3.7
中危

06cbc23ea4d7db79d272d4038e246b8792205575fb0e8cbac23761ab0b82ca22

06cbc23ea4d7db79d272d4038e246b8792205575fb0e8cbac23761ab0b82ca22.exe

分析耗时

134s

最近分析

387天前

文件大小

331.5KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN RANSOM GANDCRAB
鹰眼引擎
DACN 0.14
FACILE 1.00
IMCLNet 0.79
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Ransom:Win32/Gandcrab.8f07186d 20190527 0.3.0.5
Avast Win32:MalwareX-gen [Trj] 20200131 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20190702 1.0
Kingsoft None 20200131 2013.8.14.323
McAfee GenericRXFP-RC!B5218856537B 20200131 6.0.6.653
Tencent Malware.Win32.Gencirc.10b493ac 20200131 1.0.0.1
静态指标
查询计算机名称 (1 个事件)
Time & API Arguments Status Return Repeated
1727545316.76575
GetComputerNameW
computer_name: TU-PC
success 1 0
检查进程是否被调试器调试 (1 个事件)
Time & API Arguments Status Return Repeated
1727545312.79675
IsDebuggerPresent
failed 0 0
使用Windows API生成加密密钥 (3 个事件)
Time & API Arguments Status Return Repeated
1727545316.74975
CryptGenKey
provider_handle: 0x03d4b250
algorithm_identifier: 0x0000a400 (CALG_RSA_KEYX)
flags: 134217729
crypto_handle: 0x03d60e60
success 1 0
1727545316.74975
CryptExportKey
crypto_handle: 0x03d60e60
crypto_export_handle: 0x00000000
blob_type: 6
flags: 0
buffer: ¤RSA1#¥ Yš ¨ó¾Ìêïpý<1&é½À=»#ù&tí‰ÇGfݟõº3[a×²˜¦•§oÄø7Íû:iNP3°.èíÿs¶°† ÷ˆÍ’“Æ:.„ãÙ Ã*U EA1¬Š¬J‹ÞY.¤¡VײäkNGI–8ùэô€gÌb¹ˆÉK‘þ\˜Árø{›â5 lÕ@+RÈô÷`"TC2Z"¨ iHð^֗è¯ÞXµ–þ—1V‘Çwoü¦¾!ˆ÷‡˜nì$Îò!™Ó#1ä¦ ßE“?ø¼\gµ{9öl`ð2¡œ`>4-–%ð‹Î*ÛHôîN€A|”­ÿá
success 1 0
1727545316.74975
CryptExportKey
crypto_handle: 0x03d60e60
crypto_export_handle: 0x00000000
blob_type: 7
flags: 0
buffer: ¤RSA2#¥ Yš ¨ó¾Ìêïpý<1&é½À=»#ù&tí‰ÇGfݟõº3[a×²˜¦•§oÄø7Íû:iNP3°.èíÿs¶°† ÷ˆÍ’“Æ:.„ãÙ Ã*U EA1¬Š¬J‹ÞY.¤¡VײäkNGI–8ùэô€gÌb¹ˆÉK‘þ\˜Árø{›â5 lÕ@+RÈô÷`"TC2Z"¨ iHð^֗è¯ÞXµ–þ—1V‘Çwoü¦¾!ˆ÷‡˜nì$Îò!™Ó#1ä¦ ßE“?ø¼\gµ{9öl`ð2¡œ`>4-–%ð‹Î*ÛHôîN€A|”­ÿáÁi`*´Ö×…*á×ù/ò¨ÐHQÀ½Zç%Ú{ž®#’•V³£?ÆÚ_žäi±-”!ϔUâ¼ÆŽ< u«gSf4 Á“­”`ÝÖ!/h€‘ðˆ–Uàæ¼ÏrX\›L‹4]ªíÀX¯Â¼³ÑK¸®kЦ7ÇE”Cõ~ˆøãŸ!Â#Ö¡g:™¸ÐÆg»à$çi¢B‰/¸‚ªöê`TC2òqü“ô-IJån„9`÷ï ¿îñeeÜb{ jœR7+•OöîPZk’ɨþ?“¸ùÊHÝX"÷N/+E K×èÛñLæ×mʹe9ª\ÝÂ4êL† 5ÙÒÝÉè$ G0^3ûwã‰~ó€4ID-ÔÞœ©vÎ7ՀÅsÿ¦—Û2Žb…¥Êv5Õ}@§oÊU¢Îóæä©7ÜHhV=p0çâSMðÊé Âñ‘Ž¥È2"ïݶŠ >hÛë­Ö`¼_b»xJ£ul_šó±¹ªŠœ¯/ ï+©¾ó— †oªð׿ju‹æ¹fÁJð€@­ÛãoèºÕ5Ã}f]'4º’^¾ëÀ“ÅyÕKK^ÂèÉWl…–d[,4#AHazÍg|ÒQŽI§@ðCºb¿:(­MfÅYè-“ùHVµP~›_~Ãr(rÁ̃I@žw™ßžxXû4ö?^”ž¶+F–OeP—‚s1÷°·S›uÌ\V-iüàô)nlšsîrÕïPÜSÑv PY–q=¢°E$®‹»u¸wñWÓLj&p3N`Þd®y8啕æ”l´ á"EwÍ«èy©•íyä¸G´MÕ%=fèp)Y;Z4*`Ä|¬°'xɦ"äTÑkùÑÄDüÚõw1zêýŠÈù÷9RùóeÖ ¯EfÐ]coK§¯w‘¥Âø¦ˆzUx'ÛÅû4¯™iNÓ2ÈøÈ]N®sR„¼;¢òài0ƒÂ ý–L0¾Ÿï`ܘPÇE%3T°ü¬oL/GMõ>Ç>]Ç4Åyì“)èwiÚÊDè0Ótöq?DP×)Xè‹æQcQ+ÛP¸=tù¢•L›Eh꫎ºPm 'ÎKÉôþ<%†óŸ¬–°}ÛÕ%ÀPk·z¹Šn¨!{2Ʊ³Ùªþ¸M¥”µÉâM
success 1 0
检查系统中的内存量,这可以用于检测可用内存较少的虚拟机 (10 个事件)
Time & API Arguments Status Return Repeated
1727545320.999625
GlobalMemoryStatusEx
success 1 0
1727545332.328375
GlobalMemoryStatusEx
success 1 0
1727545343.688125
GlobalMemoryStatusEx
success 1 0
1727545354.969
GlobalMemoryStatusEx
success 1 0
1727545366.265875
GlobalMemoryStatusEx
success 1 0
1727545377.57775
GlobalMemoryStatusEx
success 1 0
1727545388.858625
GlobalMemoryStatusEx
success 1 0
1727545400.1555
GlobalMemoryStatusEx
success 1 0
1727545411.453375
GlobalMemoryStatusEx
success 1 0
1727545422.76625
GlobalMemoryStatusEx
success 1 0
可执行文件包含未知的 PE 段名称,可能指示打包器(可能是误报) (1 个事件)
section .gfids
文件包含未知的 PE 资源名称,可能指示打包器 (1 个事件)
resource name BTGF
行为判定
动态指标
分配可读-可写-可执行内存(通常用于自解压) (20 个事件)
Time & API Arguments Status Return Repeated
1727545312.49975
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00330000
region_size: 110592
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545312.57775
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00400000
length: 180224
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545314.34375
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00414000
length: 81920
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545314.34375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03bb0000
region_size: 94208
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545314.39075
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00414000
length: 81920
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.39075
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00070000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.39075
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x000b0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.57775
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00100000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.59375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00130000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.71875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00160000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.71875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00160000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.71875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x000d0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545315.71875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x000e0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545316.82775
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x066a0000
region_size: 12288
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545316.82775
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x066b0000
region_size: 12288
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545320.59375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x066a0000
region_size: 98304
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545320.59375
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x05900000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545320.60875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x07000000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545320.60875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x07000000
region_size: 36864
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
1727545320.60875
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x074a0000
region_size: 8192
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 3012
success 0 0
查询磁盘大小,可用于检测具有小固定大小或动态分配的虚拟机 (1 个事件)
Time & API Arguments Status Return Repeated
1727545316.78075
GetDiskFreeSpaceW
root_path: C:\
sectors_per_cluster: 8
bytes_per_sector: 512
number_of_free_clusters: 1782526
total_number_of_clusters: 8362495
success 1 0
在文件系统上创建可执行文件 (1 个事件)
file C:\Users\Administrator\AppData\Roaming\Microsoft\rdudud.exe
将可执行文件投放到用户的 AppData 文件夹 (1 个事件)
file C:\Users\Administrator\AppData\Roaming\Microsoft\rdudud.exe
搜索运行中的进程,可能用于识别沙箱规避、代码注入或内存转储的进程 (1 个事件)
检查适配器地址以检测虚拟网络接口 (2 个事件)
Time & API Arguments Status Return Repeated
1727545317.01575
GetAdaptersAddresses
family: 0
flags: 0
failed 111 0
1727545317.01575
GetAdaptersAddresses
family: 0
flags: 0
success 0 0
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': '.rsrc', 'virtual_address': '0x03783000', 'virtual_size': '0x0001db6a', 'size_of_data': '0x0001dc00', 'entropy': 7.757278339636987} entropy 7.757278339636987 description 发现高熵的节
entropy 0.3600605143721634 description 此PE文件的整体熵值较高
使用 Windows 工具进行基本 Windows 功能 (4 个事件)
cmdline nslookup carder.bit ns2.wowservers.ru
cmdline nslookup carder.bit ns1.wowservers.ru
cmdline nslookup ransomware.bit ns2.wowservers.ru
cmdline nslookup ransomware.bit ns1.wowservers.ru
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
检查 Windows 空闲时间以确定运行时间 (50 out of 156986 个事件)
Time & API Arguments Status Return Repeated
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
1727545307.45275
NtQuerySystemInformation
information_class: 8 (SystemProcessorPerformanceInformation)
success 0 0
在 Windows 启动时自我安装以实现自动运行 (1 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\hxgnsinultz reg_value "C:\Users\Administrator\AppData\Roaming\Microsoft\rdudud.exe"
文件已被 VirusTotal 上 61 个反病毒引擎识别为恶意 (50 out of 61 个事件)
ALYac Trojan.Mint.Jamg.C
APEX Malicious
AVG Win32:MalwareX-gen [Trj]
Acronis suspicious
Ad-Aware Trojan.Mint.Jamg.C
AhnLab-V3 Win-Trojan/Gandcrab02.Exp
Alibaba Ransom:Win32/Gandcrab.8f07186d
Arcabit Trojan.Mint.Jamg.C
Avast Win32:MalwareX-gen [Trj]
Avira HEUR/AGEN.1031253
BitDefender Trojan.Mint.Jamg.C
BitDefenderTheta Gen:NN.ZexaF.34084.uyX@aGqe7zi
CAT-QuickHeal Trojan.Mauvaise.SL1
ClamAV Win.Ransomware.Gandcrab-7145847-0
Comodo TrojWare.Win32.Chapak.GDE@7oo149
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.6537b9
Cylance Unsafe
Cyren W32/S-4dff6f6c!Eldorado
DrWeb Trojan.Encoder.24384
ESET-NOD32 Win32/Filecoder.GandCrab.B
Emsisoft Trojan.Mint.Jamg.C (B)
Endgame malicious (high confidence)
F-Prot W32/S-4dff6f6c!Eldorado
F-Secure Heuristic.HEUR/AGEN.1031253
FireEye Generic.mg.b5218856537b91e4
Fortinet W32/GenKryptik.CNAR!tr
GData Trojan.Mint.Jamg.C
Ikarus Ransom.Win32.GandCrab
Invincea heuristic
Jiangmin Trojan.Gen.uh
K7AntiVirus Trojan ( 005332f91 )
K7GW Trojan ( 005332f91 )
Kaspersky HEUR:Trojan.Win32.Generic
Lionic Trojan.Win32.Generic.4!e
MAX malware (ai score=84)
Malwarebytes Trojan.MalPack
MaxSecure Ransomeware.GandCrypt.Gen
McAfee GenericRXFP-RC!B5218856537B
McAfee-GW-Edition BehavesLike.Win32.Generic.fc
MicroWorld-eScan Trojan.Mint.Jamg.C
Microsoft Ransom:Win32/Gandcrab.G!MTB
NANO-Antivirus Trojan.Win32.GenKryptik.fdcwqh
Paloalto generic.ml
Panda Trj/Genetic.gen
Qihoo-360 Generic/HEUR/QVM10.2.331D.Malware.Gen
Rising Ransom.Gandcrab!8.F355 (TFE:dGZlOgU3twQ7uXAcXQ)
SUPERAntiSpyware Ransom.GandCrab/Variant
Sangfor Malware
SentinelOne DFI - Malicious PE
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2018-05-31 12:28:44

PE Imphash

805e23248baf0c92d7a987ad2def7236

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00022cc3 0x00022e00 6.6612191118030974
.rdata 0x00024000 0x0000e5fe 0x0000e600 5.563545856156498
.data 0x00033000 0x0374e220 0x00001600 2.7953545750004776
.gfids 0x03782000 0x00000188 0x00000200 3.1169816164224677
.rsrc 0x03783000 0x0001db6a 0x0001dc00 7.757278339636987
.reloc 0x037a1000 0x000020d4 0x00002200 0.0

Resources

Name Offset Size Language Sub-language File type
BTGF 0x0378391c 0x0001a96f LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x037a0b28 0x00000042 LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

Library KERNEL32.dll:
0x424000 VirtualAlloc
0x424004 GetLastError
0x424008 PulseEvent
0x42400c EraseTape
0x424010 GetSystemTimes
0x424014 lstrlenA
0x424018 LoadLibraryW
0x424020 AddConsoleAliasA
0x424024 ReadConsoleW
0x424028 ReadFile
0x42402c WriteConsoleW
0x424030 SetFilePointerEx
0x424034 HeapSize
0x424038 GetConsoleMode
0x42403c GetConsoleCP
0x424040 FlushFileBuffers
0x424044 SetStdHandle
0x424048 WideCharToMultiByte
0x424058 MultiByteToWideChar
0x42405c EncodePointer
0x424060 DecodePointer
0x424064 SetLastError
0x42406c CreateEventW
0x424070 TlsAlloc
0x424074 TlsGetValue
0x424078 TlsSetValue
0x42407c TlsFree
0x424084 GetModuleHandleW
0x424088 GetProcAddress
0x42408c LCMapStringW
0x424090 GetLocaleInfoW
0x424094 GetStringTypeW
0x424098 GetCPInfo
0x42409c CloseHandle
0x4240a0 SetEvent
0x4240a4 ResetEvent
0x4240b0 IsDebuggerPresent
0x4240bc GetStartupInfoW
0x4240c4 GetCurrentProcessId
0x4240c8 GetCurrentThreadId
0x4240cc InitializeSListHead
0x4240d0 GetCurrentProcess
0x4240d4 TerminateProcess
0x4240d8 RaiseException
0x4240dc RtlUnwind
0x4240e0 FreeLibrary
0x4240e4 LoadLibraryExW
0x4240e8 HeapAlloc
0x4240ec HeapFree
0x4240f0 HeapReAlloc
0x4240f4 ExitProcess
0x4240f8 GetModuleHandleExW
0x4240fc GetModuleFileNameA
0x424100 GetStdHandle
0x424104 WriteFile
0x424108 GetACP
0x42410c IsValidLocale
0x424110 GetUserDefaultLCID
0x424114 EnumSystemLocalesW
0x424118 GetFileType
0x42411c GetProcessHeap
0x424120 FindClose
0x424124 FindFirstFileExA
0x424128 FindNextFileA
0x42412c IsValidCodePage
0x424130 GetOEMCP
0x424134 GetCommandLineA
0x424138 GetCommandLineW
0x424144 CreateFileW
Library USER32.dll:
0x42414c DrawEdge
0x424150 PostMessageW
0x424154 DestroyCursor
0x424158 SetWindowsHookA
0x42415c GetWindow
0x424164 SetMenuInfo
0x424168 DeleteMenu
0x42416c MapVirtualKeyW
0x424170 GetLastInputInfo
Library ole32.dll:

L!This
"k%m cannot be run in DOS mode.
Ws6 6 6 3H 6 3J
6 3K 6 h!6 h!6 h!6 N* 6 6 6
h!6 Rich6
`.rdata
@.data
.gfids
@.rsrc
@.reloc
u_^]ND
]u/WMB
]u/WMA
]u/WM@
F F$F,F(F0
DF<_^[]
fF F$F(F,F0E
Bu+_RQM
BD:GHEB
AD9_^VVA
\SVWe}3
u|D80p
toFhDB
UVq4Fh
SVWeuE
u*H;s(+
^]UM$DSVW} t
+;s!u+Mj
Pu ERPS
AQuw_^[]UHSW}
]tn9ujVj
[]U8SW}
]t[9uWVj
[]U8SW}
]te9uaVj
U,EP=-
`SVWeu
~0_^_F0
^UU 8SVW}$t
tN~JM
+;s!u +Mj
Pu ERPS
@PuqME
AQuK_^[]U
QSVWeE
r#H#;v+Q3
t!A#H]
s"RW)M
tjwx9~
s3QWPtSu
+SV^[]
+SV^[]
+SV^[]
Au+_QR^]
3QRU^]
Au+_QR5^]
PEj@P_
VW&0_^]
VW0_^]
AQu_^[]
PEj@Pl
VW34_^]
VW4_^]
VR$_^]
ERPSVu
AQu_^]
F;u_^[]
F;u_^[]
Au+_QR^]
G8G0G<
s#QWYU
Au+_QR^]
Wu}F0N<
UQSVWS
;w<G,+M
V3~vW=xAB
F;|_^[]
A0)0A
SVWh(CC
EPEPEP
v8=|AB
[_^]USVu
[_^]UQE
u^Ujh;B
Y^]Ujh
Y_^]USW}
YY]UQj
^_]UQj
YMg]UM
M]USW{,t
YY^]VWj
339E$WWVu
tFVSuuu
t,WW9}
WWVSWu
e_^[M3
Y]Ujh;B
Y^]U 4C
3@^]USVW3
jU4h\B
_^[]U}
]3]UV5
t"3PPPu
^]UQVu
jA[jZZ+U
_+[^]Uu
(;u3^]
+PQiYYt'x$
H]SVWj
t7t3t/%P
:Y_^3[j
t!>td,
u$V54C
Vu154C
V/YY^]
SYYE=M
Y__^[]QPd5
3PuEEd
3PeuEEd
MEineIE5ntel
EEEEE|2j
u3u/4C
3[]3@39
|xffftfpflfhE
@jPEVP
^[]UDjDEj
X]hor@
8csmu%x
+SVW4C
1E3PeuEEEEd
Y__^[]QU
ME3M3M3;u
;r_^[SV
;r_^[Uj
on0v00f
on0v00f
on0v00f
u r#
Jut0
HuYUW}
Au+SVY
^]U S]
E[]UQSVu
UQQSVWd5
p$^]UV2
u3@]3]UQSE
k 3@[]U
SVWE3PPPuu
E_^[E]WVt$
on0v00f
on0v00f
on0v00f
u r#
Jut0
t{8csmusx
EPYYE)
3@EEu u
~"];D;
?csmuP
u,AVu$6u
WP_]UE
8csmu6x
3AH ]3]UDS]
>csmu+~
ME>csm
MQMQPu WU
EM~.Uu
u u0uWu
uSV,UMEB
u(u$u PWu
VNYYMh<
u$_jWu
t1?MOCt)?RCCt!u$u Su
;F|c;F
u$Nu Qj
M;r^[_]
EME~;F
u_^[]
;7|2_^[]
W_Eo3@
PQiYYPV_
eE34UE
8csmu!
9p u":csmt
t]:csmu9z
E$Pu u
R 3@_^[]UU
3@_^[]j
tJ2t#2t
B_[US]
8_^]-U
Mxf~UE
8csmu7=vB
E_^[]h4C
3;tit
j Y+3;3_^[]US]
^_[]UVhwB
|^]^]%p@B
^]UVhwB
^]UVhwB
^]UVhwB
V3j Y+
j Y+33
uYj54C
3BVj(j
VW_^]M
^SVWT$
URPQQh@@
t;T$4t
;v.4v\
UVWS33333[_^]
33333USVWj
_^[]Ul$
USVWUj
P(RP$R
UPjh0@
t:|$,t
;t$,v-4v
UQPXY]Y[
0ffffffE
>YM3_]
3PPPPPy
V3VVVVVf
^UV3PPPPPPPPU
MEEEPu
;u$0u]E
M0t,0<
O;u;tQP
X%uEuVP
USV3W}
USV3W}
t!},t%
MM]]EU,0<
Ut^;sZM
;ur%Ew
3E@}VWS
E]Pv,F
E]Pv,F
SV3W8^&u:Fd
F(EF,E]}t
BIUMUM
SV3W8^&u:Fd
F(EF,E]}t
t&uEPEPWS7
Z Z$Z([]
_Cd^[]
^ ^$^(8
^ ^$^(F
0YY]38M
UE33@b
+]+]KG
UE33@sa
YPVWSu
kPVWSu
uEUSuu
U]eMj@Y+
U3#E>_
mYY]38M
3SVW8A
B,;utZss
G;utO,ss
0,C,43
PP0SP6
@F;ut4s
A;utZss
uC3P,Ph
P,PS=,@;
@A\;ut4s
3P,P0h
3P,P0h
0,C,S3,PP0h
C03PPh
A;utLss
F;utOss
PPSP5+
@A\;ut4s
ssYCs3PPh
A;utRss
uC3P\Ph
P\PW#\@;
*3P\P`h
u|P\P`h
3P\P`h
`\A\R3\PP`h
t+;v!j
+;w9r0K;t0;`u
2*3PPh
3 ;vI+t%33@A
M_^3[w]
SV3W3r
Ft2E;uu
_33[]VpAu
}tDEF@E4d$
^_33[]
t)EMMe
M3UMq=
]]EEwPr
uMt;r)w
;Ev"E]
M33tUE
Eu]M3;wGr
9}s@t5u
u]UEHEu3U
Q V3+;
^^wUQQVj
2^@tFl^^;^H
Et3g~%i
^ ^$^(F(
E3PR]gq
^ ^$^(F
ItPLt>Tt,h
zu;@A
F F$F(2
V3uV,Uu'F
F(F$F F
?]tfSF
tX-u=;t9x
]t1X:v
]:t&uuT
8]uM[F
X]3@]j
Ej?XfEF`P
EPEP$l
EEEEEPRCYY]
uo;u*x);v%[
_^M3[pd]
;uj^L
USVWN@
F4+~8@_F4^[]
UQQSVWN@
ARSF(m*
F4+~8@_F4^[]
A A$A(fA0A8A<@
uI90t8
UQSVMWj
EN(^$^0^ ^,^<8
f<Pt8F
ItOLt>Tt-h
<Xu]A,
Klt*tt
UQSV3C3
Mt?g~1it
V 3WfEE
E N1xt
t'D=0Xt
^$+^8+
X]3@]j
UQQVWN
F(~@S]
v4YYF1<gt
v4YYF48-u
N @@F4V4
PLPF8SP:^
USVv,FY
HPXF F
@?H3;F F
~(X^4u
ESVW~<
t]F8~V~43
u&9Et!v
_^3[iS]
UQQVW}
#f;u\E
EYY_^]
YY^Dz8QQ
HLMMQP
HLMMQPV
f;u+SY
3PPPPPj
HLMMQPT
HLMMQPT
HLMMQP]T
~+8]t&M
~@8]t;M
M_^3[yI]
t'@-rA
YYtVWh
3EWWPp
tU"tPj
uYYt/ju
Y_^]WWWWW
]EPSWSSEPr
SSSSSCuE
EMQjWuP3W>r
3^_]w*
P<$f<$
A;u+;uZ
A;u+_^]
q3U;Mt
q3U;Mt
;Uu+;uf
;u+_^]
sKEPS!
3fEEEx
3]AEfEUEEj
3M3^<]j
j Y+33
j Y+33
E}PE}PWWS
_81EPEPE
Y}VY_[^]
F@>\t>"u1
UQQSVW}
PYYtm]R
PYYt0WuV
Y_^[]3PPPPP'
YuVY_^]
;uM_3^3]
P^Y]h9A
MEEEPu
MEEEPu
}]j Y+33
j Y;EtMME
_3^M3[X1]
}j Y+3
j Y+33
YY]h06C
Vj 3Y+354C
VPzVV[
YM3^-]
t*t <"u
G;uM_^3[,]
u3M_3^,]
MEEEPu
Wf83Af;:u
3]SjUu
3PPPPPu3
_^]VVVVVt
UQQSVW}
j.Yf;u-F
MMj,Zu
j.Yf;tyPVj@W:
@sh_tcPVj@
f;uCPVj
u#j,Xf;
EW3PPPPP
_^[]SSSSSs
3M_^3[
jUHh(Hl r
f>Cu43f9~
3PPPPPV
PVQ |x
WWWWWo
US3V9]
|_^[]SSSSS{o
EEPEPEPE]
F00EhB
M!EEE0hB
v(YF$t
^(F _^[]S~YN(t
v(cYF$t
v$LY3F$F
F(F F@3PPPPPbm
f;4u+;t
D4s3f9
PjUHPh
f8f;98u3f8
t,PVWn
WYM_^3[
]&3PPPPP}j
,@PjUHPh
3M_^3[.
f;18u5f8
f;Du+A
<F 4F$@G
u9t(t$
8L(DPPPPPf
^0e^]W+
SWrt!}
t0;s,E
AuVSYYt(u
SWJt#E
YYu38]
j:Xf;s
u0jAXf;w
jZXf;v
j:Xf;s
u0jAXf;w
jZXf;v
AuVSYYt(
VWet!E
Mmr3EE
<xt"<Xt
EQPjjM&
M;ur%w
3A}VWP^
MEEEPu
MEEEPu
MEEEPu
MEEEPu
t(vL;o
PqY8W55C
SY+W55C
_^[hFbA
j Y+33
MEEEPu
EPX]hxB
3;tit
j Y+3;3_^[]
MYYM3^+
t'u(u$u u
Y.V~Yt
YYu3^]j
u;tt>}
tVWLYE
WIYt!E
CE;u_^[]
H$fE3fEEPj
EAEfEEj
EPQEPEj
3^[]Wu
^0jESu
M1\E39
|j*^0}
MuQVWSj
j"^0DlUj
#W;uC;u?
U0SVW}
Hj"_8A
uR;uNSu$SWu
38] j0
j0XEM~S
OMEfyfxW
v6j0F[
Wj0XPV
Pu$u Vu
j"^0]>_^]Su$M
-jd_;|
33PPPPPn=
+MQWPV+
|*;}&t
FuFu(Ej
Pu$u Wu
S _^[]
XM3[+]
A3PPPPPJ:
UQQVW}
EYt"uSWu
u,Puu u
Ueu,t6
<t[<t?
tCf6f%
VWlCv8
}]r\SPlC
^Yt)t%C
YYM_3^][
3GY3Au
fEE;}++
u(EE$uE&
MBE3WWu
e_^[M3.]
tAP|PQ3
PIYYt*tVu
V1ttZj
PYYttVu
M_^3[]WWWWWX)
339E WWu
e_^[M3_]
}$39E(j
}3PPPPPWSu
3QQQPu
3PP9E u:PPVWPu$
u.WZY3SQY
e_^[M3S]u u
M<u(Eu$u u
t&UAMu
SW+QPEj
Fu+(VVVu
0:@t,;v!}
j"^0y#
jP^3fLGM
V3EuW}
+CEPVSQSWVr
EPVSQjWVr
Y]SVQMQj
E@GE;|E
fu0MQVVVjWVp
M_^3[]
^0P ku
E@t5;v'}
MEEEPu
j Y+33
uk;u6@p
ff#f;u3E
MPQRyf
t*f u!f t
ZmZ,$Z
$%YYuJE
tSVWjA_jZ+[
uBjAYjZ+Z
ft:f;t3
tVEfE*?P6M.j
Au+MCE
_[^]3PPPPP
sY^[_]3PPPPP;
WWWPWS
u-PWWS
M_^3[p]
u7_qY_^
MEEEPu
A;rM_^3[
wYMEIH;A
3SSVWh
W>lY_^[]
E3HHEP
uEEEPj
wHuhkj
BaYuwHu;5<C
V1kY<C
C9]vQ}
kE0E7C
uVY3_M^3[d]
W3f9:t!V
f9:u^B
3tVVYWWWW+SVWW
Et4PhYt
3PPuWSVPP
VShYYt
;u2[^M3_
^0_^[]
^03^]S+Wu
3jPfTAX3f
cj"zU](UQQSWj0j@[3
;t>Vw Sh
}^S0eY_[]
0;uVdY_[^]j
PbYF ;
PbYF$;
PbYF8;
PybYF<;
PgbYF@;
PUbYFD;
PCbYFH;
P1bYFL;
PbY^]
3VWM]M9
VkaEPbaY
E PjPWEj
E$PjQWEj
E*PjTWEj
E+PjUWEj
E,PjVWEj
E-PjWWEj
E.PjRWEj
E/PjSWEj
EHPjPWEj
ELPjQWEj
t)]S@SS_EPJ_EPA_
u"<;uF
^s||^YYEC|3
3VW]E9
3FjPVu
]3Wu]YYu
ut]3Y@F
]WuK]YY
t%uXMYu\MQ\EYYuU
<0|o<9
u}uM3@
;\YYEC|3
_^[]<;uF
Y;u_^[]
WVuEwYM
j8^huEE
Pj(WEj
Pj)WEj
Pj(WEj
Pj)WEj
PjWEj
Pj WEj
Pj WEj
WVbYYu
VVWY3@%j
3SVWf9
u_+^[]
3SVWf9
u3_^[]
H(^y6C
teF|t^8
PlU3eUYYE
EuV0UY_^[]
VVTYY^]
H(^y6C
-V0YtW
tWY3_^]
_M3^;]WWWWW
f;Eu+3
|j@PNd
S|PvT$3
j@|PF`
|PvPYYu:NX
u^9^\t/v\|PvP@H
f;uyFX
|PvPYY
VX9^`tT
f;xu+A
3PPPPP
9^\t|NPY
f;xu+;N\u\WV
Yu$^P3
f;uvP+lY;t\NX
f;xuY3
f;xu*FX
[M_3^*]
PvP>YYu6S3
M_3^i]
SSSSS8
f:f;>u
f:f;>u
Pt+E7Q
@M3^*]
3WB3xNStH
UQQSVW
u2Vj@hB
f;Eu+A
tJj_S^
3_^[]3PPPPP
PsTYYu
M_^3[E]
UVW/3JTq
USVW3j
f;u+3}
USVWH3j
PsPYYu
u+;K\uw
PsPYYuh
9C\tKPA
3339C`u99C\t4
PsP@YYuW3SVb
PsPYYu
9C`u5Wj
PsPaYYu
f:f;>u
f:f;>u
r3@]3]
UQVW;u
30;ut(}
fuwP+Y;t3@_^]
;~2_^[]
3M_^3[P]3EP
t^WjU
_=fM3?t2
YfEm}fE3
PDPEAYY
jA_M4XB
jUS@YY~
3_^[]3PPPPP
MEEEPu
EEPVYY
MQPEPu
E9Erf}
M_^3[|]
Yf;u(F
D0(tAr@L
M_^3[,{]
M_^3[>z]
M;rSShU
QP+PPSh
tiVY}e
}VY//
u.!8.
VYt9t"
uEWVPuEWVPuEWVP
3QMMMMQuWP
`-0<P3-Y3}
+E[M_3^
|?k0YY
UQQ3!EfE}=`
EVPu(Y
UQQ33fEM}=`
U SVW3}}}}}}}u
U SVW3}}}}}}}u
3j X+V
P,P0SP)
XA\PP`SP
3@j Y+
P,P0SPE
ti0<;s
P<3@5C
P\P`SP7
@A;ut4s
u]3\P:3\PP`SP
P,P0SP
F;uR;,
@A;ut4s
,ssN0,e3P,P0SP
3P,P0SP
,tw330j
0,&3P,P0SPG
\P,P=YYj
`\B3P\P`SP
0,&3P,P0SP
\P,PYYj
_+30;r
YM3.[]3PPPPP
PQW|PEPr
6uYM_3^BY][
^]S+Wu
U]DU$4C
M_3^kV]
;w_^M3[T]
_^M3FT]
;r^;t3
++;|9;s
T[M_3^
Q]UV3PPPPPPPPU
j"^0& 3f
;r3_^[]
tSVjA[jZ^+
SV3W9u
+jAZjZ^u
tEft@f;t9EP
MEEEPu
EEPV}YY
d1(_^]
F+_^[]
D8(HXt:fUf;u
ZT8,;f9Eu
SED8(Ht5FL8*
[+_^]j
totkE]j
E:Eu>E
t)t%E]j
(t]EPu
EPEPuu
P-YVY^
EPEPuu
PUxYu3]
~R<$tLD$
=:^]3PPj
$f;u7%XHYY
VSXEYY
^[]UWVSM
[^_%@B
3SVWH<
B(;r3_^[]UjhH
1E3PEd
Y_^[]UE
33h@@
+SVW4C
EPeuEEEEd
<WVU33D$
#3+#I#[
B:t6t:t't
B^_[SQQ
wuro piyenazizofo conaleseyimucayedupoxiyo go nicemibehahasepawudehukusi dadagarateriso vuhihiculicoyamiyobewijayerosoro %s %d %f
Unknown exception
bad cast
bad locale name
iostream
iostream stream error
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
string too long
invalid string position
Bm4gm@L~Gm@p
bad allocation
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
unknown error
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad array new length
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
%{pk>_
EZ%qVJ
d8L2WBJa"=
[aOni*{
+4/'Pcq
)[f.;}eSw S
gV :6
ipev &g
f) }m?
:@O?owM&
juvD,GA
~ $s%r
@b;zO]3AOmm
-G 8NhU]i<
@;*xh2k
zKG-wn@
-Ciu+-,W
Ly;-"m^8{
yrvxyN
\lo};obwQ4Y+X<XF"
|WYu&Sgw
E]B.4o?nz(wKgg;
H[=J6RMq!
;<(wXC=sF|bt
P,=87Msgm
Ob{!@f
wdq=v/
3v2!L.2
@@w,=q/
ycg6fvPb
ut^6n16B(
.=k=yICyJ"p
BncW[5
^<V7w8=O
oi^,dH9
H'W&|.
IND)ind)
`h`hhh
xwpwpp
(null)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
EnumSystemLocalesEx
GetUserDefaultLocaleName
IsValidLocaleName
LCIDToLocaleName
LocaleNameToLCID
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
k?wNo?
1#QNAN
1#SNAN
?p9t^<=
Ohe??0=
?X&eBE=
rr?\3#.J=
3:?LtmYE=
@'z+?"e
tLVv?p$M=
`dH?h6_~(=
YL?wJQ\C=
0?e37.=
`I?)-W0=
D?7Tf(G=
C?]u<=
g?Z}=\uI=
s~Q?g:"(N=
q?n1%=
`X:?q.W =
/?1w<=
>'eH?`
pt4z?
l?i.Eg<
Ht=c?Az
h<?z)t
n]vQ<)8
|)P!?Ua0
`7E?'a
MkK?*b<=
|S?KT'K=
p^BY?E&=
Eb2]A=
c?e2a1=
0h?[2ieO=
E`q?}e
r?}~:fE=
PSs?&A=
t?,&8=
u?^p?o40=
v?+#GYM=
z?d,GB=
|?w31!=
y1~?|"
4/?*K_<*=
?wYV%A+=
.?x+s7E=
8#o?efE=
',?7X#=
BC?'2x
GQve$l
dw)tv#
fqsg~7(
t]rLvO
#D5pO/3N
hk<@8K
gmg1&3
X]La6M
PZXm4I@
Ai0TWq
@VNQ?|G
`7O84
fXLzB7C
Ip4"%H
@%OAA9"I
x<u*6"d
@O1O(;>
>(i&I=
>Qyu3=
>B NC=
>!ls1=
?UtQ$=
?PiB{^C=
?Gv72=
?qlm+=
?!.j7/=
?5Od%
?*Hga2=
?gC i8=
?|I7Z#/=
?>,'1D=
?1z@J=
?g)([|X>=
?|[{~*L=
?{mu!K=
?{7!O=
?=u <=
?IT$7QN=
?4%@@=
~U`?K
W?FPn;M=
.h ?5m3=
2 !?y$
.5!?]uE:=
"6!?l#
"?!y##<
98"?xyF=
:h"?bC
="?2w}
? #?'A=
@H#?43
Ax#?uN}*
C#?)r7Yr7=
F0$?3=1Z1=
H`$?h|
K$?{<9=
%?uYPwH=
Px%?yF.=
-Q%?\9
R%?29Zd@=
&?~YK|
sU0&?W
VX&?RIG=
?Wdy>c*GP
)a<aw>,?]
Y?eus<)kp?&<
E?Ka<>?5a1
aJ.<Gr+?qO
<2?R{'
f?{NkQ[
Q-B?6/Q
j@<{Q}<r?u
uo[?hI{L[<\
.5Sh1?<d
<}I?~<8bunz8?r
~<?OQ?U<|eEk?@3<c
?:L?U
<V/>?#E
?1j<1Lp!?|
<?Y6!'<_V?(FN\\
:7q?B:f
-?)]7"4
i^P1?y_
Aj?vdK<<?bs<*?Vb
?3xj<,v?WY
ivOV+4?<
Q?h'6Go?
L2<FY&?i
U:~$?@~ 4FC?2u<H%"U8b?3
sLU?d>D8`<;
e<?<h:kQ}?
<t_u?zGntH??;el
gBV_?m1WY$?]Oi?,
<bN6?~y
*B?&KV<D
2?2^p6w
?#%X.y
77?~_g
RDZ?9|KvPN
?qF||<##
c?nLx$x<e]{f
]IY3-J0?6}\0<]%>
U?An/X0
<yUk?1
k?l4Z?]4
0^b:YrY?mqG^v
?:T~OXuJ
[?rk?R
7E<KW.g?<HM<
m?D\Hq<i ?I
/?wq{H
<_{3?[K
z'?.P?
<k7+%?C
<@En[vP?-
SH<q+?yetb<log10
A.lzZ?
@-32?Dz
Jwk?zn
@$"3?5Wg4p6=
T?Nv$^
St)?4K
$?QhBC .=
(lX ?T@b ==
f??# =
G? $l
?sdLi==
p|?rx"#2=
p?h}s"=
%S#[k=
!V1?}a2=
q?20J5=
/@?"B <1=
z?\-!y!=
X0z?~b>==
Cq?y7i9+=
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.tls$ZZZ
.gfids$x
.gfids$y
.rsrc$01
.rsrc$02
VirtualAlloc
GetLastError
PulseEvent
EraseTape
GetSystemTimes
lstrlenA
LoadLibraryW
FindFirstVolumeMountPointW
AddConsoleAliasA
KERNEL32.dll
DrawEdge
PostMessageW
GetLastInputInfo
MapVirtualKeyW
DeleteMenu
SetMenuInfo
GetWindowTextLengthA
GetWindow
SetWindowsHookA
DestroyCursor
USER32.dll
CoReleaseMarshalData
GetHGlobalFromStream
ole32.dll
WideCharToMultiByte
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
MultiByteToWideChar
EncodePointer
DecodePointer
SetLastError
InitializeCriticalSectionAndSpinCount
CreateEventW
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
GetModuleHandleW
GetProcAddress
LCMapStringW
GetLocaleInfoW
GetStringTypeW
GetCPInfo
CloseHandle
SetEvent
ResetEvent
WaitForSingleObjectEx
IsProcessorFeaturePresent
IsDebuggerPresent
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
GetCurrentProcess
TerminateProcess
RaiseException
RtlUnwind
FreeLibrary
LoadLibraryExW
HeapAlloc
HeapFree
HeapReAlloc
ExitProcess
GetModuleHandleExW
GetModuleFileNameA
GetStdHandle
WriteFile
GetACP
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetFileType
GetProcessHeap
FindClose
FindFirstFileExA
FindNextFileA
IsValidCodePage
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
FlushFileBuffers
GetConsoleCP
GetConsoleMode
HeapSize
SetFilePointerEx
WriteConsoleW
ReadFile
ReadConsoleW
CreateFileW
Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVruntime_error@std@@
.?AVexception@std@@
.?AVfailure@ios_base@std@@
.?AVsystem_error@std@@
.?AV_System_error@std@@
.?AVbad_cast@std@@
.?AVios_base@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV_Facet_base@std@@
.?AVfacet@locale@std@@
.?AU_Crt_new_delete@std@@
.?AUctype_base@std@@
.?AV?$ctype@D@std@@
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$numpunct@D@std@@
.?AVbad_alloc@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
/:>khc
<zISa$
fLu/X*{d@]S>
I:J u9x7Pg
V4^dAc0/
x?z/kZ
%i03i]m
LVFe4s2Kl
Oy~+\0
+&-:sfQt
~~|@5acf
LV)^$sbu
dH)]JqA
qo3a8?f6>
mL!>~!
1=_xuk
MLeF0%:
Zc4W&a"J
v's3]6e^P
re(ox
2dXtE(Q
_EP^g:U
/Y(h|}o
QwcP>Biv;{
1V6PIR
_#qEQ%;h00,^
wFNi"/
CI}95$
9qIn9KJI|
q?wP$%zu
c(P{`l
FRY!tL= }
/y8I'>+7
Q,8O[{iY5
)iKDg!
h"m6^T+
',4yV
NmN:-dZ(?
2<# >b_(
eGQtT/
6PcR~sx
^5?0&-XvW
Z;rmv9d3Y
\Fj;"//YxtO
owu]M;
~({l9;E?j0
B6cbMs:d*
"'Pe*J^@
^ZZ)$.
#lKtK#8=KnSTW5Jk]`n2/1#
KsihdmI8X.F
&I1{5uoL
tL'2HcFWSd
CD6e 9O-K;.L^MI_
tj01tpobEXo
.P%5XSI
#by Wdh?
W6W]5b@b
z4@~)d
RC-dK|
Zjt[Dv
Tk54Kw,B.
^nO=?VE:E~<!qH'M
S^8:.LLX
^{{3:OF
u%b~X[2=
[&B47~9E
Dyq}AX~q
=K6yW=R1L
|TmT!s&
K+\(i0}[
fZ*irl0?"
DBBh!%e7TJP$k2H
6mUlK.
Yf8|6[
L7>-Go
W@$"jN
f1$)ap`/&Z3
5E^|t![7sw
3q4/i
A_XWWz*35a
{m{YM!
L:9ge<-+^6I,
YgnfT$c'
V_^~&.>-
H.u5x%- J046Lh|#:
qt{7xR/c
s;Y*S
m>!SaAS
O',vBmh$3F
*%<:a\~t)
4j`/&X8t!l$
oLpK=~d
d)Mi#M
YL6N|Dh!Wn<4joL$
IlgJtd!Y) rP"
wXk2e+#Z,
4RAe@-)g{De2S\T5Jhs|PM9|p6
J"'s^#
I9Y=qE5[^]s\
jBGvu:la.z
-V)0pG
iq>(+&"
1%X3"ko
8r?6Ba/
ClA"`vxRZ^H4
u|RAvA
aopi^|[l~k
!j XDH
1!JMMR@Ix';kCo
Hnh;=s@
}qy/<bc0Uz
;7iy9Dd;wX
LpPnrJ69z
Zs}yr"
sRl5j\
W`:<'p
r*<fqn
h5.dvC}
wDDI(~
Y-~fkR2
d><62iUXl3
TJB/AGrx
E]E+i#7H
^L2Py@t?
?X=sPy$3,
Xw}5k4
on!D[d; eD
kP"%Wad
LHzLuU>WU
k%df)b~
!.S&b yx
GTLQb!1+
3[!Fhp)TG
~\ioPS[
1_NE=K
IYtrdPaT\u
K(Vz|`
+FeIq-K
j'w#]M8`f
UIGc|N
Pr=Ri:
s3h_L1$O
[S5/Cj
|m`hCp
|W.d(4+AO
k))Js|TJ][
gk`p"Z
n@^M5w S1If$
}g&YR|
m:AyM_kha=
yz[X0'12]Ye
'K8EHU
eLLly/014/TD
K_-1pA5:I6/"nL#j>
*t1}x8
{WcFgj^ 1,"g
"?*ui_
ep5XOy&+x
:eJ-OQ@-
'D#L@lxYUY{
r<hUkh-9
Ne{^x#
`,[$Mg0<
P`lfCGy
yr(5J~Q5
_PFvX?gC
&q!P'@(
3Jr6mi;e/
3/_Uh/m_3Xm^G
P:sCu>RdRxvH
OS^n.=
Um;I8x-
SuES<@
G%|BU>`y;_
V#5$`3"
|#_%)^3QS H
=abs0G%s'VbSjk
f+xdyiy_"
K].?O;+pJ6
]$8.?h
W^V/&F
k3CH:t="
>%}@+)c
N8kY,O
c7PsqzVS
ZSh"`;@91
k<3.(e
jZXi"myZ
yL=DOp)
'b[w_$%
]4d7h&-g
h*}$UB
Z$w/EU
?y|O#~
nla0>GpV
X KPx7 hI0=\d
GlB!aqP<~8%o).tRp=
K(OlRUY
ZhpQ.*p"-
D@\;2,
~ZZE5C
.YUUq-
wGSZ>-S
g130db
&)9r29
{^ujYnQ
aYmKjErQ
~2^FdG
;yd8XJD_
(HzWHXQ
B|9w `i.
%CxCcBg
mPo#C&9
XCi8GG3Qc
;+0JEv0u+|P*
w$ !2Wfu<G
h93n-fV
'~LOk|Yhv/
:{i2Dgi
\>G-yyIA,vC
y\^d/!@"J
"4bt^\NI
8.#_Q;ZLf9s
<e{s_GCF
TsB)5X
N1])QHX
4o?p_WGH:D
}1D}w=jfYQSP;
^fkvK'L7M=.WsTVOpz:t
yu'% do
gE,~LshX|=^21*
\5mW$f
cUv;T4`dE
TX1qc0Q
\%|4 ,
zF0y}e
0/=&jl1
<'j:z
oe@*~o]
$~7NC0
mP7PUa~Ke
o:_M(LAlF/i
J0X;5/
p4ODE=
0f[?\b
iz:#oy
).~hh1
7nqo*+3&2~o
I`[qKu}
A#XmAJh2rGt#[\vU
:M<_7AQ|
1Ig77`(o
>SPJUfK
.@|F'-
R6P04cB
+u3}D;
HY#^|q
UL%~XI'
1o{HxmHrG
J-DuyLZR
F,u:&Z
V|xoL=
is%~xP@b
S(#b5fHk
X?bN-=k
xb30V!
9DXqLIAHf
GlF=pYLE
@<Hfd}lAOnT
[K<rM}G
O@m"D.Yp
/$R|PzX
)gMy8~
kfSUO)eI!
e<sm%F./(0Rg
goIw9?
_'Ojq:{uMQ
{y.m.,
6_D~'Lt
?"eb^$-h9k;P
BFYdxC
K:req:
zP_^S+Z@:'{X<
%.$.#`
rXsC:AG:1O)qT
dj*%k/jZ
'xqHP|L
>|MJ_o
;$/7?
~_rOry
2J^bV
2]97if,
wCxt{uTQJ
.Ax%$bW:r9.d_
\^20yH
+@WZr.|
u"w$}|J
[zAg0>43
8nT2>"
=7:pbcb
%@{iHvPd3G#
G^|0y"
GHRydEW
F`lcg(Z~
56e85v
?Tk>xe45|
%b5Hbza
BwYm7h
4vONhTM
Na[@84[
eMA3[: 6ERA
0P+{V2k
>@[;{d U
>a\h-X46ro
3cSXWfw
'MWJ'D.R=XQ<0vcoo
8-sHS$W
ew7]pV}
X~;iFY
B4 ?uM2[hR:0wM
ntCnZF3
pCWo64
s"_{Ml8
x,)XGI'n,|2%
M4@#f#
f&`I@8i#
G'8S9F<
!wvv+5pjK~7T2a(5ya
@!`2@@"XK
w#2@$d
tjQ6uI(0
(lwI7U1
!i{[NeDRn
//eD^3$F
kMC,D|
(WWQSIQCDn~\zrQ_
>Oo%SV!
}=}@@bG
]ZvF&!
+HWh:AO~
jY.nSb
p/fzysd
;sasB1)/
BM25!G'b?=t>
9&, EO2
ET-6gSGhv>&NY*Z
_b._R)fpJ7
$n/YVJ$
W8,'Pc
mP)TL';x~p
/tZ tR
l,Kj0mZ
`8VhVgL<f9L~
BFf=^"
[M/{}u^_>
F-E\A/Z
vSx'&H
'{J6uv)|R
]R-[b'
{i7VQj$QA#g
$4[!tT
e#6!HKq
{,^p=P}b
xW<2kv
;JS;I
TTBr{G" BW
cxwB+iC
f8#''X
U1gzV-8Y
S#Dnfn1
.7n3kuCn(p
\Yew3~?9
rVkH;~8
\d*}-v.Fa
Q}zC+{1FM
'\;b.#>~Yr2NNa
H)RT"R"
T%9;2s
';t#I]]+\
e)lO_jY*b
f>@0!h(M7
rLQh43e
v5'|H^
xP'K*:
F-FBg0
Ff?q9V%
hF]AwIRP
$(1/tx*KJU
C]r@;='
\^e6,x*
k;A4|WRP
/0+N(k
^7d*@;t
\MbS0Yf
](M7TdOi@pu
cy:)+cD0
o`n>Ks/%&<tdeQl
H?uq<Cj)
'D\2vK
gX{OT#Jjs?}i
?"yhF_
1#$;_q
s;dyW|
fm2Z,GN{q
7E-575_l.^2i
\3xBH]qA
|U+oQ] f
_5p6r#+
r](d~i`p}3S9,
sGxvX>SEbU
+IR.5b
01ZonF
f[ne&/&
,~$ZlC
/j&ZTG
P.|]7_O(~!>A
u(yt47O
1bE{FM_R
/E$fo3E(wKEw
&`_:)BI)
]L%GaI\
1\tO\o
{[.`.rh
%{!aO
4,*L0=>\x1%
Qn}SorI@@aR#U<6UHi
lp|>>;Wt
c=L`]6(
?Z6mal
g2ju:$
}b#orJ
)D4xLY8
['nn@LAO
X5VL8T
dOz/&i?g
i7yR2a4+!}
+M7%`
]|C5=Yrs06
D'|)+.(
''u5X#
g851-iI9\E
aRotqo>&t)P(
;d5' D
^8BL/|
z<k5%H&-
`#P|!K
=l/=i6\
c~G6Z*v/,q2
^6->g`D.
jnY}Mn)
9EW,J4
jVD*I<
LB}5w_
CQ5</2
2Xo&N2[P
P!@7ti56
dffBQua[]
d52&zIrO
@:;xfqb
zqm]{%|Efr(.D$#D
(E5cFF
__R?}:
i/Rk%pJ.
9ehs6s
900<.=
~BC*H[
~Q&oICRr
_uL|#";
$#0w}+;#J%')y
|zKyA`1SSI
&,VvC+BbkuS-:-
OwXz@7\$~3
=:BiI'
}8Q>[SK/
Ys]x}_
M`=m~mElb
T.V7.&K>LsWI+I
{/h<VXM
j[gzBX
Wk<WDCBgr8T"
afC XM
I8g.Xm*<
=>$A7P*'
{w+"^v
`<SAiz52Hk
Q4W;6O !0B
7vV}O"
ZK4Soi
9(j,g g
Yh[eu.
N=+^~"r
"N'1L9?.Dj:s[
</0C)0
zCB_h3.I:
(0'G~m
Xw#H$h_!
jYgL[C}G
//<}olq!
4q2`nUk|2|
{#*EJ#W
hq2Wr;V'
u/rOH6
X8Idk:k!
fh%%mNVM0/
Ex<Vxqa
e.` !&
i[zpVS"\r,4
]-tcU(&
0OYx;rm{H'!Sf
wSrX2G J
iLD+)u*~&:
w%Y/sS6'
j)LH~F
q-zy<G
W8Ht5BWJXy)*u$kKRRC
g=P\6fQo`\XL
kiAZH5~x}d
Rj@x%\G
(^/^_/!
5i0{v*082
hwF,a_=?
\Ej)Nfw0u
\!I!dp
.W|'$m8IE
"zE'=`
7C5EEhMV
=c{bhUw6\
X*pg{- ?pqp$r
n?4r15i
4"LA2d_D
&a~YM\;
8[T_7[?
4?o-HGt-A
v(-8y#t
jV<NFyF`
YC@nXa
gPre>:LeN
>l].M5"
F:o&z'
'glM.aKe'N
[bLZDs
eP}@m!*
ZA<qf|zm>gn`DlO$qjw-@g
OZJ!+V2*
hP#^(&
\5An0pAI%
JS&lxpLpM
+:QZ|A
+JZCoxjw32sW`Zt
#(1*{_Js
83(`WB`
(CT_u7
oO02"S
!;5YW%
l"kH6<_
>mw.{0
eU)&5?J
N&Cchdj
JUME{hx
;~\UP<
`1UG$3
-qsKqTNdLC%
tH UK%=efc[r,:
(3D.$(
z vXz!
H"cT)1jTLwK:'kN
X+YJ<I]
,#}U#K-?
t@'W)*(cAl
2FU5Rp
+g+gkE>
fjmt^1
j~Cp%)RR`R@jw
6Z. P'k
lph\U!z
w1Mtx_9
-?FRKi-+/
7;+Akv
69"q41a
C#+B@70
d]N13j
WhH{d!
3O/'B&
Umu+U[
o %f*S0M<8))hYcEH/hH
q2mKen
x?f]WdU
!fh,El
Fh'&Z;g
Tow\ZOcUv3uDm+
:k@r*Gq{e9
UfE68VK
pY3n4V;!O@
s/zD#V
1FB3"6
|F1F+WD
fHPx`|6
V[ww_f,
MSDUJa<_
!K\(wq1my
*Ny%JF
:n*rW`b
CW%T,h-
(xs3w{M
#=[]w-&ow?
/',G;_*O6'@
eux*r]?Z
43z%}{}
StE??4*Fj}3&a
:pY^@
9;M38MVN
G8`*L%][
?+#Q2"
{?kQ0r*O
yH)25WuDKh
3s40Ya
&!-BLQYUl
;XrGFDze
|xI9j`Y
D?nA)c
%[M_T8JGRz
$A4(>Fe_c
cAN]?~b
@>LJa~aR+
zzF=Y53
Toub[6
NM "k0$[.TSt)5_*
_5dQ'4I
a7YGkt4y
1]o~ix;
o}kTDOG]>
CV np[
#@/+ruQW
.vo8\sX
CQFwL,=kLAA.'B
~15BaNK3G=H4
D`gUefcC0~^
c'@>8l
\3M4F"c&
1?CL]
,9WJ>!e,F
AlM~SJ
w>W1`5'b-KY
6]x+iX*pCP
t"w[P#
D=t@-,dVo&@W*+dDaL
QH5-W-M
vv;6|O
:M~S^Hq[/i%
Pvn_MdN
@[wmh4
2JZI!tXH
>E:WR#
!UL+xdN
<~|92\[2efD
z}QcN+(V!2uv
2w^M~S|:\
KnDwoF!
nWJf:Irb`NS
6l%bg9BqO*7G
ZJS&*xmws
[tkeVLP
Ad!@Rj
PEtTR{|M
,Q8#N$
0/=^%hR|e-:F>;#
hIfyq;,FRSc)
QDRX**q@~^
2n&T},
pq~7/I?
2 [Y?$U
{bu'.2w
*w0h0P^
Dmi\{e
tM>ym< 9
[2R0VWB6n)
CfKp~@D
1,6u.~RF
oD+?LS
mku_wq{pUj}C0|
PQ;Wh}E
f\0A+pxiH:w+9[/W7{
*\UcP
I%}C4yzT
J{xs['i
'dNLNh
N!\2_
JV25>t
W-<ap7F5B*
pMj-)f
22c&y1`LZCKM
R,jQjr
8av!WAim>
k:y'C h
q|,#Ls
ACE$L#
rk_V02 7?j
dnkavT
]VEm,Z8f
A_{^}q
J[s=fg
VKYFjC
g#k>1]O
<2p#bA)d`lt
f[43J.&.sv:Pg
,r0QR^{Xc
T#nCN/g8PnWU
l+$MR(
Eaw >a
|P$z*2
eUBFQFQG0A
UgTzP4
b/FqJ3
n(gSTCk
<lD`NKD
C;Efx^y7
ERe!^fC
0+C-kqaod
JW{~ Rgr#_}C#H?{3
(ddeJpq\2FYb~3m=
M])z~q(1N4ivq
)%VN4ZA
_.$q@uxZ]
s%5u9i*_2 >
MdqGfQ
ut!EsC
IjQA{l
uh'\zuf
.,GI3(&yEn3xUA?Fg
/z82[em&
0J,V!DZZ
^Uc`Wi!;jP
yO(<'T_
#%u8 MZ(Gkb
uD7v/M)}
MER4sb
B*x\@OA
slyPY9eoQ
^|~X.p
98MD>e
C*mT=a0A7.
l<G[?
z>VtT]Z5
|%~/?UqO9
\v$Hko
Z,'3>Gv'4
lvB8'w
3UWfj)
bXU5ISN-u
GockgH3h9
9/3k9&X"3Y%
+C$]H5R
Yc<F;<
7Wk%4>`@
X6l&O?OK)5:u7
d2Ly=&vJJI
=Eq2yaYfqK
Ku\KRf
'oK&PZ(v
,4C_>>:Fjx
?a(J.W
+sBtYIDQ
KucYdEP
'1'@>,u
)89~e
?"cBps/Z
E!IPt%m{sH|Lz;
't|MhM^
w%bxxI
k10Mph8Az<<er
2dN!-*!
GC&b_<tEp
.k}>:U
D'9@T[
q)A 1{OWy
tbgw26
$W0bnG!j6@
%[.zg")P9
:+}Ig{[*
NU,Po6P
Sh<D7e62Hbe
Cec(p?O,av>(l
tM*S\*q y
.UQd]&ZT<
Wwdj7Y
50)A"R~-=
yCSR@\. z=S
O[("Z*o3=q4-
MHi[yOi,u{j}]k
x@yJ>}Y
KMM3eu!jhG;
an<1GpsyJo`tX,
]-O`9"
81j~-?w!
+&t6t}_
bw;r"[
a^D4NyXq
DIrtr%[
_rZ0N&
ME%[@'3vmGq
'A,=AIm1
O=Q2-kYKKN <
$<Tz 9]j*P<z'
B-,AaP#B
4'7Rw:%%oM6
%I4_?<76rq
t&MSJK]z
y<HNm x'
:DOkGuG;>bHyhfqY
2]sM]!~JDfn{#o
?6lH[h
XoS+_pjNV![
ZI=<<'S
Gh534
K&G~`EzV/
&ui<:ksE
9Wo7g~
nvmIrib
\/Wt=u
;rzvYHboR
l1keHc)
Px>v47tO
$>4r{J>.$
J1@H$nTbR#
ID}K9>'
.z{qGAP"
knCP<Bf
aGqINTl}z
<`4T(3t?%^
1wIneZ7v8C)
W=zILZ(9
ZdbJ)W.
\"h1,e
1t imDzc
n#3d;1
_uSZtIKxZ
j6x>1+q%4
$)>D/y
WwU(MDy}?q$&/
4V2_@e}
0=PHj.7F~gq-JDB(7G
f)^>r|Z
{Zn<%Kx
ky+S1t`
ocYPGb
b-2Nh
Lk8"j/
hA[[;;\8ZQ 9
=n]ZvHQ,
vwszQNZ9{11|
t!uPA'
t"=/9P
OUY<pr
~&PX@)
y<g<eAi=
=}Wx5|j
K;B(q:
t@ew[\#&l
UA@<jc=D'W
@-:qTRYE!
p/*\0HN3
@b083
a!F+t_ZFA
`4*sDh
t#j;UM|
cOz*m5efv
5ek"C+
2B@KF=O(#s'{
C^2}aTK"w"K
t<><1L
'Z37/l
n~c||R#4
/:h\/BY%$}5
5AQ-;s1
Sg)k#t
yJwr2b
G?}K3Oi
lD!m$@E]Vx
L)Q;&]2RA}m
cml^+#bJ
1CBG;h
y'-|@UHF,TC!
+|]e#gIG6G
fuxSKaL
8SdSo[aCy[1\r
$o6!I'i
Z^0;on
^yseQV^!t
>bx`{"D-]jn
70g<c58
Q-eki|bG5W)
;>-neP
vk\fy'fc$3S/
h]Nw)sL}&
j7b1z.
]jSY|rsFt
NSC[& `(Q
TK,D$"h7(N
x*c26l
.:|<6y?{1
$Gaj/s+LOr2I.
d,@02EfDO-
^B3*&
L@IM?
s_[Y8In
nI9\2~I0
:UKsuf
gy~A)D%Gn
d97y(|*nlg
AOTVC9<fim
:4<;eT
mB!GzJ
4@Yb*FT<rBe$@
z'oo^mB1dwi<12
?xHct"
cBkHKEc
/)bP-#ICm
C~{I,`
M?\q?;C7
3iZk08UJU]j_zzh11U.%n
%TLHh:
?&yf1<h\
`w2G@D
P!B8]\
eBjM~^
M^wS(map
}11JZiuYJz(,~A7vp
XONot w
vLoV8db44]
&m=j<
l"W{TAL
LF'esj
'#ol)]u9
G0fnl(0|&L
Ap]T?i
0"gR;!|<Jq
$(@VyRQfKZ&}
k\p$5iDqgF
pS3d](
v@BHo-
e"PQ_
M CW\OzXYhDa
+I =W^3"Y
HF$wC=\
%+n|X!
@r3-fu(p*lM3=\
opnZT2
Ft~0Zl
t!#2r`v
/0t&Jf_p0R $
xspgH}
MA>];2~c
LOC9.\/
1(zu\0@
eO!}ZDR=Jv}]pQ-J%
CbO($;
cKjM!2fD
`%m5$yt
p`!Zpjj
EuKG{-sd
sCjP5NHTF
pp6%Oc
W"l%[B[
,h/gzOq!o
"[/5j4`
=i/WJu&Uv=NwZP
Y!Cb]~
nP1,C*0
,RIqM'
SK=7K@;eQD?
iCC:Y*E
7?^tyt
1ikdu_
?WV^Cjf
JHRhxn4
h3;_07C^\
Hg0iD}|z{
hJQ)YyiY
Jx cx'{mak
T]a|3b
N6`pw^7
"$%zR"
DGd=yf"&;
Ka-Jp}hJ`
<~q!04.OzF1
9.t^FV
=:wI- :a-
\aZi|$E:nY
^dyV:I
+6Y;%_
<96@w})m%yr
iq*QWb8
V%uFX3H Y
+[R_x}Wtho
3xW~2g
5m=h/Z
'5_WhaSFyg2=wKUy:f
lw\MtSARulg
G\NYIN
i3mFaT
W;JaeX
M~/(lb
_4rnV_(l`/
p}~00/
fPeHE-u
4i9xCPH
OBN4bw
ONBfRO1
pZd&5T
BPa3Q0*sQ
;MXV/`VM>Z
[8hhn*
lz5M(q@
[B)g jXQ
J#wpY+dJrTr)b
AH&lE%
>$|{8$_=5<*9n
lIXHi8
l*q).[QeM?
L<%M8 X
uIDHqo5GD&G
TUQ&~L
%2StK8H
D{-pL1VL[
7xDM}UQ
!O!xv&e.|
<-;hz?`e[
I1WzbVdtN
5:Q+uNR{
s.)NdlD
_rDp,V{T.;
YPo<w)*zMW8?&
Z!6`JB9
'!Dk(@1L1 n
r2*:#:
U,6Q@O
lu^Qd9'b]
%)S[_~i
ZU-4d g7_
$S:76Amb)Y
eG>IHS
9eDj.$x
g&'_]f
_x,-o
q:V\N4
gX;l.[w
UD.*&3 2
lyaGB?]j
,,CrFeGn
Is%-yR-i>]m 'D>J9
U'v8.,$
OdJq]lz
;bApQ4
E. "Rb
/#z7`s
-;J}l[X
28w?8<@
G-qdg
^q/s r
Hb]K0<QHHy>RoJHp
A9Mb7T
96&8PN
twdhm#<4
[umh*{%%&XES6J
w4(HV
EL7(bdx
_?I4Pt
~j(`;z.
+h{YeL}8zRL
m ><hqxt
1h|e|[W@
kLj%_<d
91b6iC
l#$7Cl]'OI
iP2IaM>g"dDLIn.7 dHZB
E=".I}jAPO.o
VR-/ix
P!"YwE*iucDnX6u?z
J{Uak7(
N p~hwl[
={rL+&5D(r
u#R$C=lFu/*(YWG
$xC!&;
QI}o'Cj1.
&clmo8l
E;/`sG
sMh"%B
|)m;0h
>aun`e-
%g$!]Y?
00H,p3s
W`{lW_
5W2_:9Yz
{]w@ .
Lra[&cj`?}~
xPl>{w5%7
Uz^KvXh/cFU;u
vNZFJ(
F0\WsYcR
A{aCQ5
wTT-&?a[3
.)}p5n/0P
N 2!PP
"$q!?#5 {
yjf+"%
(x9st6
w{RIhN
?B<RN'
%""=]?p
Y_cUN6
E_;##)bwjx<
Hui~n9Io~ g*xq'
6"sP70 7^CI
1ul(sP*9
['"a93
|Wi^*`ax
9TJ}>GJp
poHT#^,
?s$vy)OV[o0
Gx$Mi`Q86R~X
r@l)h_S8
@25](]
)uJMmq
([w0WN
<]c(^8
;,tS8y
1^i)tlLk-QV0p2og"7>
|Tl#{ur1P
gyUP6eh=0
;L@nz*iIR]
xSs?m;o;+Vj
I7R-j*h
UV86aH4N4T
t^G4gAn
#?EbN)
.RzO[w
|*duNz
CF6^I}ZlZQ4#
aVr6SG
pq"-0C
`lJzR3
`ol,U@iG=/7
CR.7CC}@\
1 N;{1%WB
kAu'Kn'C:
]T>ex:
c@Y_eB
$a9$r,
9<VKXMt&lWX
A^6s_#eoeI
(W|rV[*TU9
8h6}Dc
$@P-u~
BYFQxg%GkMx
ITV9MZrQR`
Qt [i,Bna<
)G,`]E<
aH8IATHA
)vqji LbvVb>
h[=[5|
%~fUbQM
A :(K~"
M)-GRiPMmoG] &S8ZZZ?pwt
)!tSj``Yh
T?Q*ee
>~0W9w=o6{"+q
Ik_DQExQ!R~-T<
gT3aP&x
p;^u<J[>
U@#Jr7c
UMHF>E;b
zx$XcQ6
Q{:E;FT
%nI_.Z
I7q3c;5*
(M@2^qc
;GKj>0
.jm\D]
[ADIAp&
zJ9T5SrJ]j;^H
r:X7 _
nD^?yX
Nz-}>
'?RN%MB-/i4kL3jw
"b9*dI
gl|Ics\5
WmA^$^c,
\Dy+Tv
pw7v^m7>e
d-7n(m(-FMK`dis
[o)>F2
Er!K1BdK
n^R>)Dv(;q
v5?l.4
33V/~{D>
R]y&OOGn
v@Sc'g
@En6Vg
Ze{jzr"ey
<WEI\xSlz6~`
MBn#hePX$
McY{QE&?ge]
2y<4mIQ
R `\0^z)q%
|XaWr$<el5
0,9jDGv
P?|lZ3
N>#B9UDl
Y!7h[:z
!am)+U&+
l=0Ev6cBK
Gj][aK
\i!Fx]Z
|BXZ)MR)C2
XY@S@[
]oW[c n
R)L_h,[
>$@@$u?[*
-2y(Str
YQ:Iem"[*c
F2z9Uzr|D
mMs(ynfd5d<hF$1W
0Z'-],+FX
kkE(F@
(&tZ:3v
2tVt&_\x
[+!9]6
kFDH#H6(
4YQ$arK
N@I;xZ
DKQoW#:
dntU@-f
OIGQ<&Y
{2E*Y=xzd!}
*eU:S;sf
tVP~'XnzXGcLQ
sx(=Opt
TTl/ow
MpT.4##=e9
+EM[~aQN
$Ii^@!
3SxE-h
jRQ&?Od
T'y2~'w$
}9Y`;uN$g*F9NmH
8IF*t,
;EuCD}p8!\nm
J|'+Kv(
69bj[;
L=0Qh(
@{|uDJ7xb
0f>0|:W
r:o)+_1h|Ge
+kBM={w"r(
cv)dwy
TUo[)13DN*$9
]ZP3p+
kd}j=b
4d,E2P~
kFom~7W~}r7j
z4NxUqF
;N><lv
!d?SFDC
Z#rtOg
pfv>.z^
Pmled[
^blvTg
).CFRu8
PLndHFQ
>zV?bm_+!
}I*>/Gp~31-,
pOgqo1
N?0Izwn
&m.W--u|
:hwQZ7qp.
l@VnT1.f
3Or_t<
6ylj0Jj@Y9]Y
fzU$J
pviyF5(p
E"W1v;VJ
$7V>"8%
ZGOQbI
NqU)-I
27\=(X198HNVOZ4wm_7
o'xa3)9q
[#DseC
0]Mpu _DK
mqUZ\OK
TSn(cB=(
3FhLKI{$
1I,T6g)
R[]e$YQhD
a|]uYAm
SVw!T?T5^:-g^d
~^QiRa~
DHS51~N
sq G5
r&I2pOA
*6ob&+}
-@QM!Wm
"GJt5}
#r/B32
WVz./4TAg
W&l<=,3cm"
Wq~&uxiZt
4@dz9-MCQ
k|0#2V
ibjG8p
fhi<ywQ#
<?1 rR
~ p+0_Lb
h)}:!_Op~0SmR
pJ+T-<
(q5NA[0(
2>]#i$
;2HPg
!O>-"~{
g]g8Ihy
/6IR[\LL+Y
$sa->||
^`^;Ch
e PPgK
1f\TWY
y %:2;
4`CxvtXo
?#Vt~Vp`
3H3RAz]
R`8gZZ
Y;N+GMK4j
uQU"D4
]345Oz
(cBP%,,
{^~1{D{
}vTV%T
<~m}i5
pH a~\
_1"w=h
jivan]~+
^J~6vzETsB{@d
C#jS4.54d
*QEH,B&
s6TM5yH
e<Cj7ss+
'M.Q@A|
UIxY"xr9
jkXT"N
a/'!=x)T
.N~< [PA
^^> *s&
9{]nT<v}U$`"qzyf~brdZj
a]p\w#RjM
I?vU9J
*"wM&Wi
FWgY&AQ
V-#Q?}D<X
Kbx6HJB
Xmn^R^+`A
wU)R|jG)6k*:
Ta" <d\
Rv|%z%*Yp
F9`*nV[z;
yJ&uZ?^
QW;q6[
b;=#/c{
=ip},N
|=/wJ3&wr>=J
aM0Lxf5z
TmcF(yd]6
&}&D$zDT3Y*t 6YNvM
HPZ*IA
,M-:l@<3%
#^f5^8 '8
h_$VK@A][{)
~jv:%!
8fR!}A
x_eVZ*-)}
68;9X$Z
A>qn\%k5jZw$k-y
a<nnKl x
XBX\`a
"Cq7e:DO
[teok
fK:g3`Kry
$|-`P8
(nT</01cz$|_]Pc
>2["f1w
0[A-$Um.K
zY=&Q|Hb
&5RcmQ{sZ
dUWY=g/
QEfhd?
)*bSC[_
\"#"j8$3
qI27@7
j(~0z
x0BIEA[
+nxg=r?
d"Yn4Rj
ZWVVK3
RkgG5t8
VD=:&
EtY6>')s12s
S;d#}d7"
fq2yy,Re}!S
/:[jpDGudh
F}9k+m
V(KIAD
*I^"% <x4t%UH
S@_d&e'
F`QM2<O&
2[J|TA#xz
A;;q\6
(dnkjG
6dsQf(x[>
kw>?BE@n6
JQi{jGT~
U5{u'Y,
4SSZh+
cOWO#/QH
MB_Wcp/\ZCr
u`]H#t`l
W{8B:),X<s%
NM5c]W}p
Yi2{=G
J{$C~>U<~
=\RGtI8Y3O
`~zIyj!N
o2NJO.
m=U>Dv
Q~\uMb4
h"XVyQ
@DJsw<[
p|=lC\nmT3
0xk'\;
]\2,:,Z.C]oM++
mD[U@~-
@XQc=1
rz>XD%W
\R(L9CoYuR#
~"I^7&
ps{xf Y
Mb:PV[ba
Q5lKOG
STJ{k'
mM/+kG
Ebb<5w
YrDgMQS""RIdWv
>.YILYk(Dp.y
m-<,BhrPK
EXpHUj
lb^[/_~O
Qbsa{1Gn>`
0#j fBMXw*$ C^&zA<3
hlc_] E
#Zun:nN1
ZCT y,zCE[b
$xyrA{]zV)(
UzA8+
<pTU%B~}.
g}+Zcq
Jw2rQi
|SjTMXcK{
bA&XEfuKnOD|x
\99,{:#=f
oS91Ad
qy|h!:~vIF
>2WHZ=
zOO>1x
ob?@jy*
yKm=zw[q9
8/n/r[j.z|2P/g+GLT
tz:3kmX<2
#hvlo]E2
uT6BJ_
qYwb.uvDUx^GP
9pyw"KTC
lZ\vP{
W0icj7'
SYk(-v%NU
F'oyL!
QeqATR.
PplN_m#
F'~Rfvi
IB,\/mw}
YEQ)o7#
M~)"q+I{DC
pLQP\boShy
Cwm[?DXr(, yA
pK8lk$oBZro7&);E{P0$
NIN4{V
)Q;vTET0\
Q9&--u{$
=jrm{nR
8,KANG~m
\cZ}k/;
S--.(
Pt-a+6^0L-
D?vP/WE}mA|k
jR`|td
!JKr)V
/dT;x\
'Jf:O
z2&4ws*
90^W3491
"_3/Bu2
ADE*aE7I;=kC`p
"Ejf_k(b3{;%C"
2^ )2W ah_$]
`G}h{]Im%
V`$~wSjey\Z
mF%`%:h
7)H5{W
^pb^S~
hZ[vAF~\
5:O&Z)K.
OMO>;a
\Sdd>XU
-HV+k5d_
"Q%u*(Q
pxIgboj0?i
$6l5 PIcD
;e1N$wKQV6
H#tExX0
D/0|y$m
AD1IE8*#FMYH}gcN<r4
)<[8x6rHt
LF~x/,tV
n2[,q_
WK%}o^
06A_q<
K3&pdr
7K)YfuJ
s.2Ou#i{iRV
7|G{pFVwc
.?8=aXacV:5)gAXsgl
=RGIs6
0Yhyx\a
)biNlS\
%`>t)KC
3x~Y)!U
\Q|._
\mp.^y:D
f'^37W
)86<&59
M^c87
!(}yAg
o1FWR5GR.:\JN
H kTC D-kM
-*~E^w
[j_P9X65
x{DK#fQ
!.w^pM]'
)aqV~/Yk
Z-e6Wp>
SvHIHDe0
J9>4)V_\52}$+7
b.YX)H)
|hgTMJ
\g>Qc[
)Y%f9vP
# q;WJ+}u
#)I<SK
gs1%jo
FsIFYZ
nO<+6I`
+M`}O}
0dBxeWi%
&6lnN0@DzSt$(k
<;;MXk
Q9GiY}M
(2=.Gf{gn}
1:Tg`l
5tN^p+h
%M3!*v2/
-QTS>*
04h\\wre
&8fDMx,
R(,s7v7mNw
7 78(Qwg]
g?T}*bmu%Y
S0IYf"qk#
\t>iQ+P
EOscT?#>!L;BT;{n
qLrbd%?
3[4>9y-.
#\mTiq/
r3/!P<
z=<fE"
eMDerJ0aE%:
+"2MHF
j.`d*EZ
4s?<Nz
n&!~|-
A.3{xLSY3
P?X7eOpR0
IlEl/z0
4D=\8Rtq5
LZ!]z-g
{L/&wcM3K
->$4qmf&F
*z59n3z
H\V+1V~H
6@VJ<BFqd;
jA.+TtS
t@hYV-Lg
QV{@/zlP|
X*SU{J
:^W\AB8
#>0`j\e
tC8vHI~
Dh3oL1b|nE
eWzvb4
sa"H(OO
r2D%yK"
guYg{G$$y7
~#7aT^g
!)$U'~YZ#XDJU
jU-Qy-
>a(a=:
VYuzsE
LtJ CT
g*[nHhr
i'@RP"
R_X7jL
ikMIgjX
wUzM<6?
`VmV?le
4n+>FZCGkpG
V#R=Y~
~OkwN; 4
{:ry2-
!G.#,%Q
Y0`6h5oB
Sz:A't?Pfp
EbQ'4Z1
m"bVWL
Jtr;=p4D
1Mc HFD
1s _4"u{m
pow4&_8W
fKR:8XDeZ=6
x|V>q7j$
GfjWIh
]S9~gjvW3w
DLVh$AA
qA9KP:C
Bh-|zs
9E-3g83
Dv6~c3W
pCo(|-
5da#'!0
.IR)RF
-(L7b"
VW;m3H;u
}:ioii
rYHp(n
Ut$yPB
EMITQAR+Ez
-yuz4,
/4T3pZ/9<1
U\F_O\
7SDy^}Ip1
#[wES40vR
s;7T\#
Pt_7}@
; Hj!k
"|~Ej3"
G`(QC[
[!-lT'U{\M)8`;
\:1;/c!A
apER<gm;o'We{gXHK^
>u^$Xm
rK&fd5ek nY
G~:Z2c@ ox
2p,/j)
j8FO{Uno
~P":]`'}
~Jo&BDA
2Hot3Z
O<KRI*
C6Syo<&
/Ge3:0I)
Dl\P+f
u<$+9P?*rJ~
z`QT[vjP'
}yGSZa6
#5xJWYO
)l7g''}2G
Iw`O s?O-
O`[*%+
s<9jHc
1Z6mW&aLA
- do#R
8d2eTEZSDJ)f
t2;/\E:-w|?>
Y:=d_.
,<HxSv
$ljI\Q]#Bg
_G/"B;xI`$Usxy4ad
4V4r~J eVSJk.&
w47/d!l~TUQ6
3n~(82X<S)
TttcWvP`-
y)nCY7Bm32wy
ob+e$e|
qkMTz2T
{[nUxR=
h<Ld<`'n[M8%
b5H#S6k"
t$>?OKi
17OP7S
/CIjq
|'wc=Qf
7-G./7
w*2=u=
[PK>:*
m;FdF']
r=e'BCpXuN(
>v&%TOy
EK\`r
ut;RiV*&
Q-Zv[w
vhGWB|%
[i<q0/aL9}6rmU
M)h,W#=e
\sLfWh
@h$F<3W
(Ji HM(
<%| fwb
.b*OY86]^A
0.(FhW
9Yab[;
ir1A;EG
{v>}9*;`
kW"*9i_3#
MGuRZV_*ExA%?u
;>QjhU'KK&
XG}+"
k*`c3g
1H_&{15dce
3z<i/d
iz{lRw
2tFlNZ
4bf&LUPs{w;PjArv
% $t>#Gt
qP$hrj
f8pW3M6g'd
dgVMzm
m7Xk57
OZ:j`!
3M <C^;
5z]s8JS;3
5Qt_3OC{xuXe{
kx3rr}?N
%k~V,1N
8&mk$.y0gI
_&;(ucsT{V
7{buq2
iw8Qm8
NE(eHWFQ"yxh
w"sL:3
v;%O"K:
$]-5|W
Un(%=?[%o7U
SU=uc$
@mYPoh2
\TAkmz
R|GXnHpi]
UDWUU;%#MMP
EHO5/s]KnP._kW&
9]{o_$jtG
SM]p%P
BY~,o`!
m_a<vEw
d YnIUn
M~}etc
|M?+.Q(H0us
C* J|g(0
q2FM[M.g{
iHqZbCV*
\\x,XJl
;:<`!e!ew_3-7
L>[tQN<
oZmpA_
^)OSH
U'h4#h
I.8[kp
Ti(%T4p1?#C
amvRpb/Gs1
:\cbU7i5I
Zm/x/_,KHxH
L(0Qu{<
lX\lh}.
TG=$vY
uqNA6Y
VqppJKwj5
%YXudTK
WIIa)"
dt#6$x
8D6Tk0U)@
`Hw B}6,
.{$0GgSC|zB<`
`Z4QZl>1il0P"
240`OAylVVUx1%'$
*s1K7X
}%stH[
~Y-Vu1
b&bJcW/DD
8FN@\p,ZyZ[D9/v
0f3P(8G!M8
i?"`!=qE
s8fLOqwS{/)$K
wzDo$,6O!
$J0km)y1e\j6$]`bmQ;C
oe6aX.
D.3#):f
ULzBm!-B&=
wNp`Ig2~
bXp8#C
@N"S\heMS
`{IkH#
f+mL";3u
e^wCN22BE4<6YFfzT
T"*5EWdO
Dt()~GG
}VdHmmYL
=)`~X
f`yJ|e4-j
NbkW[+`Ri=
#y3V]d
'M2IJ@c,|q7
IE1!>Z
&!J# 5
L1SYX6
";\_%_i
-t] f!KK
^JK8;9
M_ (@?#
.-e4U.
e|l&fm4F9ih\
t[wD/OU[
1_KZ\gx/(l@o
3j`sa Qa
!s?Kq@X0
Zkt?NaDP?
[zyBC%OCaq>qoM;IzKj
;_GI2-
I)KU<AhALDd|
"#Jt+)
1I's/D
l&d]22
3!Z<kf]
[oov.)
>0T`$}
+m'4Fu
sJ/-:%LH_
OMRJ#C
Xv 7Oa
/eMoH/V*(Ad
~zJU/B
-Cz43h&.5
u/R*[}&
SI!3wjITBxO
0*.@F.(
}Nj%PJ
&Yp5<5WiI]T,>zM
P)=ri[UC.
N)mEaYi
)6Un{]
y33,R6Fm
Lxqu_{Eq"H;0~]*>K4m^_T
+3DkON~`
(>'uZ*Zzp;&,
WkN$!<[zk
-$[Y{$%
s;F(s(L>:
QO"m1N
NULFr`
aP#"}HF
nFL-- TWQr\l3R
jw-wkm
%~_7OBih;/Q6`Q
:Zn2\ oj;3
H9g5J6M9
E s`n1op_M%T-Wi
D+Sb+@lvV
o_N;pJ?u
&i]>a{
29FS&<]@
\ZFNVr'
#nb`6Z
u+\HKhG#
v7+4EP
1b}Ub9v>
YsJT`x
xX.?I5F
4%2)_IC!
?DCp^h
!9eW@.e#oU;9rn}p{Vpv
QkRFVQ
k0!mD[kZAV
p;Wos7
pz^AND\;
-_E6pW{G
on6K9y
$cy:`}
-eOV0pgek8
/vjJJiE-
y&?q1p
y3l$'{K
FZ1P0@mF
Ez15[6Vc
P_ 9+[9
24+34h)iu5M;
FJ/}mb}h[:]
q?8*3c%-rc$
^gG`BR
V.[A5&!
{N(KBi
+qG;cV
BYT!a7M
1OtM~G7Nc
Pl{_!ND`mOdBw>Ss
?U^Q)m%Q
E%RJ6}
d+S",g$
Wp!9F6
fQ=Uvy-
iCL,'wz
&"\=>S
Oi{]vj
Na"Do<@aU
"(YA$W
W"]ggN`x]_
z[ DUc@R^+v
Lu`!xm}
8g>[.u$0H
V/l$[@
,gL/YpXI7-
$sgb_\+s~
`b2lyZ\F
>fGVYk
3Zl6E3u]
mW{1;lW^Hgn5%h=6~fZ I
}^Bp[P<X
sUoCvv
UGi8S{f7
aCyKY'N+<v)V
\[;Uc,`o
I'*vamVU,Uvd"TDwq
=*WwL'2lU
RM7vf|`
K0/`E;
^<i$_]5oV-
zjsGR[
#h.-Fl
)&KXSL{N*Y%
A2Qj7r[9I
bvon4%r
hpaIg]~
)7i@,y'D
1TC`=c[i6
HDxPOZ
+),V~NX kf
33GT~=I}Q
U+8AL0
;$iK',
,__IIbb0>
}ysd2f
Y\kMgwV!:+k
x(h,QO
TPKLei3OK
1E6EZe
alhX2b->auD#
nIf\);(2d
qWg()Um
"~>-:,4
Nfj]QfJc/5
qUZ|$Rxg!
gIi,1,Jss"
jy}5vj9
OtLgE|c
5R<,31p`
c(pNHuy[
$2&P=F
T+\u-H 9 Wv&%|L!y`e
OW6epa
jr)^hJ
Up\|=:Y
dEu\Wz
{r(.,E
>-a8:{9~
@OM-".MZZjZ-
C\[{&v']ks=
/>Eu!>
ZpH>m792R
!ONG+{z3sS
+U'66jsar
-$2,nT
]0`U}tL
,Rh7W
j$)a=h2L
(`T$K_
XEi6SK'V
A4i6vk
v~+(dUtw\'E?WJ
'`BaWO
JHL['4OR
p`iz[I
p3'+3s L
7KOH/i
O-CX5Hldv
9j96AXRFej
sK*!s>m=iYP
&':,$7pym&
YoC:BN{Ed
}q5h"I
hr53ZL`
S)_0Imm
S3bG xsfv8U2]
er_hFS
w!<L%d
R`!(_2
+})Q~;(
7l;]{x$&Zl
3<M({!
;/3Md@hF#
2VU(o-
i3Pr;+
nc?[7r^' 3
<^2c6n
tuYvsWsf
VSJQ'n
#~<[$*]&~
MMt4"4
l[:a~'
&Ljcdj
R^H]$O
PyusbP'5@
03.gu:'
mY)34m
~gMh-y
N5T0X7
7jKYn$3F
bX[~tCp
r_fxugcg
RLgpr:knrDq!%
`<Fx%&JCuI
2*xl@@Bl|
B"p#|E)k
:O:^JHF
i&kT4;
{n^|G,)^SO
\MYWn0
cB]kA&
tV4!r'
:JDq8|
x]q]n;#9i
MERh_)p#
DAVGudo`
;3(^,:=a
5i(=bK
%ul&1W-
nzuPJl
-ZgovsG
u||zDP\eFoMwG2
KmF{}J
O/qdAo
FFdE:=
y9%x2W%L9w7Z(
]S"u$?`L(>]ubl0
br3vN\=W7:&Lo3
Mn>|t+8D
3Ir|jN
uggS?CV"V$OZ
h7ngZVKFr
Q"M7e7
?5J q,
#w5z/hZK4
XDw(M2
<(Q/OG5wZ^,
@@@@@@@@@@
kernel32.dll
De rerojufebusuyiyofakitawe vileretixahaweraluzujicehowo dizoduremefule bitinekatixebalewufevujoka
kernel32.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
Badvapi32
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
(null)
((((( H
(
((((( H
mscoree.dll
CALC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Bapi-ms-win-appmodel-runtime-l1-1-1
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l2-1-1
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-kernel32-package-current-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
user32
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
BBBBBBBBBBB
BBBBBBBBB
BBBBBB
Bamerican
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
CONOUT$
-Mipuzigovujo ziluwiba duyoxitijigude suhanudi
Gosekado
6Vuhufiraze pibo migifu zihuhikeba zukila jatovita cofu
)Hu se zo yifuwupi vizimajaka canaluhibuzo
0Kakupiki ku mujagubola gijonavaji goyuporidukafe
cNebaza hinojagohoxoga mekixitunodo leko xosizeve kececudixetixa kehereseyeta sohorabe nusereva take
Payacuci8Hajedumiyabe daseye ru xiyehoxi decekajege xozayagope gi
Wutogogi
SLuwafujojoxa rukulurazapune kucedolape dubo jirehebetaje daragulu yoda wohuracurema
/Hifu ra jodacirari civupo samize zahomasowakuzu
)Pikosi hemukuxabiku gikijabeso gutuyozuko
Yanivoxa zowiwaye paxoli
*Degumofipasi cajo cowenodipe cecidujuci ye
Ri xecufazukofa tepaxudocagi
@Fixoba moye vetizababage woxo doce sapajayeyazede xisudoyomuhosa
Hotiyiwi fuvudamo
<Cegudohakomo jeweho gidipo kafusucojaxifo gu jeyitabemo jeyu
vYayehacubenegi jugudanepi kotigodimuwu socudiwuzemike vasohirova copisagibepisa toxiwucatojosu tuyadolezosiwa yuhumuni*Fepi jiwage kuwi zu medelo cifucavo xilitu
JKibagegu zovewanavetogi sadayaro johe fajagoma te ca wijatazepuredu neyijo
!Goreri vekeka risaruginile vusubo
Yutusu wofobolikuhu
hRuxayogorayoci cenehozogole hejosa zobilono ziwovazefabo favisefuno tudovozaweso jimetasujinefe gecipano
VZofogijuxonu cose gogilibobixa yogaciku yiletozoyihe bezobuwuciwudo cadu ferojudewo ce
Pi wetewavasaloge juxosidijoha
8Gorakojatobu yuko xu hirurena gepuxakenihi feza cesilota:Xadatebi cofu tiwefo gucubohexuviyi cayane mo yicehijetude
Sukenahewe hovemari wikujinuce
Yadeyafi piha jabonorexoke
TKodiki cisupizipikare begivinenasa bugakuku cehalisozazelo puguyewotune dobeduhixoti
Luyi fozoberifezi dawa zuge
Rahodomafe miroci
Locitote bosinimusebu yu
Nipihowuso cegutosixu
cNevagumege dagupegale heru wagobukire dexuvuwa jeyowujovutuzu diposuxe zoyirudipu fo picivehopowegi
MJijobo dugore kosorecuso tubatariki yahavixurifi zaki xuhikati pucaxegecavapu
Bopinecesaxiku latebutohute
Tepezesokaxo
/Modifejigefaso zamoluyugi hepipigudisira buzoga
0Teramexizosi makeluxepu vemira zelerine kabatigi
Xawekoza
Xojo sewumajamepozo
=Naxiwiyo vizicesehi zuji zayo nizinukisihi nitufa toto vohewi
Hezimosafo
Didusepejacuda gemu
Rodehuha movetoketu
Pebo kazumigesaku kixoiVafa lomi seyicuwatitako neyepijosudota kupove temulavifi posoxohilujusu cufususaboheni hideyadizeru levi
GMari joyaneye vetu wipufebedopi yocomujiyeze josusuti mevumavi zasehape
ISojisori zosexabonera muyoke zanibo rukikekimuxuru povo jurotavugoyiyi yu
'Xicawomu tegafefopi woze mogigaxujazaji
VWaho kenonohu wumi putedimabozode seyilemejevu xotipufite yiyapeli tayazu kesijavobohi
JDare jaxu ladawimiduvi tanamiro gifunoha buzonovi te kicolese nimupezumoti
$Vovahoteribewi vojohikinoniwo helago
WSuxipamenupo nagaro zukafotovibi bozuvema yuzute dorajuxejili zuyowijufe bodoyilubulico
Niyokuluyesepu
Yahu dejita
1Baji rasularule gafefo ji xe jalugivoci fa wizale
WXemedapi posijepafi naradolo numuwiwito wepo reje zalefe wuxamuxetajo vowotaxayula wuze
Giyovekesodo xofezavu
Wuza zaludavakofa fahofecuza
Vabujupexoyixu ha
ECoxu vaze ge sucidu lasabaho home gevula heloyeho zojiki lovaxarujufu
CLufafora foduju gifoyunicekino be mitoku waci tixahaluxuluge zeloka
Zebazobu puyobume telawe
4Goro zotahujami juruku kiyi pu cajetu tolo rubewo ma
8Sabiyohoxuco janukazahavi wexepeni wanegi kicudosoyihuru
Neveki vubakive kesa

Process Tree


06cbc23ea4d7db79d272d4038e246b8792205575fb0e8cbac23761ab0b82ca22.exe, PID: 3012, Parent PID: 2236

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1404, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1448, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 2940, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 2520, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1596, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 332, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1776, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 2908, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 852, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1268, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53
192.168.56.101 51758 224.0.0.252 5355
192.168.56.101 52215 114.114.114.114 53
192.168.56.101 62361 114.114.114.114 53
192.168.56.101 62362 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58985 114.114.114.114 53
192.168.56.101 58986 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58987 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58988 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58989 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50075 114.114.114.114 53
192.168.56.101 50076 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50077 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50078 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50079 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50080 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50081 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50082 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50083 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50084 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50085 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50086 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50087 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50088 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50089 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50090 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50091 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50092 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50093 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50094 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50095 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50096 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50097 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50098 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50099 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50100 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50101 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50102 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50103 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50104 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50105 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50106 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50107 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50108 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50109 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50110 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50111 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50112 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50113 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50114 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50115 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50116 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 50117 107.178.223.183 ns2.wowservers.ru 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name a6ed95e4865dc52c_rdudud.exe
Filepath C:\Users\Administrator\AppData\Roaming\Microsoft\rdudud.exe
Size 331.5KB
Processes 3012 (06cbc23ea4d7db79d272d4038e246b8792205575fb0e8cbac23761ab0b82ca22.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 5dc1114db0eeb1ea8f76c0bdc707dd3c
SHA1 db8a521d6beb076e19591de0eab6376d9705d912
SHA256 a6ed95e4865dc52c6c43b84ba650775a5b41327fe6bd3207c43dd56a859cf75d
CRC32 CCE7E46E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.