=Hu
;ogA^1@;B8}bo
k!uRUF
:4w:;7|\
NkcAzc}
(vg6Hm<\
yD:^+.n
"}+z(^
(bzRUDx>r_
+c*2n]
[5_['
@ramd$21
vfb9{"2
#B>yr'
N<}}W
F~]217m
@(Lcj
+D1LUA4
YB Gk9q
VK^.fLh
|??[O$o`]/I
Ic!S+pF
F,|z$*&|j
xCrx:y) BM+
R6Qf+z|
bu}WfX_}
yEDDWJ|=3'^Q[mjj
"'4!a
=Xw*aBV<ZH
\q'K1
9.I6Xg
wGSKtsUB)
@O1IU'Ksx
txw]GXyavke
3gZM1f_
I=vSP&
1z3.fg
5\KL:d
pf^1@h'anDy%}E
`h]X@)C~I
`5((sl4U:P
%prT,w7?~
y$ulWt?xG
\ZQ^V_
!k&|66d^%
7#yANgK
^B~yFgbx8Y
^~D~yrKK;U
]TTQm
dqrKuA}
%1\?}JM--}ecB
#%x[sS>u.5[bV
6F^2a5ibT;EP{W
Q678U F
XtvohGRa> 8
IAQ1&,X
2&!gfWr
POB_r;tK
,^GX[e
@H:Vcdk
!G7xR<x
X3+-8ha:
V8@1uO)N#I+
YIU X[)wA'
Xk1z{{SN
Q>c$^B.|-(
0x")`lql
+wP;Q2phQ2
cgkEvOkk
0m]"Pd*g
k"@^&r5pQb
Prb]ZKTv
E$6+,\'#
sQ/IBJ4"o
{{>K9v
8M?Y!Z
,}POM<
-6JV$}1KyM:
2h&")bP
:Php54
[yHRoSua
SgA$R(-
qa8^gg#n
F@8<:ZF)C
@baZE5Oy
G<28WRKN8t)M
Q6'%&ke
id+b3wX]>B
n@8B(2{{
TxNF"2Pyc
^w<E/s
?d:Vf$xf
MGCEe #&M"M
.<R@$
"09Sh!gR
E^jrw-&%U?Tq/H
1#EO+-
0IbUe-'8nGe
4=Sxnt
3Pi2GzE]
?K5`dA
~MzLW~vB5dD)x><3
N*G&(c~
x?AulP
F:5UR8{1
{:MI0C$
H^VO~G
p!zLcs }x6G45&rd=c66Z5v
Vr>N]M
md^81Q
<65fQt6{
p_j;QT|r
sZ'*L-
lJ'shUw
o5**qc1l9~H2
nxyhd
:puB<
] R[9WL_
F+.E]z
X:j}*Q6^
uUI|3~Q,
d)B?oX~
94tcWY|L
@:d`5}`P
$=z~|I
)Zb!.z
<8|='l
}LeXui(.
7-Eu,&<q
V2o}&Lw
~*,)O0
mTF7n.s
^)n1#3(XI
Kh17P{
}uIgfd;B&?*u{
rwgR[^
{[5ymkV%
BUeIN;:
;nx9Sr
Y7`X8lE4
ZP;A_{n`^F>JK{j
?}D;&W
)=,*}QwT<
.8)x2l
_/wABtF>
UOLJPo
5DPK*k~Ih
>:Pd8L
d@nuB\>TJ)MGb
mZ(-:u.'lPK>f
HM8H@EV
&6(asK
s}et8{WV
yf~hMk
L@9b$(N81mMn
?TQm&oQO\E
8b|nj)P
/$(_^N
awpu@J
pXhTQK
a/[ZY%MsoA40|
:+wN72@F%=s]
REX+w!,U
OJ(z9wxC]q<C9
i<$PR)::|Q
=B|#x]
0I.W?b,e$C
A\Y id
y/0*WU%
(IK9&u
it"di.Q{zXC
:eZhqhl
2JilFX0
LZ~",A
F~4'Ah
=|kk_h
cf]l\!
kWbkx|'S[~4g%
h91n'`m
QCO%$U
>6vk0H
NN^OV<w
t_V&n
#/0xO- U
=pTSKAE
G"]QW@T%
UnOf^
'EBKR]
YF[ES@Z*,
aO%+E\W
8P!-6~O
6r$S7
2x;~s4@9
4X]Td/_
Wok|@<G
%iQ6 `uPX{
;xq>t+mEKu
2!MvL9(x#
]l6!\)$Ai1
:9!?H.+
OKg:2k<&
{Evd3-:.
Z^p|r,
>H}f.yYp
`K[LY3
0_=,F-T'Kju
%QpP(Warf
}%nH:<9
fJ7^h~O+eg
j)xZ[I
TDHn HS
+8xs]M)GrE
[lZXQe1JRa EDj
#<k Y;p
9f^/)#12-Fa5D
}k]2-WA
ey$z0D6(!kr;uc(
lnu|Qr
.S`\iUG
N@@i&}
#17S!&W
l%9Li~}E/
j42QCS#
L]5Ef<
#$mqi)v
<6v**Vn
erBBYN
Kne`yI=Z
XM`M-@8,E
e4z2j<Lk6O
tV"9$9ZvW
oapDXkU4%<mQeu
?+H[DY<
,eg,^sh_
e%|'t|6M{Y
5!%nui
214|\qTjv
@-Nk#!#C7g
:wocvP
z`\1NY&#z*
_0?e`1
=aW"l[od
-j}40Fc0
!~ 2m|l
S=Tr3BTQ_?
zIoz\]P)/
sZsHfXZi
k[$FjT&NP
HNQyf;4b
rseZT<'
')e>-\=.
xr?z;U(__w<Z|soZ
~,?~jlp
Cb6@d~{~
%i\cqN
&H=lz%>
7t%0>t
#IY%*SB~BK
*W:F*S
[3c)8Lno):K
p2`e%IWP0Aj*hN
RCkea?*
jy7wQiU('Q78;
EC+6in+M6|v
jPqlS}(D?&
Ij 3.&
t;nsx=
+ZdfzSF*)
gU#>0J
KPgDd]
#Kji6)FrG?Pn?U!Y
Er>(H0
"I^>&%bMMB
pDZuOr
a{{>x7
d1"vw/>K[O?I
r0u%q,?
Nr-"&~
766jFSk7|
*f7/(+
be&UG"w%'q'
H:!c2Hf
zYK G-,
D)b YJ
t}m9J-
\Lr]Nf4;Kox+SklAKlR$IACIwLA{=
>wTTSc
jdb5m3~3
+k!CiK[
dVtG1k
CUSRe[[
l!A%EV
'0^p\\F
OY4#IE
+k<|/y&-3?7
sw~u?d
V/njhqw:D
_3qo"d
bS)DC\m
@'ZY]Qnpw?
'|L8p
dbg\4"
$bW/q4AkK
"m'FF^l~=81
lrg{~8
1IyShK
rgd# 4N
pfQ}ZK@
fzrz;}O)I,/yVA
*'5cf./w
q42Kp]RPw\
eei%P>5U7*
@C.U|C
_:ACLD=F
4cXW1`Y
U?Cf})o
29~0yz
ioEX-bTyZKO!F
jBD15o
8Ltr|:
Kh"VesW
Vzm&"1V
`44(U!.
`x&zu1P-cyb
3{4PctY
uAufG3
xVZqP+ht
k)~_k44
?$GxmUSehTa\a}+Y>U>:H6
r`*M5*S[k{
#Cl>LJR
eWCSNZ
jhi=g|c
&vEllSrU.`eL
]E=Y9JxwE[#aA0F=i
(-qJX{H[
J?#/@;2r7##
x#KCT3=P
H"vk:?YAke_K
$f%N_i
54DF]K
<>[JV0Qyo7\6r
BZ1,A_0ht
$-Iiio7|#
) H[WN
~da4k
Lf3s/a 4
sYsJO"
ofV6Gc
R{FId=
}@ [OI4=
TK6~Tvuqs
jd/$%eYh
1DU@v}
-sAuPz
S'{=W2p:$X`L
n.XLbFQ
sFs'F=Gr
Jq4M's
/).oYw}JOi>A
4TDmmU
Hhfe,E
kA\t:^B
f TmrG
.H %JXK|Cd}Z.
"= dL>i
[;TWAo.
#?g| ,N
+ MWlxk~*
}1|9!'Z
uX>j7cI
||ze*-I\
Vqe`u[O~
~fI=uu
s2f?^50h
'o1n_i
c,':9{1
|k@A9b{SG
JN3TE68
B"@T}R!
GIe8WK5
U[S&h`R
"t}/y`
o%'eBf
:|s(2QYW;>z^y?4
`\+X9!
piX50\.
pk~vTj8#yAKd)&.
Sw>[4*+
O>P+-~
7zYr%sV
wtutYo*s~Xl
:xO$j(
nG[&{=DB|6T?5
U#z#uQHqFA
jZ5_1v}
OxpGh=
wPRBEmQ^&>
ZiW:V$Q
DZ~P3l'
g&+uA82#X4'Q
oW-`sf
KG*Iq_wiIB^
>W ;?4\vF
0 T-T['
3eOoA/%hS`H%pt 0
Q)]5k5@\\e/>B>
!1YL/^
%_m1?&?^EA*HZ
8lZ}*![
\1RW2*D
NS/UKK
qELerdw^)>U \H
51TWZ5
Ml2T5ql
5~'HprJLsd=
6:" r?DPH
j'V2;?
`2}(6U{\
6$&=]0Do2+{
DTx":
dT&iv]H
RRN"RS3q%
%,[NSB+D>3$<
;rpFmg^#
-;}aqM`
Jl+R-D
-0=X:UK
,O}f.t
0z5>P*
x7<$KD
d-~/Ae+ @o
3aBE,aZ|R$s
[Vd/^uUO(
.j+m]c6k
{^kGWRMTBQ"+;`
Jw`c-j
z)hp6T
n7VTy8;^Y
i5^ldX
e6aAb|
dJDM_uo
G(+PH1
oa0>7Xxq7 e
$o4NZ/xx+
zs#q8yd/
;`l|k_Y
3b~i$<c
~wtlW_Mk
q(n\^7R0N+{
'=.SYmPKI}`
S Ym;U
xK)?c.0
!Li)!C
r_i@1mzA
d5;x)hr)Pm~%q@^o
jl4VP:
yaf3mH^E>b
+}k.M0
@nzv4(`
}vRjWfb
Ic[X8_x#i!p,r/Nm
)9Vpt>%"o=
PX,CeW1Rnm a
g>=n'D6
?sYV<8;oP7
pW{;>"?C
_S2+Cf'
I'N!"&
Qs}= Y
Uh6w4Uq`
Ih@Vb@K
roCYp*d
pDs{KL
<|: 865U
A3C;Bxi?{
Hb_0j~
2-urGEv!
#)Nl[}
l ,=Cq~
s+R]8X<
-h,9J6' d'1
i0z}q;!)o
\#[Cx?rPV8EP
sM4ch]>*${
,_9n"u@&2Aaz!
(v&VmMs
[ug-U|`[h
S~QE!)_
G*S)ut8
Y'2V>8.b+7pz;<)
y@FE\L
+ed*JR
PkA{EzO_
--m{8u~Q
J"D=|<Fb>.r'u
KAxYlW
JSdX5(;5E
I EDJ:-H
B*ZHHmD?
P?Q\N8/E
.FMH$!E
3N{aj\^
!rl:`v4--
/_`p"g
sA9l/M}bb>"
<`OT6R0"
rcpjl}{{mHO
x)ib*/
nq$;}(
~X%8T)M!vj7
DB2RT-
id>/{c
3IUJ#r8*
"Z1;>i
gq\dOWQ|<
V"$:3]&
u8YT,
Lh4"-Eco
X9F^J1-
C\1U=Qe
J1GB66
;8i`jD+'3(j
=D:AUW
KX\R]_mym3NS
;|&bJP}f
B P_M<nk
Ns[l;Bs
fmVn/=1(/
^A}0~<7~
TWvqSx`;@
947n^L$8
B=nLTd`wUkw
s(CfqU!6
'w?FnIO4_+(
&~Nz}?'Aa\)>*
#fZ:3f?O>Z.2:z0D
<}u%8k/BT
Z(Gt"^
6rY&/QF
UPlZ2}M?;w
"On*=6QOM8
<3!QZB,r6ok
mNaiO;uD0
9+0X,\
3!Z%R
yeVA['
i!k{#lR
9~f;s{
zSdB@}jy8d
8)#r!J^
-)RB-{
09.T2Oh
<T'4OGI
~e7X#^D"2
Yq;!gSB
&Iw&|4s
1kw#\;3L
S@RlSa hG&`g9}uw
kAA=^f0Ezm~
cg#4Lo;Qe
aap]"d
_'j`ix
)(k2>%4PX-
4mK$4%BSv*
d<i}X [
AM}4aK[m4
=Ks;"LY8
X<`jX-:)
= hjhHX5"<]Xja*c*2/}x{dO
@c!eQ^g.n
(~xpPp
jzp=-B
h]S|K?!XF
W&w$"Z
P"#c&H
-?r[Kvh*>
I[hI4N
O[$.\R
s.c@QdZ]
P*kc2<
EX.^Tx4$w
/c*uZ0
u<=%}4
Z9)ETo
nEk%7Q
{Riud,t~1
@W1"%zwd{uF>!>
)#!}Z|
bw'YmC
p/7@a'0
Y1M><>~!
3GT1P})
2(9`W}E
'[{8Wnn6Q?gp;M )W&1
+-W[n } vE.
p{u2ID(y7p
>9@CVc
P)6uEj
ayiQV!F\
gmnbf-8
*U?Ttx
j8[^B[f
3A=D49
[bt*anA1Z 20
\\RVl_'8^&g\]mk(]
N_:vL"N
AEvi}FJB
<"|\gN[0~7ER:&u
az}K2t?};
&n(P>:
I4[xyW%
?d00xwe
vkQXQAaU-8KC+8*> &4wY6
8yZL_8f l
Y1t%[#XH
t4)`os
0j!3rbQq
037SO5i[
pPIG+M{sX-x\
gTVbb*{n
}+NR)~
4)tmRM!
T45A)Q_
]g*B|j
0bsmV(:
C_5+[5DnZ#k
/R2\3]n]e
4\F\1/\?
*){;t}sn
(qy"Sw
8mc9?QN
-.3X|]mK|=
{.h<c=*
'"B-<DWu
&Y8^&EQF
>%F,=X
)bUC-SI(
1wBv6vcG
udq1LuV
Pa^%3-
=1QN/Z]c
I:Bd6v='q
reVr$uE
Vf[^AU|@
zd*jX3
&fp8o.SS;MK,
lRUPMyG
~37+w!i-M%Z
[;+Y>vHr
:*+Mupn,`a
Hf;}Db
H,i9eT
2Da}i[_
]zsfN-OZMuL
Bb"_$I
R']e:"
l$3BxBCi8J
W;O#RB+zG
B;nyzoP>
^[Pz v^h
o[MU*h%+q-5@k]
RCG(C^Kb
[EJ&n>%.
_7;[Bs2PAES>v
o(=7{j
uBiI=`j
1/xsB?)[>qg-R0
vU*=x<
jhmu?ue
R=IuRwQnZ
Tn:}}!@
SCJa}`$4wF
)Z7`0(
b@{M:8
+q|7"5
IWCx\v;@
MI<YW}
uRD!2Z8
,}){o|k
]V0q o=A
xLQn*!|
8N"B[o*~cNGm
{U !eJp8&
aVmZ-uJe
+n)}\43v%i&YXRis
D|oc#>
8oXo~
Iq/^v0,
m[6h`,VYJJ0
0M#aRwx42m<
mj%`X+)
)]5z:mM4
FzY$#y
4R%fHmVp
&!`,^8
8:t"xedOW#
)(}pq>+
t.*z!2"@ab
~Gu|yI
IiPMd~
pK7QdVpI(e
p pr3&@(
D2p'gI*C
/ve6ibZ6H*XH4$t^NEl"
8NZQHhxGIeI<
u-:Dnu
~Z,-0'9t?
nsn+B1gjYTfZm@
%~xs?{3FJ-sE
ZBn~r`_.3=vz
A=T*Lh
tRhuw~
HLB_WZ;
5~k2IDF)
b5uZ"kIK
>%):A,v
@Xq29Cv$Uq
V5i.?pa[ar,
D{z<p$
+R]RH]
GlZAW!mgHDb
,}v[[L
gzM`F[=OU]5Wn+9J6
W}0OTQxlJF3U~
EF5^Zm
1_@Grx2
c.;]tJ@KC
6`niO;
HKCb-m7
}g;'<s
X;5CO,
xhH!E'
BR`gl
LD"i)6
i21Q]|<$
QE}\lU
nN(rOx
E=L6e&~
1$KPF>x
SaG$8HT
&3W-Q|R:8s
wvmv5S
Ex%qne\o
cW(Db[
y .OAx
MLYVgDOP
td/bJ}5,
W^X ,i
kyLdRD1
bI=&xaFH
(bduaj.J
,$PgyAS<
AeSe)NRru0
oBwFAJ
Uf6sDdNev^eU&
L:8kWxc
Z{5}GpT
S!hJhC
:RXrduq,O
aCV$gS
7S8 :}
.&hI!3]fp9Y
a=;F2NjU
e1x+<>&x
x!/Pi<L
g&@I_Mvd
c'iV.H
CAHwSj$j
Zz@%&`B
8W5W\:ztk68\k;5l3DS
#@k@]:VZ[5`Q
diyZNJPAm}HEgbU
D)1xQx#*9
a3QF=nQ
"dPs#^
GQjC[Uh
f^tk_$Y?c
ido@n-4
)ywiF4/FF
IbSOSo
:,%^#UO<^
+x]2L7jx6
1BWv.r?MUN
.jS7.wBc
PvUC#8>z
aEAF-y
4GRT$[
{`]Rtnz
bI, T)_,&
t[[PMNP
aBoF r
TOXaKjt
_AD_\e
|FTA<G'?KDOJwD
Uvu}5u`W
B"=S?e0
=4Ih;U
a \HX$
`tXJbzn4O
J2JLP'
?bC8/e:
w,9o4A
e10~=Ju
m}w?tGm_
B_Es5p#q!
nbER9)W:408
\dGix&h8
fh_p#S7
H66iOkPNbE-
f54,Dk
#$D~7/
=)fU7p[
{LbtwT
a9#uxpu
dY:nURv,Pu
cw$@Y9
VE0R3Gb$
Q7,YF$
7-;O'9
b+1)U(!
nS#5,ck
(+vV]3.
rT/@b7
,~m@oV!
cm3}la;H6
(BT[A,
XH]!jdvNLOAB
|#amKfO,?
a&?C,t
0e{CpjdKZ
lNteZa3
,ZI5d@
U[!'")09fR
|?1@e*[6c5TJ
Outx@veL#JH
a>;d-E
Qx(6bexkc;H
pb|,~)U>88
]y3!O[ F
U%N~AKl
\@L."h
4Ml[=G|'
qIb#qXf
*0cXbG
j6tEOdg
-,cxU
=^cv<>R
_>,I{yo\
M>2+7z
H#`Y`]Z^L(
x(!Vn /U'
Pc`@:z0Ecgux`
E(e!qx
x1Htq U5rt
|UlcO1
_k#j^~
.`he`^>Q
DyOrnW
g~CaQo
(*H:@:rl
<U%UIv
4f/E2yspA!`(
@c?PkB
H~=+&~d"@k[
X2`468*
qe*o( *Z;
ZfWt !i
0l%1I\
k8INge
~=FdfsJD
^^SlC3s!
G@?igM>>
K#`#yQ
w+P_iK1
tPO')O7{t-W
RyobtK=!$w>S__>vV
y8E/w-J4P;
UI8@qUz=
`:|o9wKUvOdV-DNb
qX)^:aXBXv_
vlmZ.DZ
:(Rva~
w?U^An3p|.s2
._AAA*#
@?4r1&R0fn
dq[2W
qi<b%
vzB?UPS,w&
_V^]du`K
wy}S5n~
Ny^lGd
Lo<W*#
t=+d$P&VIUH
uByA28o:FA@l
v}ljZUm
<MImn
?nsQum-
)}a3^NBNNf8|]m
*t<?\3H
q`kyK'
gdMNX_
@#XY}RA%5
L$_~bt
Q|rTjlQY;[(_
kfBOFe
&KJX]":d
REI]LSu,
S`pN)Q
n%!{@DlT-
/!bB4o`V>
Fu}G-L
5g7gM/(wc^J0
;@UA|W
:rU4Nyk}[`w
_4w*P
Y4Q$]D
rUKc*n
G+?Z]g ,Fj([Y
6;1F}|>
GjM9!rX
>Luqr/
~@j{%/@ba
kh#Xp.ZR5Sch
IY'a8M2
b$T!JJP8]]ju9
0&;j]|@FG/
yBvK6.`
DVCLAL
PACKAGEINFO
MAINICON(

Process Tree


06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe, PID: 2400, Parent PID: 2948

default registry file network process services synchronisation iexplore office pdf

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 9e97c3bfd9a607ec_ielowutil.exe
Filepath C:\Windows\SysWOW64\DC++ Share\ielowutil.exe
Size 148.9KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9dab9038395178c5bbc25f296ab2ae99
SHA1 16752cc3509131fecf40db85bdf71ae9b62c90fe
SHA256 9e97c3bfd9a607ec4f8d83b49994bb4819ea29a9392c6813a5aaa1ac330cdd25
CRC32 E7C53063
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ed9e3615eb8ddd00_wmpconfig.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpconfig.exe
Size 150.9KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ead92e67747646472830a532ab760977
SHA1 86519472b14bc1dd0bc051f8fea65fb753311902
SHA256 ed9e3615eb8ddd00ecd53b73ec368ab63c13100ebb46332dd211f4cb5478cd13
CRC32 94CA8D7C
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9da656fb2e9d6934_convertinkstore.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\ConvertInkStore.exe
Size 188.4KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 54806921aca2cc3a8d8087f9a35baa6e
SHA1 c543429c7504e40bc6f0265c4a6720e909dd335c
SHA256 9da656fb2e9d6934ac1eb88f8cf83a7fe5b2c8478bd44573385eb80b4a3bc677
CRC32 5A5521C8
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name f25c7d871d38fb58_setup_wm.exe.exe
Filepath C:\Windows\SysWOW64\DC++ Share\setup_wm.exe.exe
Size 149.6KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a0dfd441947434c7f13f26fb2d123384
SHA1 dcba7bc3648c0ecd725543e258adf5e677790203
SHA256 f25c7d871d38fb58a6a564abfb6fd18f703c8186d0025bacf443e05a96829e6c
CRC32 CB07093F
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9cf81de319cfc7bb_wmpenc.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpenc.exe
Size 152.5KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b07995a42a9401efa785062f3f584fdb
SHA1 bbb06c574b560e9746814fee7691511fcf3c224b
SHA256 9cf81de319cfc7bb33c993a001a2ef6c49891c76182cc585c8d5d6e8f1d1a55c
CRC32 4CDA0B9E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e2a5ba511f2ffad2_dvdmaker.exe
Filepath C:\Windows\SysWOW64\DC++ Share\DVDMaker.exe
Size 2.2MB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 7fe421824ba7d15f3c51e8cca6aa3ef1
SHA1 25705abbdd0e3de16442e302677c4bbec7bdfb57
SHA256 e2a5ba511f2ffad226329b6f7e5445f6d687f79c5a226854cd7613179dbb3449
CRC32 F2E58F5F
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 00573a041f62035a_install.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\install.exe
Size 549.4KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d2fbdcb1a4ebb23b696a6c9b1c9e251c
SHA1 946bd0f5654fcc618ef7c4b01a2e6d2f1f609495
SHA256 00573a041f62035a64a0695a8cd3bb106740eee79acbbdb13160d31f685a5c5a
CRC32 5225A460
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 32bc5950c6295337_wmplayer.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmplayer.exe
Size 163.4KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 90bd395416fb36587ee02a72d41e9215
SHA1 6a49db051e05b8b01bcd4a22c40faa0abf096e7c
SHA256 32bc5950c629533701eff19fea83f687b4704b859b6846c415c619ec8d98e4e7
CRC32 444E0263
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name af6b2af3a848b01f_ieinstal.exe
Filepath C:\Windows\SysWOW64\DC++ Share\ieinstal.exe
Size 263.4KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 44d6a280f04c35a666d7796dc11598de
SHA1 95cd3ae5449c21e7813ae721751c8f2946044705
SHA256 af6b2af3a848b01f9f88843ff3f0598272775a566b425e5a2a5cc12638c241c4
CRC32 B70C9EC3
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 4e8893871a3de1af_iexplore.exe
Filepath C:\Windows\SysWOW64\DC++ Share\iexplore.exe
Size 678.7KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 97b803d992c258be6d635a521f3c4282
SHA1 ce1af15e4470e758f9e57694983f0a5a7f0ff118
SHA256 4e8893871a3de1afdff42be100c86c605ad90055b6b84434f43c21dcab09c934
CRC32 CE8E5931
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 806f73982ce36800_inject-x64.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\inject-x64.exe
Size 149.0KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e179b882810de66f4808723c0640364c
SHA1 ce95b4ac39fbace1ebeab0fa722a6c549d26d5b2
SHA256 806f73982ce36800ef412b1ecc7c4059b6a8c1d7bb058701620ed3973934425c
CRC32 4B975CBF
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 31825be86316393b_wordpad.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wordpad.exe
Size 4.4MB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 950401dc97a364a69775dfc958b5a20d
SHA1 cbd98fca00aabafba4e01f3fbfc1b745a0bdc854
SHA256 31825be86316393b36cfe37114d4fdd3d710e62210d12487024f3075ad49d858
CRC32 A6A11376
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 32c8c7693fc5ba02_wabmig.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wabmig.exe
Size 160.9KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ab9fe05ecc230dae94e711aac27a816d
SHA1 d09340259c69056fa54594991315a92324f1ac6e
SHA256 32c8c7693fc5ba02da0ff1b84d8df98d547a4b4b0210468d910a2dd0a3116996
CRC32 E31CA13A
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 08268216622ce824_pdialog.exe
Filepath C:\Windows\SysWOW64\DC++ Share\PDIALOG.exe
Size 159.7KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 a75306504b1b822ceed5f0469f87e90e
SHA1 ff2223287256a00455ff005e13556640fa3d6682
SHA256 08268216622ce824b663d1abe7308ead9058462acf5bfe72e07acb2a31cf2f08
CRC32 9E93EAF7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 461f77a0bd669ea4_msinfo32.exe
Filepath C:\Windows\SysWOW64\DC++ Share\msinfo32.exe
Size 369.9KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e6f1dc11594fb20758871949c96e37a4
SHA1 49abd61deec04c05e4cc5550e855bdb2e57e7b04
SHA256 461f77a0bd669ea4781db3e2e896c95a4f08fcf3e58031ed29a1df3d08d14042
CRC32 9E2712A5
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9b1dc642bc1db269_wab.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wab.exe
Size 503.9KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 aa37c9e8983f0a2b905664ba2b43be93
SHA1 e7b7493855833d98a92db31fcc3bf458a9322d9a
SHA256 9b1dc642bc1db269f3e2807d2ce9536f2819b2517f929db09cab0bb0fb92a3f2
CRC32 C1FB0B0D
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a1e88659a4ad4f4f_marijuana.txt
Filepath C:\marijuana.txt
Size 21.2KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 c0214c7723fe7bde6bc2834742bcc506
SHA1 f3d8e78975bf169fc1ed3ae95ad41d84ff6a36c3
SHA256 a1e88659a4ad4f4fd55f246ab076dee048881fcac3ea8a300e2fe8cdffd88b73
CRC32 0D0BD2E9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name b3b58203d214dccb_wmprph.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmprph.exe
Size 163.8KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 08ab7a45829c5aa2be15351f1cf0f5d9
SHA1 316be6ca72a41269e4be836cebe94c02482c32f5
SHA256 b3b58203d214dccb09afd5ce5d3baee229eefed5510d543e9d0f655dd5dffc30
CRC32 A7BCA4B1
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6ac5f0c1b1d5a3a2_shapecollector.exe
Filepath C:\Windows\SysWOW64\DC++ Share\ShapeCollector.exe
Size 678.9KB
Processes 2400 (06daa5b9246b38f6cc3c8e6b7cbf56b174d9a95127d8f5cc24c9f0382b81aa81.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 549a792e0fc8c112ff447bbc322be412
SHA1 69a9dcf0559fa8594c9ba3ff2612bec12cd27feb
SHA256 6ac5f0c1b1d5a3a21ec254ba69f384559e47d56f2425184b550fe9b51c42a2e2
CRC32 9A99D496
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.