Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
00#U2800.exe

Overview

General Information

Sample name:00#U2800.exe
renamed because original name is a hash value
Original sample name: 2024 - SM Entertainment ASIA.pdf .exe
Analysis ID:1439459
MD5:ff6ddcc3a1804e75999a12f983ec76a8
SHA1:9bc7369c82203c261e398cb44944662517870e7a
SHA256:05525c085fe8d08ca8a6a52a27ef1594b87276187738a55e8751eb8ab8fa8975
Infos:

Detection

Score:84
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Icon mismatch, binary includes an icon from a different legit application in order to fool users
System process connects to network (likely due to code injection or exploit)
Contains functionality to infect the boot sector
Drops PE files with benign system names
Found pyInstaller with non standard icon
Hides threads from debuggers
Modifies the context of a thread in another process (thread injection)
Sigma detected: Files With System Process Name In Unsuspected Locations
Sigma detected: System File Execution Location Anomaly
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
PE file contains an invalid checksum
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Conhost Spawned By Uncommon Parent Process
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • 00#U2800.exe (PID: 7280 cmdline: "C:\Users\user\Desktop\00#U2800.exe" MD5: FF6DDCC3A1804E75999A12F983EC76A8)
    • conhost.exe (PID: 7288 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • Acrobat.exe (PID: 7384 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\None.pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C)
      • AcroCEF.exe (PID: 7592 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
        • AcroCEF.exe (PID: 7796 cmdline: "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1896 --field-trial-handle=1640,i,18113123113952577735,16265978303955578204,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
    • pdf.exe (PID: 8372 cmdline: "C:\explorerwin\pdf.exe" MD5: 86EDB9CBB19D37360BB868ACE85691C5)
      • conhost.exe (PID: 8400 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • explorer.exe (PID: 8564 cmdline: "C:\explorerwin\explorer.exe" MD5: 490B24AAABFD71DC7561947289B252A5)
        • conhost.exe (PID: 8636 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • explorer.exe (PID: 8920 cmdline: "C:\explorerwin\explorer.exe" MD5: 490B24AAABFD71DC7561947289B252A5)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: File createdAuthor: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Users\user\Desktop\00#U2800.exe, ProcessId: 7280, TargetFilename: C:\explorerwin\explorer.exe
Source: Process startedAuthor: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: Data: Command: "C:\explorerwin\explorer.exe" , CommandLine: "C:\explorerwin\explorer.exe" , CommandLine|base64offset|contains: , Image: C:\explorerwin\explorer.exe, NewProcessName: C:\explorerwin\explorer.exe, OriginalFileName: C:\explorerwin\explorer.exe, ParentCommandLine: "C:\explorerwin\pdf.exe" , ParentImage: C:\explorerwin\pdf.exe, ParentProcessId: 8372, ParentProcessName: pdf.exe, ProcessCommandLine: "C:\explorerwin\explorer.exe" , ProcessId: 8564, ProcessName: explorer.exe
Source: Process startedAuthor: Tim Rauch: Data: Command: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1, CommandLine: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1, CommandLine|base64offset|contains: }}, Image: C:\Windows\System32\conhost.exe, NewProcessName: C:\Windows\System32\conhost.exe, OriginalFileName: C:\Windows\System32\conhost.exe, ParentCommandLine: "C:\explorerwin\explorer.exe" , ParentImage: C:\explorerwin\explorer.exe, ParentProcessId: 8564, ParentProcessName: explorer.exe, ProcessCommandLine: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1, ProcessId: 8636, ProcessName: conhost.exe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A380F0 CryptAcquireContextA,CryptAcquireContextA,CryptAcquireContextA,CryptGenRandom,CryptReleaseContext,clock,clock,clock,clock,CryptReleaseContext,15_2_70A380F0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3C10 PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,CryptHashData,_Py_NoneStruct,_Py_NoneStruct,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3AD3C10
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADB400 PyArg_ParseTupleAndKeywords,PyList_New,PyEval_SaveThread,CryptEnumOIDInfo,PyEval_RestoreThread,_Py_Dealloc,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3ADB400
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADCC00 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyExc_TypeError,PyErr_SetString,PyEval_SaveThread,CryptGetMessageCertificates,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NewReference,PyLong_FromVoidPtr,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3ADCC00
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD43F0 CryptDestroyKey,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NoneStruct,_Py_NoneStruct,15_2_00007FFDE3AD43F0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD9450 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,_Py_NoneStruct,PyExc_TypeError,PyErr_SetString,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,??1PyWinBufferView@@QEAA@XZ,??1PyWinBufferView@@QEAA@XZ,_Py_NoneStruct,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,??1PyWinBufferView@@QEAA@XZ,_Py_NoneStruct,PyEval_SaveThread,CryptUnprotectData,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,PyBytes_FromStringAndSize,?PyWinObject_FromOLECHAR@@YAPEAU_object@@PEB_W@Z,Py_BuildValue,LocalFree,LocalFree,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,15_2_00007FFDE3AD9450
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4430 PyArg_ParseTupleAndKeywords,PyExc_TypeError,PyErr_SetString,CryptExportKey,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,CryptExportKey,PyBytes_FromStringAndSize,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,free,15_2_00007FFDE3AD4430
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADC370 PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptDecryptMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyErr_NoMemory,PyEval_SaveThread,CryptDecryptMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,free,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,PyBytes_FromStringAndSize,Py_BuildValue,free,??1PyWinBufferView@@QEAA@XZ,CertCloseStore,free,15_2_00007FFDE3ADC370
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD9BA0 PyList_New,PyEval_SaveThread,CryptEnumProviderTypesW,PyEval_RestoreThread,malloc,PyEval_SaveThread,CryptEnumProviderTypesW,PyEval_RestoreThread,_Py_NoneStruct,Py_BuildValue,PyList_Append,_Py_Dealloc,free,PyEval_SaveThread,CryptEnumProviderTypesW,PyEval_RestoreThread,GetLastError,_Py_Dealloc,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_Dealloc,free,GetLastError,free,PyExc_MemoryError,PyErr_Format,15_2_00007FFDE3AD9BA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADEBA0 PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptBinaryToStringW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyErr_NoMemory,PyEval_SaveThread,CryptBinaryToStringW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,?PyWinObject_FromOLECHAR@@YAPEAU_object@@PEB_W_J@Z,free,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3ADEBA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3B00 CryptDestroyHash,_Py_NoneStruct,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD3B00
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5AF0 _Py_NoneStruct,_PyArg_ParseTupleAndKeywords_SizeT,PyExc_TypeError,PyErr_SetString,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,CryptImportKey,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3AD5AF0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3B40 PyArg_ParseTupleAndKeywords,CryptDuplicateHash,_Py_NewReference,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD3B40
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4330 _Py_Dealloc,_Py_Dealloc,CryptDestroyKey,15_2_00007FFDE3AD4330
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADD320 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptDecryptAndVerifyMessageSignature,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyErr_NoMemory,PyEval_SaveThread,CryptDecryptAndVerifyMessageSignature,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,free,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,PyBytes_FromStringAndSize,Py_BuildValue,free,??1PyWinBufferView@@QEAA@XZ,free,CertCloseStore,free,15_2_00007FFDE3ADD320
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3A90 CryptDestroyHash,15_2_00007FFDE3AD3A90
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4280 _Py_Dealloc,_Py_Dealloc,CryptDestroyKey,15_2_00007FFDE3AD4280
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3A60 CryptDestroyHash,15_2_00007FFDE3AD3A60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD42D0 _Py_Dealloc,_Py_Dealloc,CryptDestroyKey,15_2_00007FFDE3AD42D0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADBAC1 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptDecodeMessage,PyEval_RestoreThread,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,??1PyWinBufferView@@QEAA@XZ,free,CertCloseStore,free,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,_Py_NoneStruct,Py_BuildValue,malloc,PyErr_NoMemory,PyEval_SaveThread,CryptDecodeMessage,PyEval_RestoreThread,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,free,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,PyBytes_FromStringAndSize,Py_BuildValue,free,CertFreeCertificateContext,CertFreeCertificateContext,15_2_00007FFDE3ADBAC1
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD91F0 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,_Py_NoneStruct,PyExc_TypeError,PyErr_SetString,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,??1PyWinBufferView@@QEAA@XZ,??1PyWinBufferView@@QEAA@XZ,_Py_NoneStruct,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,??1PyWinBufferView@@QEAA@XZ,??1PyWinBufferView@@QEAA@XZ,_Py_NoneStruct,PyEval_SaveThread,CryptProtectData,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,LocalFree,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,PyMem_Free,15_2_00007FFDE3AD91F0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADB1E0 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,?init@PyWinBufferView@@QEAA_NPEAU_object@@_N1@Z,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyList_New,PyEval_SaveThread,CryptEnumKeyIdentifierProperties,PyEval_RestoreThread,_Py_Dealloc,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,??1PyWinBufferView@@QEAA@XZ,PyMem_Free,15_2_00007FFDE3ADB1E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3A50 CryptDestroyHash,15_2_00007FFDE3AD3A50
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4A40 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,PyExc_TypeError,PyErr_SetString,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,malloc,PyErr_NoMemory,memcpy,CryptDecrypt,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,free,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3AD4A40
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5170 _PyArg_ParseTupleAndKeywords_SizeT,CryptGetProvParam,malloc,PyExc_MemoryError,PyErr_Format,CryptGetProvParam,PyExc_NotImplementedError,PyErr_SetString,free,CryptGetProvParam,PyBool_FromLong,PyList_New,CryptGetProvParam,?PyWinCoreString_FromString@@YAPEAU_object@@PEBD_J@Z,?PyWinCoreString_FromString@@YAPEAU_object@@PEBD_J@Z,_Py_BuildValue_SizeT,PyList_Append,_Py_Dealloc,CryptGetProvParam,_Py_Dealloc,CryptGetProvParam,GetLastError,malloc,PyList_New,CryptGetProvParam,?PyWinCoreString_FromString@@YAPEAU_object@@PEBD_J@Z,PyList_Append,_Py_Dealloc,CryptGetProvParam,_Py_Dealloc,GetLastError,_Py_Dealloc,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,free,PyList_New,CryptGetProvParam,?PyWinCoreString_FromString@@YAPEAU_object@@PEBD_J@Z,_Py_BuildValue_SizeT,PyList_Append,_Py_Dealloc,CryptGetProvParam,_Py_Dealloc,GetLastError,_Py_Dealloc,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD5170
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD9960 PyList_New,PyEval_SaveThread,CryptEnumProvidersW,PyEval_RestoreThread,malloc,PyEval_SaveThread,CryptEnumProvidersW,PyEval_RestoreThread,Py_BuildValue,PyList_Append,_Py_Dealloc,free,PyEval_SaveThread,CryptEnumProvidersW,PyEval_RestoreThread,GetLastError,_Py_Dealloc,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_Dealloc,free,GetLastError,free,PyExc_MemoryError,PyErr_Format,15_2_00007FFDE3AD9960
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD59B0 _Py_NoneStruct,_PyArg_ParseTupleAndKeywords_SizeT,PyExc_TypeError,PyErr_SetString,CryptCreateHash,_Py_NewReference,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD59B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADC900 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptVerifyMessageSignature,PyEval_RestoreThread,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,_Py_NoneStruct,Py_BuildValue,malloc,PyErr_NoMemory,PyEval_SaveThread,CryptVerifyMessageSignature,PyEval_RestoreThread,PyErr_Occurred,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,PyBytes_FromStringAndSize,Py_BuildValue,free,CertFreeCertificateContext,??1PyWinBufferView@@QEAA@XZ,free,15_2_00007FFDE3ADC900
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADD120 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptVerifyDetachedMessageSignature,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,free,free,??1PyWinBufferView@@QEAA@XZ,free,15_2_00007FFDE3ADD120
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5090 _PyArg_ParseTupleAndKeywords_SizeT,CryptGenKey,GetLastError,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD5090
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5880 _PyArg_ParseTupleAndKeywords_SizeT,malloc,PyExc_MemoryError,PyErr_Format,memset,memcpy,CryptGenRandom,PyBytes_FromStringAndSize,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,free,15_2_00007FFDE3AD5880
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4870 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,PyExc_TypeError,PyErr_SetString,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,CryptEncrypt,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyErr_NoMemory,CryptEncrypt,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,free,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3AD4870
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADA060 PyArg_ParseTupleAndKeywords,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyEval_SaveThread,CryptFindLocalizedName,PyEval_RestoreThread,_Py_NoneStruct,_Py_NoneStruct,?PyWinObject_FromOLECHAR@@YAPEAU_object@@PEB_W@Z,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,15_2_00007FFDE3ADA060
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5010 _PyArg_ParseTupleAndKeywords_SizeT,CryptReleaseContext,_Py_NoneStruct,_Py_NoneStruct,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD5010
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4040 PyArg_ParseTupleAndKeywords,CryptGetHashParam,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,CryptGetHashParam,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyExc_NotImplementedError,PyErr_Format,PyBytes_FromStringAndSize,PyLong_FromUnsignedLong,free,15_2_00007FFDE3AD4040
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADC030 PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,?PyWinSequence_Tuple@@YAPEAU_object@@PEAU1@PEAK@Z,malloc,PyErr_NoMemory,_Py_Dealloc,??1PyWinBufferView@@QEAA@XZ,memset,CertDuplicateCertificateContext,_Py_Dealloc,PyEval_SaveThread,CryptEncryptMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyExc_ValueError,PyExc_TypeError,PyErr_SetString,CertFreeCertificateContext,free,malloc,PyExc_MemoryError,PyErr_Format,PyEval_SaveThread,CryptEncryptMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,CertFreeCertificateContext,free,free,15_2_00007FFDE3ADC030
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD578D _PyArg_ParseTupleAndKeywords_SizeT,CryptGetUserKey,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD578D
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD97D0 PyArg_ParseTupleAndKeywords,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyEval_SaveThread,CryptAcquireContextW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,15_2_00007FFDE3AD97D0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADB710 PyArg_ParseTupleAndKeywords,PyExc_ValueError,PyErr_Format,?init@PyWinBufferView@@QEAA_NPEAU_object@@_N1@Z,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyEval_SaveThread,CryptQueryObject,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NoneStruct,_Py_NoneStruct,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,PyLong_FromVoidPtr,_Py_NoneStruct,_Py_NoneStruct,_Py_NewReference,PyLong_FromVoidPtr,Py_BuildValue,??1PyWinBufferView@@QEAA@XZ,PyMem_Free,15_2_00007FFDE3ADB710
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADD710 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,PyLong_AsVoidPtr,PyErr_Occurred,PyErr_Clear,PyBytes_AsString,PyExc_ValueError,PyErr_Format,_Py_NoneStruct,PyExc_NotImplementedError,PyErr_SetString,strcmp,malloc,PyExc_MemoryError,PyErr_Format,strcmp,PyExc_NotImplementedError,PyErr_Format,PyErr_Format,malloc,PyEval_SaveThread,CryptEncodeObjectEx,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,strcmp,free,LocalFree,15_2_00007FFDE3ADD710
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3F10 PyArg_ParseTupleAndKeywords,PyExc_TypeError,PyErr_SetString,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,CryptVerifySignatureW,_Py_NoneStruct,_Py_NoneStruct,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3AD3F10
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4F10 CryptReleaseContext,15_2_00007FFDE3AD4F10
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4F00 CryptReleaseContext,15_2_00007FFDE3AD4F00
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD475B PyArg_ParseTupleAndKeywords,CryptDuplicateKey,GetLastError,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD475B
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD9F50 PyArg_ParseTupleAndKeywords,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyEval_SaveThread,CryptSetProviderExW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,_Py_NoneStruct,_Py_NoneStruct,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,15_2_00007FFDE3AD9F50
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4F40 CryptReleaseContext,15_2_00007FFDE3AD4F40
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADCE70 PyArg_ParseTupleAndKeywords,PyEval_SaveThread,CryptSignMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,PyEval_SaveThread,CryptSignMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,CertFreeCertificateContext,free,free,free,free,15_2_00007FFDE3ADCE70
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADAE60 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyEval_SaveThread,CryptGetKeyIdentifierProperty,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyExc_NotImplementedError,PyErr_SetString,LocalFree,??1PyWinBufferView@@QEAA@XZ,PyMem_Free,15_2_00007FFDE3ADAE60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4E60 CryptMsgClose,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NoneStruct,_Py_NoneStruct,15_2_00007FFDE3AD4E60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD9DF0 PyArg_ParseTupleAndKeywords,PyEval_SaveThread,CryptGetDefaultProviderW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,PyEval_SaveThread,CryptGetDefaultProviderW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,?PyWinObject_FromOLECHAR@@YAPEAU_object@@PEB_W@Z,free,15_2_00007FFDE3AD9DF0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADC5E0 PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptSignAndEncryptMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,PyEval_SaveThread,CryptSignAndEncryptMessage,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,CertFreeCertificateContext,free,CertFreeCertificateContext,free,free,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3ADC5E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADCD80 PyArg_ParseTupleAndKeywords,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,PyEval_SaveThread,CryptGetMessageSignerCount,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyLong_FromLong,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3ADCD80
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4D70 CryptMsgClose,_Py_Dealloc,15_2_00007FFDE3AD4D70
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3DC0 PyArg_ParseTupleAndKeywords,CryptSignHashW,GetLastError,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,CryptSignHashW,GetLastError,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,free,15_2_00007FFDE3AD3DC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD45C0 PyArg_ParseTupleAndKeywords,CryptGetKeyParam,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,CryptGetKeyParam,GetLastError,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyExc_NotImplementedError,PyErr_SetString,free,15_2_00007FFDE3AD45C0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4DC0 CryptMsgClose,_Py_Dealloc,15_2_00007FFDE3AD4DC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADE5A0 _Py_NoneStruct,PyArg_ParseTupleAndKeywords,PyLong_AsVoidPtr,PyErr_Occurred,PyErr_Clear,PyBytes_AsString,PyExc_ValueError,PyErr_Format,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,_Py_NoneStruct,PyExc_ValueError,PyErr_SetString,PyEval_SaveThread,CryptFormatObject,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,PyEval_SaveThread,CryptFormatObject,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,?PyWinObject_FromOLECHAR@@YAPEAU_object@@PEB_W@Z,free,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3ADE5A0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5DA0 _PyArg_ParseTupleAndKeywords_SizeT,PyType_GetFlags,PyExc_TypeError,PyErr_SetString,_PyArg_ParseTupleAndKeywords_SizeT,CryptImportPublicKeyInfo,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD5DA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD3D00 PyArg_ParseTupleAndKeywords,PyExc_TypeError,PyErr_SetString,CryptHashSessionKey,_Py_NoneStruct,_Py_NoneStruct,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3AD3D00
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD2D40 PyExc_ValueError,PyErr_SetString,PyArg_ParseTupleAndKeywords,PyEval_SaveThread,CryptAcquireCertificatePrivateKey,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,CryptContextAddRef,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,_Py_NewReference,Py_BuildValue,15_2_00007FFDE3AD2D40
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADED30 PyArg_ParseTupleAndKeywords,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyEval_SaveThread,CryptStringToBinaryW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,PyBytes_FromStringAndSize,PyEval_SaveThread,CryptStringToBinaryW,PyEval_RestoreThread,_Py_Dealloc,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,Py_BuildValue,PyMem_Free,15_2_00007FFDE3ADED30
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD4D30 CryptMsgClose,_Py_Dealloc,15_2_00007FFDE3AD4D30
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5C60 _PyArg_ParseTupleAndKeywords_SizeT,CryptExportPublicKeyInfo,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,malloc,PyExc_MemoryError,PyErr_Format,CryptExportPublicKeyInfo,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,free,15_2_00007FFDE3AD5C60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADACA0 PyArg_ParseTupleAndKeywords,PyExc_ValueError,PyErr_SetString,PyType_GetFlags,PyExc_TypeError,PyErr_SetString,PyArg_ParseTuple,PyLong_AsLong,PyErr_Occurred,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyBytes_AsString,PyEval_SaveThread,CryptFindOIDInfo,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,15_2_00007FFDE3ADACA0
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\pip-20.2.3.dist-info\LICENSE.txtJump to behavior
Source: 00#U2800.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-39\Release\win32trace.pdb source: explorer.exe, 0000000B.00000003.2182240870.00000261CCBBF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000002.2185839061.00000261CCBDA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2183856176.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-39\Release\win32crypt.pdb source: explorer.exe, 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmp
Source: Binary string: Initial commands are read from .pdbrc files in your home directory source: explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173772225.000002147F298000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149458667.000002147F274000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: .pdbrc source: explorer.exe, 0000000F.00000002.2163298727.0000021402000000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: D:\build-exe\project\target\release\deps\wpsz.pdb source: pdf.exe, 00000009.00000000.1848075257.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp, pdf.exe, 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-39\Release\win32crypt.pdb!! source: explorer.exe, 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmp
Source: Binary string: D:\build-exe\project\target\release\deps\wpsz.pdb# source: pdf.exe, 00000009.00000000.1848075257.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp, pdf.exe, 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: ~/.pdbrc source: explorer.exe, 0000000F.00000002.2163298727.0000021402000000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: placed in the .pdbrc file): source: explorer.exe, 0000000F.00000003.2152998430.000002147A021000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157680273.000002147F400000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167223634.000002147A025000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F3EF000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: pdb.Pdb source: explorer.exe, 0000000F.00000002.2163298727.0000021402000000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\A\31\b\bin\amd64\sqlite3.pdb source: explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmp
Source: Binary string: -c are executed after commands from .pdbrc files. source: explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173772225.000002147F298000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149458667.000002147F274000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: The standard debugger class (pdb.Pdb) is an example. source: explorer.exe, 0000000F.00000003.2138109510.000002147A11B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141978194.000002147A11B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141435604.000002147F2C0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173860089.000002147F2C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167914861.000002147A11B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: If a file ".pdbrc" exists in your home directory or in the current source: explorer.exe, 0000000F.00000003.2157680273.000002147F400000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F3EF000.00000004.00000020.00020000.00000000.sdmp
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE8110 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,11_2_00007FF71DBE8110
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBD7B80 FindFirstFileExW,FindClose,11_2_00007FF71DBD7B80
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF20D4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,11_2_00007FF71DBF20D4
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE8110 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,11_2_00007FF71DBE8110
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI85642\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\
Source: C:\explorerwin\explorer.exeCode function: 4x nop then push rbp15_2_70A2BD40
Source: C:\explorerwin\explorer.exeCode function: 4x nop then push rbp15_2_70A2BD40

Networking

barindex
Source: C:\explorerwin\explorer.exeNetwork Connect: 142.250.191.129 443
Source: Joe Sandbox ViewIP Address: 23.78.8.145 23.78.8.145
Source: global trafficHTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownTCP traffic detected without corresponding DNS query: 23.78.8.145
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /onboarding/smskillreader.txt HTTP/1.1Host: armmf.adobe.comConnection: keep-aliveAccept-Language: en-US,en;q=0.9User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brIf-None-Match: "78-5faa31cce96da"If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
Source: explorer.exe, 0000000F.00000002.2172721648.000002147AED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: YouTube: https://www.youtube.com/c/NeuralNine equals www.youtube.com (Youtube)
Source: global trafficDNS traffic detected: DNS query: drive.usercontent.google.com
Source: explorer.exe, 0000000F.00000002.2163730600.00000214022C0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://.../back.jpeg
Source: explorer.exe, 0000000F.00000002.2172257624.000002147ABE0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://aka.ms/vcpython27
Source: explorer.exe, 0000000F.00000002.2172257624.000002147ABE0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://aka.ms/vcpython27pr
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://arxiv.org/abs/1805.10941.
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141232934.000002147A968000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170231800.000002147A7DA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171543382.000002147A988000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147892239.000002147A7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150774518.000002147F6DB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156575809.000002147F6F0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154103568.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156947101.000002147F46D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156152506.000002147A7D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152165654.000002147F6FB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155304271.000002147A7D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://blog.cryptographyengineering.com/2012/05/how-to-choose-authenticated-encryption.html
Source: explorer.exe, 0000000F.00000002.2176884692.000002147FF60000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://bugs.python.org/issue23606)
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: explorer.exe, 0000000F.00000003.2158552679.0000021402540000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://cffi.readthedocs.io/en/latest/cdef.html#ffi-cdef-limitations
Source: explorer.exe, 0000000F.00000002.2174434845.000002147F4E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154570329.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.certigna.fr/certignarootca.crl01
Source: explorer.exe, 0000000F.00000002.2174540689.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156670444.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153992483.000002147F4F9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl
Source: explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl0
Source: explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl
Source: explorer.exe, 0000000F.00000002.2174434845.000002147F4E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154570329.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl0
Source: explorer.exe, 0000000F.00000003.2137967740.000002147F7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137847675.000002147F72B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl
Source: explorer.exe, 0000000F.00000003.2152165654.000002147F6FB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152006230.000002147F613000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142798938.000002147F614000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl0
Source: explorer.exe, 0000000F.00000003.2137967740.000002147F7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137847675.000002147F72B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crlrt
Source: explorer.exe, 0000000F.00000003.2137967740.000002147F7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137847675.000002147F72B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl
Source: explorer.exe, 0000000F.00000003.2142798938.000002147F614000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl0
Source: explorer.exe, 0000000F.00000003.2137967740.000002147F7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137847675.000002147F72B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
Source: explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154103568.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156947101.000002147F46D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F46B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/groups/ST/toolkit/BCM/documents/proposedmodes/eax/eax-spec.pdf
Source: explorer.exe, 0000000F.00000003.2141232934.000002147A968000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171543382.000002147A988000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156575809.000002147F6F0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142428414.000002147A981000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38C/SP800-38C.pdf
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170231800.000002147A7DA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147892239.000002147A7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156152506.000002147A7D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152165654.000002147F6FB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155304271.000002147A7D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdf
Source: explorer.exe, 0000000F.00000003.2140521903.000002147F4D6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4D6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2164285213.00000214026C0000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2175064070.000002147F6A2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2158552679.0000021402540000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2158739819.00000214025C0000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149904205.000002147F4D6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157401217.000002147F69E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157024057.000002147F72E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137847675.000002147F72B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://csrc.nist.gov/publications/nistpubs/800-38a/sp800-38a.pdf
Source: explorer.exe, 0000000F.00000002.2163730600.00000214022C0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://curl.haxx.se/rfc/cookie_spec.html
Source: explorer.exe, 0000000F.00000003.2143655152.000002147A864000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170484790.000002147A865000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://digitalassets.lib.berkeley.edu/sdtr/ucb/text/34.pdf
Source: explorer.exe, 0000000F.00000003.2149219365.000002147A03A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089873794.000002147A5E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167348102.000002147A03B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089906356.0000021479E34000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089763777.000002147A1AC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/3/library/pprint.html#pprint.pprint
Source: explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/library/unittest.html
Source: explorer.exe, 0000000F.00000002.2169077395.000002147A450000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://github.com/ActiveState/appdirs
Source: explorer.exe, 0000000F.00000002.2163859384.0000021402380000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://goo.gl/zeJZl.
Source: explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156388017.000002147F437000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174405440.000002147F444000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156310082.000002147F1A2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/
Source: explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156388017.000002147F437000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174405440.000002147F444000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/mail
Source: explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170231800.000002147A7DA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147892239.000002147A7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156152506.000002147A7D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155304271.000002147A7D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/mail/
Source: explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155025061.000002147F470000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154103568.000002147F470000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F3EF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153698660.000002147F46F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535
Source: explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156310082.000002147F1A2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://httpbin.org/
Source: explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://json.org
Source: explorer.exe, 0000000F.00000002.2163775231.0000021402300000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://mail.python.org/pipermail/python-dev/2012-June/120787.html.
Source: explorer.exe, 0000000F.00000003.2145146599.000002147F1BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173533640.000002147F1BB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/BinomialDistribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/CauchyDistribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/GammaDistribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/HypergeometricDistribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/LaplaceDistribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/LogisticDistribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/NegativeBinomialDistribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/NoncentralF-Distribution.html
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/PoissonDistribution.html
Source: explorer.exe, 0000000F.00000003.2145146599.000002147F187000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142943087.000002147F16D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143119134.000002147F185000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://mathworld.wolfram.com/SincFunction.html
Source: explorer.exe, 0000000F.00000002.2174540689.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156670444.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153992483.000002147F4F9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es
Source: explorer.exe, 0000000F.00000002.2174540689.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156670444.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153992483.000002147F4F9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es0
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0C
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0O
Source: explorer.exe, 0000000F.00000002.2168769849.000002147A2F0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://opensource.apple.com/source/CF/CF-744.18/CFBinaryPList.c
Source: explorer.exe, 0000000F.00000002.2174375044.000002147F436000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://portaudio.com/docs/v19-doxydocs/portaudio_8h.html#a8a60fb2a5ec9cbade3f54a9c978e2710
Source: explorer.exe, 0000000F.00000003.2143655152.000002147A864000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170484790.000002147A865000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://pracrand.sourceforge.net/RNG_engines.txt
Source: explorer.exe, 0000000F.00000003.2139478910.000002147A612000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://pyparsing.wikispaces.com
Source: explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/
Source: explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/0
Source: explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150833143.000002147F6D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/r1
Source: explorer.exe, 0000000F.00000002.2171956878.000002147AAE0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://stackoverflow.com/questions/19622133/
Source: explorer.exe, 0000000F.00000003.2153185439.0000021479E36000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089873794.000002147A5E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141371601.0000021479E35000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150081732.0000021479E36000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169601562.000002147A61A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139759148.000002147A617000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139397082.000002147A60B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141088457.0000021479E2A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153480068.0000021479E3F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089763777.000002147A1AC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139478910.000002147A612000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://stackoverflow.com/questions/267399/how-do-you-match-only-valid-roman-numerals-with-a-regular-
Source: explorer.exe, 0000000F.00000002.2163818129.0000021402340000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://timgolden.me.uk/python/wmi.html
Source: explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141435604.000002147F2C0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173860089.000002147F2C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tip.tcl.tk/48)
Source: explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc4880
Source: explorer.exe, 0000000F.00000002.2164166200.0000021402640000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2164410605.0000021402780000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc5297
Source: explorer.exe, 0000000F.00000003.2157519328.000002147F472000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156947101.000002147F472000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174434845.000002147F472000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155025061.000002147F470000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154103568.000002147F470000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153698660.000002147F46F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc5869
Source: explorer.exe, 0000000F.00000002.2175099944.000002147F6D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150833143.000002147F6D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://web.cs.ucdavis.edu/~rogaway/ocb/license.htm
Source: explorer.exe, 0000000F.00000002.2174540689.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156670444.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153992483.000002147F4F9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
Source: explorer.exe, 0000000F.00000002.2175099944.000002147F6D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150833143.000002147F6D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
Source: explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0
Source: explorer.exe, 0000000F.00000003.2155424273.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140521903.000002147F4D2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139093209.000002147F4CB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149904205.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174434845.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F4CB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm
Source: explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm0U
Source: explorer.exe, 0000000F.00000003.2155424273.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140521903.000002147F4D2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139093209.000002147F4CB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149904205.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174434845.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F4CB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htmSH
Source: explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140521903.000002147F4D2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139093209.000002147F4CB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149904205.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174434845.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F4CB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es00
Source: explorer.exe, 0000000F.00000003.2142943087.000002147F16D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.ams.org/journals/mcom/1988-51-184/
Source: explorer.exe, 0000000F.00000003.2136544835.000002147F872000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156388017.000002147F437000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136181653.000002147F817000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/
Source: explorer.exe, 0000000F.00000003.2136544835.000002147F872000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/5
Source: explorer.exe, 0000000F.00000003.2136181653.000002147F817000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/C
Source: explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150774518.000002147F6DB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155330030.000002147F6F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cs.ucdavis.edu/~rogaway/papers/keywrap.pdf
Source: explorer.exe, 0000000F.00000003.2158684877.0000021402600000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.dabeaz.com/ply)
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171042561.000002147A8D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A8D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149749022.000002147A8D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.doi.org/10.1109/IEEESTD.2008.4610935
Source: explorer.exe, 0000000F.00000003.2137365771.000002147F86F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141819586.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174939212.000002147F621000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156730575.000002147F621000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2175929087.000002147F86F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136265305.000002147F8A1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149830605.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169824492.000002147A667000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.firmaprofesional.com/cps0
Source: explorer.exe, 0000000F.00000002.2169824492.000002147A667000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/
Source: explorer.exe, 0000000F.00000003.2141819586.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6B3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149830605.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169824492.000002147A667000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.google.com/index.html
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153639849.000002147A773000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148179743.000002147A733000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6
Source: explorer.exe, 0000000F.00000003.2145146599.000002147F1BB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173533640.000002147F1BB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.inference.org.uk/mackay/itila/
Source: explorer.exe, 0000000F.00000002.2163775231.0000021402300000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F4CB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.opensource.org/licenses/mit-license.php
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.pcg-random.org/
Source: explorer.exe, 0000000F.00000003.2146158257.000002147A9D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171716827.000002147A9D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140303857.000002147A9D4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.pcg-random.org/posts/developing-a-seed_seq-alternative.html
Source: explorer.exe, 0000000F.00000003.2143655152.000002147A864000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170484790.000002147A865000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.pcg-random.org/posts/random-invertible-mapping-statistics.html
Source: explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151337033.000002147A6C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170002159.000002147A6C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.python.org/
Source: explorer.exe, 0000000F.00000002.2168846556.000002147A330000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.python.org/dev/peps/pep-0205/
Source: explorer.exe, 0000000F.00000002.2166586976.0000021479EB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.python.org/download/releases/2.3/mro/.
Source: explorer.exe, 0000000F.00000003.2157116193.000002147A199000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps
Source: explorer.exe, 0000000F.00000002.2175099944.000002147F6D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150833143.000002147F6D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.rfc-editor.org/info/rfc7253
Source: explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6B3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.scipy.org/not/real/data.txt
Source: explorer.exe, 0000000F.00000003.2154511765.000002147F6DA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150833143.000002147F6D1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.tarsnap.com/scrypt/scrypt-slides.pdf
Source: explorer.exe, 0000000F.00000003.2141819586.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6B3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149830605.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169824492.000002147A667000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.xyz.edu/data
Source: explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154103568.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156947101.000002147F46D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F46B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://wwwsearch.sf.net/):
Source: explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156388017.000002147F437000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174405440.000002147F444000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://yahoo.com/
Source: explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155250205.000002147A197000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://askubuntu.com/questions/697397/python3-is-not-supporting-gtk-module
Source: explorer.exe, 0000000F.00000002.2163536387.00000214021A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://cloud.google.com/appengine/docs/standard/runtimes
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cryptography.io
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cryptography.io/
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cryptography.io/en/latest/changelog/
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cryptography.io/en/latest/installation/
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cryptography.io/en/latest/security/
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147134776.000002147A8A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://data-apis.org/array-api/latest/design_topics/data_interchange.html#syntax-for-data-interchan
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147134776.000002147A8A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dmlc.github.io/dlpack/latest/python_spec.html
Source: explorer.exe, 0000000F.00000003.2141232934.000002147A968000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148467109.000002147A974000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/library/string.html#format-specification-mini-language
Source: explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148467109.000002147A977000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143287206.000002147A975000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141232934.000002147A968000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169939286.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171504784.000002147A977000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.scipy.org/doc/numpy/user/basics.io.genfromtxt.html
Source: explorer.exe, 0000000F.00000002.2173085615.000002147F050000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.scipy.org/doc/numpy/user/numpy-for-matlab-users.html).
Source: explorer.exe, 0000000F.00000002.2164459135.0000021402830000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2172257624.000002147ABE0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1jXogZ3BVhm3hMU_kRpqaBt9g52obIRtw&export=download
Source: explorer.exe, 0000000F.00000002.2164459135.0000021402830000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1jXogZ3BVhm3hMU_kRpqaBt9g52obIRtw&export=download0
Source: explorer.exe, 0000000F.00000002.2172257624.000002147ABE0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1jXogZ3BVhm3hMU_kRpqaBt9g52obIRtw&export=downloadns
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170030369.000002147A6F5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148179743.000002147A733000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150038408.000002147A6F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1jXogZ3BVhm3hMU_kRpqaBt9g52obIRtw&export=downloadz
Source: explorer.exe, 0000000F.00000003.2146158257.000002147A9D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171716827.000002147A9D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140303857.000002147A9D4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gist.github.com/imneme/540829265469e673d045
Source: explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/Ousret/charset_normalizer
Source: explorer.exe, 0000000F.00000003.2143512645.0000021477DF7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2087401912.0000021477E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143762194.0000021477E81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477DDC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477E48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149245662.0000021477DFB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2165299038.0000021477E83000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_sy
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A8C6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144823824.000002147A8C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144510409.000002147A8B2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/arogozhnikov/einops
Source: explorer.exe, 0000000F.00000002.2163435004.0000021402100000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/asweigart/pyperclip/issues/55
Source: explorer.exe, 0000000F.00000002.2163435004.0000021402100000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/asweigart/pyperclip/issues/550p
Source: explorer.exe, 0000000F.00000002.2163859384.0000021402380000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/giampaolo/psutil/issues/875.
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A927000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/joblib/threadpoolctl
Source: explorer.exe, explorer.exe, 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpString found in binary or memory: https://github.com/mhammond/pywin32
Source: explorer.exe, 0000000F.00000002.2172405009.000002147AD70000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/nu
Source: explorer.exe, 0000000B.00000003.1956032668.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/opencv/opencv/issues/18502)
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pyca/cryptography
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pyca/cryptography/
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pyca/cryptography/actions?query=workflow%3ACI
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pyca/cryptography/issues
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pyca/cryptography/workflows/CI/badge.svg?branch=main
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144187429.000002147A944000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pydata/bottleneck
Source: explorer.exe, 0000000F.00000002.2172011668.000002147AB20000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169112523.000002147A490000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/packaging
Source: explorer.exe, 0000000F.00000002.2172011668.000002147AB20000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169112523.000002147A490000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/packagingEI85642
Source: explorer.exe, 0000000F.00000002.2171909009.000002147AAA0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/1024.
Source: explorer.exe, 0000000F.00000002.2171747782.000002147A9E0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/417#issuecomment-392298401
Source: explorer.exe, 0000000F.00000002.2176745515.000002147FE90000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python-pillow/Pillow/
Source: explorer.exe, 0000000F.00000003.2148940178.000002147A87C000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143655152.000002147A877000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170538643.000002147A87D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/3.7/Objects/listsort.txt
Source: explorer.exe, 0000000F.00000002.2165400349.0000021479670000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688
Source: explorer.exe, 0000000F.00000002.2165299038.0000021477E83000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.py
Source: explorer.exe, 0000000F.00000003.2143512645.0000021477DF7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2087401912.0000021477E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143762194.0000021477E81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477DDC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477E48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149245662.0000021477DFB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2165299038.0000021477E83000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/reader
Source: explorer.exe, 0000000B.00000003.1956032668.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/pull/12302
Source: explorer.exe, 0000000F.00000003.2143512645.0000021477DF7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2087401912.0000021477E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143762194.0000021477E81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477DDC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477E48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149245662.0000021477DFB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2165299038.0000021477E83000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#
Source: explorer.exe, 0000000F.00000003.2158866210.000002147FFB0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/497
Source: explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156310082.000002147F1A2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/
Source: explorer.exe, 0000000F.00000002.2163600273.00000214021E0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/get
Source: explorer.exe, 0000000F.00000002.2174035598.000002147F359000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/post
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://img.shields.io/pypi/v/cryptography.svg
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A817000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170392707.000002147A818000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143145236.000002147A815000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ipython.org
Source: explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151337033.000002147A6C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170002159.000002147A6C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://mahler:8092/site-updates.py
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://mail.python.org/mailman/listinfo/cryptography-dev
Source: explorer.exe, 0000000F.00000003.2145146599.000002147F187000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142943087.000002147F16D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143119134.000002147F185000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://metacpan.org/pod/distribution/Math-Cephes/lib/Math/Cephes.pod#i0:-Modified-Bessel-function-o
Source: explorer.exe, 0000000F.00000002.2163435004.0000021402100000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://mouseinfo.readthedocs.io
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A817000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170392707.000002147A818000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143145236.000002147A815000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151337033.000002147A6C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170030369.000002147A6F5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148179743.000002147A733000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170002159.000002147A6C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150038408.000002147A6F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/devdocs/release/1.20.0-notes.html#deprecations
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170030369.000002147A6F5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150038408.000002147A6F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/devdocs/release/1.20.0-notes.html#deprecations0
Source: explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151337033.000002147A6C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170002159.000002147A6C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/devdocs/release/1.20.0-notes.html#deprecationsft
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170030369.000002147A6F5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150038408.000002147A6F5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/devdocs/release/1.20.0-notes.html#deprecationsusarr
Source: explorer.exe, 0000000F.00000003.2143655152.000002147A877000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/devdocs/release/1.25.0-notes.html
Source: explorer.exe, 0000000F.00000002.2176162075.000002147F950000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/doc/stable/reference/random/index.html
Source: explorer.exe, 0000000B.00000003.1980822855.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.1980822855.00000261CCBDA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/doc/stable/user/basics.subclassing.html
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152193166.000002147A8E0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A8D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149051367.000002147A8DD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149093215.000002147A8DF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://numpy.org/neps/nep-0013-ufunc-overrides.html
Source: explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156388017.000002147F437000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-108r1.pdf
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A8C6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144823824.000002147A8C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144510409.000002147A8B2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://optimized-einsum.readthedocs.io/en/stable/
Source: explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170183828.000002147A7A0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://people.eecs.berkeley.edu/~wkahan/ieee754status/IEEE754.PDF
Source: explorer.exe, 0000000F.00000003.2145146599.000002147F187000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142943087.000002147F16D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143119134.000002147F185000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://personal.math.ubc.ca/~cbm/aands/page_379.htm
Source: explorer.exe, 0000000F.00000003.2149152040.000002147A95D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151833548.000002147A963000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A945000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144187429.000002147A944000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://personal.math.ubc.ca/~cbm/aands/page_69.htm
Source: explorer.exe, 0000000F.00000003.2146626712.000002147A060000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://personal.math.ubc.ca/~cbm/aands/page_79.htm
Source: explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://personal.math.ubc.ca/~cbm/aands/page_86.htm
Source: explorer.exe, 0000000F.00000002.2176884692.000002147FF60000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pyperclip.readthedocs.io/en/latest/index.html#not-implemented-error
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/cryptography/
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial0
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial0u
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial0v
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial0w
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial0x
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial0y
Source: explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/numpy-financial0z
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A927000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171210176.000002147A928000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/threadpoolctl/
Source: explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://readthedocs.org/projects/cryptography/badge/?version=latest
Source: explorer.exe, 0000000F.00000002.2163685429.0000021402270000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174035598.000002147F359000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://requests.readthedocs.io
Source: explorer.exe, 0000000F.00000002.2165836340.0000021479DB9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://scipy-cookbook.readthedocs.io/items/Ctypes.html
Source: explorer.exe, 0000000F.00000003.2152357276.000002147A047000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2087769941.0000021479E91000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144663359.000002147A046000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167519396.000002147A048000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2087665137.000002147A015000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140779141.000002147A03F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.readthedocs.io/en/latest/pkg_resources.html#basic-resource-access
Source: explorer.exe, 0000000F.00000002.2176837743.000002147FF20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/18905702/python-ctypes-and-mutable-buffers
Source: explorer.exe, 0000000F.00000002.2163859384.0000021402380000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/4457745#4457745.
Source: explorer.exe, 0000000F.00000002.2176837743.000002147FF20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/455434/how-should-i-use-formatmessage-properly-in-c
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://stat.ethz.ch/~stahel/lognormal/bioscience.pdf
Source: explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173772225.000002147F298000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149458667.000002147F274000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc2388#section-4.4
Source: explorer.exe, 0000000F.00000003.2141232934.000002147A968000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171543382.000002147A988000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156575809.000002147F6F0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142428414.000002147A981000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc3610
Source: explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150774518.000002147F6DB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155330030.000002147F6F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc5297
Source: explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156310082.000002147F1A2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://twitter.com/
Source: explorer.exe, 0000000F.00000002.2171956878.000002147AAE0000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171909009.000002147AAA0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://upload.pypi.org/legacy/
Source: explorer.exe, 0000000F.00000002.2172011668.000002147AB20000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://upload.pypi.org/legacy/p
Source: explorer.exe, 0000000F.00000002.2163536387.00000214021A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/1.26.x/advanced-usage.html#ssl-warnings
Source: explorer.exe, 0000000F.00000003.2139505452.000002147A1CF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137389439.000002147A1CC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168400237.000002147A1CF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://w3c.github.io/html/sec-forms.html#multipart-form-data
Source: explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.archive.org/web/20080221202153/https://www.math.hmc.edu/~benjamin/papers/CombTrig.pdf
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.archive.org/web/20090423014010/http://www.brighton-webs.co.uk:80/distributions/wald.asp
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web.archive.org/web/20090514091424/http://brighton-webs.co.uk:80/distributions/rayleigh.asp
Source: explorer.exe, 0000000F.00000002.2165836340.0000021479DB9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wiki.debian.org/XDGBaseDirectorySpecification#state
Source: explorer.exe, 0000000B.00000003.1953659387.00000261CCBE3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.apache.org/licenses/LICENSE-2.0
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.cs.hmc.edu/tr/hmc-cs-2014-0905.pdf
Source: explorer.exe, 0000000B.00000003.1931128115.00000261CCBE2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.digicert.com/CPS0
Source: explorer.exe, 0000000F.00000002.2175064070.000002147F6A2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157401217.000002147F69E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ietf.org/rfc/rfc2898.txt
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.itl.nist.gov/div898/handbook/eda/section3/eda3663.htm
Source: explorer.exe, 0000000F.00000003.2146158257.000002147A9D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171716827.000002147A9D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140303857.000002147A9D4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.itl.nist.gov/div898/handbook/eda/section3/eda3666.htm
Source: explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.itl.nist.gov/div898/software/dataplot/refman2/auxillar/powpdf.pdf
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A927000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171210176.000002147A928000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.mathworks.com/help/techdoc/ref/rank.html
Source: explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A927000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.openblas.net/
Source: explorer.exe, 0000000F.00000002.2174035598.000002147F359000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org
Source: explorer.exe, 0000000F.00000002.2172721648.000002147AED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.youtube.com/c/NeuralNine
Source: explorer.exe, 0000000F.00000003.2136544835.000002147F872000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136181653.000002147F817000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/
Source: explorer.exe, 0000000F.00000002.2174434845.000002147F4E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154570329.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/0m
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD5AF0 _Py_NoneStruct,_PyArg_ParseTupleAndKeywords_SizeT,PyExc_TypeError,PyErr_SetString,??0PyWinBufferView@@QEAA@PEAU_object@@_N1@Z,CryptImportKey,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,??1PyWinBufferView@@QEAA@XZ,15_2_00007FFDE3AD5AF0
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1FEE10 NtWriteFile,WaitForSingleObject,RtlNtStatusToDosError,9_2_00007FF70A1FEE10
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A97091: DeviceIoControl,15_2_70A97091
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1FF3909_2_00007FF70A1FF390
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1F14709_2_00007FF70A1F1470
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A2024F09_2_00007FF70A2024F0
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A2012309_2_00007FF70A201230
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1FA2609_2_00007FF70A1FA260
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A20BF909_2_00007FF70A20BF90
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A20C5709_2_00007FF70A20C570
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A203DB09_2_00007FF70A203DB0
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A207E609_2_00007FF70A207E60
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF656011_2_00007FF71DBF6560
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE811011_2_00007FF71DBE8110
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF74AC11_2_00007FF71DBF74AC
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBD6B5011_2_00007FF71DBD6B50
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBEA6F011_2_00007FF71DBEA6F0
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE270411_2_00007FF71DBE2704
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE365411_2_00007FF71DBE3654
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBEEDF011_2_00007FF71DBEEDF0
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE15A011_2_00007FF71DBE15A0
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE0D8011_2_00007FF71DBE0D80
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF490C11_2_00007FF71DBF490C
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF20D411_2_00007FF71DBF20D4
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF67DC11_2_00007FF71DBF67DC
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE17A411_2_00007FF71DBE17A4
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF6F6011_2_00007FF71DBF6F60
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE7F5C11_2_00007FF71DBE7F5C
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBEE77011_2_00007FF71DBEE770
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE0F8411_2_00007FF71DBE0F84
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBEE2DC11_2_00007FF71DBEE2DC
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE3A5811_2_00007FF71DBE3A58
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE811011_2_00007FF71DBE8110
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE321C11_2_00007FF71DBE321C
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBFA1E811_2_00007FF71DBFA1E8
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE618011_2_00007FF71DBE6180
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE899411_2_00007FF71DBE8994
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE119011_2_00007FF71DBE1190
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF112811_2_00007FF71DBF1128
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBD84A011_2_00007FF71DBD84A0
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF447011_2_00007FF71DBF4470
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF112811_2_00007FF71DBF1128
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE236C11_2_00007FF71DBE236C
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE139411_2_00007FF71DBE1394
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A0E6F015_2_70A0E6F0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A0A7B015_2_70A0A7B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A6FFB015_2_70A6FFB0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3A0A015_2_70A3A0A0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3D80015_2_70A3D800
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3E86015_2_70A3E860
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A7719015_2_70A77190
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A2711015_2_70A27110
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3B11015_2_70A3B110
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A7D91015_2_70A7D910
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A2394015_2_70A23940
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A5E14015_2_70A5E140
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A4395015_2_70A43950
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A6E15015_2_70A6E150
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A35AF015_2_70A35AF0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A0F22015_2_70A0F220
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3827015_2_70A38270
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3625015_2_70A36250
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A013E015_2_70A013E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A6C33015_2_70A6C330
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3D31015_2_70A3D310
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A2236015_2_70A22360
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A5737015_2_70A57370
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A6BB7015_2_70A6BB70
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3EC8015_2_70A3EC80
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A34C2015_2_70A34C20
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A6CC1515_2_70A6CC15
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A24DA015_2_70A24DA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A265B015_2_70A265B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A965E015_2_70A965E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A7DDF015_2_70A7DDF0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A38DC015_2_70A38DC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A6EDC015_2_70A6EDC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A7E51015_2_70A7E510
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3157015_2_70A31570
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A2254015_2_70A22540
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A2BD4015_2_70A2BD40
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A41D4015_2_70A41D40
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3B55015_2_70A3B550
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A436D015_2_70A436D0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A07E2015_2_70A07E20
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A31E3015_2_70A31E30
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A6D63015_2_70A6D630
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A29E7015_2_70A29E70
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A18E4015_2_70A18E40
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A56FE215_2_70A56FE2
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A0F7C015_2_70A0F7C0
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A3CF2015_2_70A3CF20
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A36F0015_2_70A36F00
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A4070015_2_70A40700
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A26F7015_2_70A26F70
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD945015_2_00007FFDE3AD9450
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD91F015_2_00007FFDE3AD91F0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AD517015_2_00007FFDE3AD5170
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BFB44015_2_00007FFDE3BFB440
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BDB44015_2_00007FFDE3BDB440
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BCD44015_2_00007FFDE3BCD440
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BCB40015_2_00007FFDE3BCB400
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6737015_2_00007FFDE3B67370
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BAF38015_2_00007FFDE3BAF380
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B5932015_2_00007FFDE3B59320
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6D2E015_2_00007FFDE3B6D2E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B5D2E015_2_00007FFDE3B5D2E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B4722115_2_00007FFDE3B47221
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BF11B015_2_00007FFDE3BF11B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BFA11015_2_00007FFDE3BFA110
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B760D015_2_00007FFDE3B760D0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BFC0D015_2_00007FFDE3BFC0D0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BBB09015_2_00007FFDE3BBB090
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BEC7B015_2_00007FFDE3BEC7B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B4977015_2_00007FFDE3B49770
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6E70015_2_00007FFDE3B6E700
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BEF70015_2_00007FFDE3BEF700
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BCE6A015_2_00007FFDE3BCE6A0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B8D6B015_2_00007FFDE3B8D6B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BAE68015_2_00007FFDE3BAE680
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B5162015_2_00007FFDE3B51620
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6863015_2_00007FFDE3B68630
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B5560015_2_00007FFDE3B55600
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BCC5A015_2_00007FFDE3BCC5A0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B4F5D015_2_00007FFDE3B4F5D0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BB257015_2_00007FFDE3BB2570
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B9452015_2_00007FFDE3B94520
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6255015_2_00007FFDE3B62550
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3C064B015_2_00007FFDE3C064B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B4348015_2_00007FFDE3B43480
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B4FBE015_2_00007FFDE3B4FBE0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BEEC1015_2_00007FFDE3BEEC10
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B5CBA015_2_00007FFDE3B5CBA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B9CBB015_2_00007FFDE3B9CBB0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BC7B3015_2_00007FFDE3BC7B30
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B7DB4015_2_00007FFDE3B7DB40
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BD5B1015_2_00007FFDE3BD5B10
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B78AA015_2_00007FFDE3B78AA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BB8AB015_2_00007FFDE3BB8AB0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B71AC015_2_00007FFDE3B71AC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BF8AD015_2_00007FFDE3BF8AD0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BA9A8015_2_00007FFDE3BA9A80
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B50A9015_2_00007FFDE3B50A90
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BF3A3015_2_00007FFDE3BF3A30
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BA69E015_2_00007FFDE3BA69E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BF2A1015_2_00007FFDE3BF2A10
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B8496015_2_00007FFDE3B84960
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6F96015_2_00007FFDE3B6F960
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BF991015_2_00007FFDE3BF9910
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6402015_2_00007FFDE3B64020
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B4B05015_2_00007FFDE3B4B050
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BCFFB015_2_00007FFDE3BCFFB0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B69FC015_2_00007FFDE3B69FC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BE9FD015_2_00007FFDE3BE9FD0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B9EF9015_2_00007FFDE3B9EF90
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B6DF3015_2_00007FFDE3B6DF30
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BB4F4015_2_00007FFDE3BB4F40
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BCEF5015_2_00007FFDE3BCEF50
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BB5E6015_2_00007FFDE3BB5E60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B42E6C15_2_00007FFDE3B42E6C
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BA7E2015_2_00007FFDE3BA7E20
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B93E2015_2_00007FFDE3B93E20
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BF5E2015_2_00007FFDE3BF5E20
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B46E3E15_2_00007FFDE3B46E3E
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BD1CB015_2_00007FFDE3BD1CB0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3B8ACC015_2_00007FFDE3B8ACC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BB6C6015_2_00007FFDE3BB6C60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3BE8C6015_2_00007FFDE3BE8C60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FEA8C015_2_00007FFDE3FEA8C0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE402A1A015_2_00007FFDE402A1A0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE407B46015_2_00007FFDE407B460
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE4038D3015_2_00007FFDE4038D30
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FC853015_2_00007FFDE3FC8530
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FF756015_2_00007FFDE3FF7560
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FDFD6015_2_00007FFDE3FDFD60
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FAA5A015_2_00007FFDE3FAA5A0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FADDA015_2_00007FFDE3FADDA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE400668015_2_00007FFDE4006680
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F63E9015_2_00007FFDE3F63E90
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FABE9015_2_00007FFDE3FABE90
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F586A915_2_00007FFDE3F586A9
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE404A6E015_2_00007FFDE404A6E0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FC57D015_2_00007FFDE3FC57D0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FFC89015_2_00007FFDE3FFC890
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FBA8C015_2_00007FFDE3FBA8C0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE406A10015_2_00007FFDE406A100
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE402B17015_2_00007FFDE402B170
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F5395D15_2_00007FFDE3F5395D
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F5F17015_2_00007FFDE3F5F170
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FF917015_2_00007FFDE3FF9170
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F5397715_2_00007FFDE3F53977
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F4218E15_2_00007FFDE3F4218E
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE40309F015_2_00007FFDE40309F0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FB120015_2_00007FFDE3FB1200
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE4008A0015_2_00007FFDE4008A00
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE4050A2015_2_00007FFDE4050A20
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FAAA4015_2_00007FFDE3FAAA40
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE406D26015_2_00007FFDE406D260
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F51AC015_2_00007FFDE3F51AC0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F6B2F015_2_00007FFDE3F6B2F0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F6CB2015_2_00007FFDE3F6CB20
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FC939015_2_00007FFDE3FC9390
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FD9BA015_2_00007FFDE3FD9BA0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3FADBB015_2_00007FFDE3FADBB0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F62BF015_2_00007FFDE3F62BF0
Source: C:\explorerwin\explorer.exeCode function: String function: 00007FFDE3B49030 appears 124 times
Source: C:\explorerwin\explorer.exeCode function: String function: 00007FFDE4027370 appears 791 times
Source: C:\explorerwin\explorer.exeCode function: String function: 70A04230 appears 238 times
Source: C:\explorerwin\explorer.exeCode function: String function: 70A2D400 appears 325 times
Source: C:\explorerwin\explorer.exeCode function: String function: 00007FFDE3B4A300 appears 181 times
Source: C:\explorerwin\explorer.exeCode function: String function: 00007FFDE3B48D90 appears 32 times
Source: C:\explorerwin\explorer.exeCode function: String function: 00007FFDE403E7E0 appears 104 times
Source: C:\explorerwin\explorer.exeCode function: String function: 00007FF71DBD2010 appears 52 times
Source: C:\explorerwin\explorer.exeCode function: String function: 70A96CA0 appears 192 times
Source: C:\explorerwin\explorer.exeCode function: String function: 00007FFDE4038170 appears 59 times
Source: C:\explorerwin\explorer.exeCode function: String function: 70A96730 appears 31 times
Source: C:\explorerwin\pdf.exeCode function: String function: 00007FF70A20B850 appears 73 times
Source: opencv_videoio_ffmpeg490_64.dll.11.drStatic PE information: Number of sections : 13 > 10
Source: _pytransform.dll.11.drStatic PE information: Number of sections : 11 > 10
Source: cv2.pyd.11.drStatic PE information: Number of sections : 15 > 10
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: Number of sections : 19 > 10
Source: python3.dll.11.drStatic PE information: No import functions for PE file found
Source: classification engineClassification label: mal84.evad.winEXE@25/1074@4/2
Source: None.pdf.0.drInitial sample: https://www.adobe.com/vn_en/documentcloud/integrations.html
Source: None.pdf.0.drInitial sample: https://www.adobe.com/vn_en/acrobat.html
Source: None.pdf.0.drInitial sample: https://www.adobe.com/vn_en/sign.html
Source: None.pdf.0.drInitial sample: https://www.adobe.com/vn_en/documentcloud/resources.html
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1FEF70 GetModuleHandleW,FormatMessageW,GetLastError,9_2_00007FF70A1FEF70
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADA8FF _Py_NoneStruct,PyArg_ParseTupleAndKeywords,PyExc_TypeError,PyErr_SetString,?PyWinObject_AsWCHAR@@YAHPEAU_object@@PEAPEA_WHPEAK@Z,PyEval_SaveThread,CertOpenSystemStoreW,PyEval_RestoreThread,?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,_Py_NewReference,PyLong_FromVoidPtr,?PyWinObject_FreeWCHAR@@YAXPEA_W@Z,15_2_00007FFDE3ADA8FF
Source: C:\Users\user\Desktop\00#U2800.exeFile created: C:\Users\user\None.pdfJump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8400:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7288:120:WilError_03
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8636:120:WilError_03
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeFile created: C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2024-05-10 10-38-17-789.logJump to behavior
Source: C:\explorerwin\pdf.exeProcess created: C:\explorerwin\explorer.exe
Source: C:\explorerwin\explorer.exeProcess created: C:\explorerwin\explorer.exe
Source: C:\explorerwin\pdf.exeProcess created: C:\explorerwin\explorer.exeJump to behavior
Source: C:\explorerwin\explorer.exeProcess created: C:\explorerwin\explorer.exeJump to behavior
Source: 00#U2800.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\00#U2800.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmpBinary or memory string: UPDATE %Q.%s SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: explorer.exe, explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmpBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
Source: explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmpBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmpBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmpBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmpBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: unknownProcess created: C:\Users\user\Desktop\00#U2800.exe "C:\Users\user\Desktop\00#U2800.exe"
Source: C:\Users\user\Desktop\00#U2800.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\00#U2800.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\None.pdf"
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1896 --field-trial-handle=1640,i,18113123113952577735,16265978303955578204,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
Source: C:\Users\user\Desktop\00#U2800.exeProcess created: C:\explorerwin\pdf.exe "C:\explorerwin\pdf.exe"
Source: C:\explorerwin\pdf.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\explorerwin\pdf.exeProcess created: C:\explorerwin\explorer.exe "C:\explorerwin\explorer.exe"
Source: C:\explorerwin\explorer.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\explorerwin\explorer.exeProcess created: C:\explorerwin\explorer.exe "C:\explorerwin\explorer.exe"
Source: C:\Users\user\Desktop\00#U2800.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\None.pdf"Jump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeProcess created: C:\explorerwin\pdf.exe "C:\explorerwin\pdf.exe" Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1896 --field-trial-handle=1640,i,18113123113952577735,16265978303955578204,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8Jump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess created: unknown unknownJump to behavior
Source: C:\explorerwin\pdf.exeProcess created: C:\explorerwin\explorer.exe "C:\explorerwin\explorer.exe" Jump to behavior
Source: C:\explorerwin\explorer.exeProcess created: C:\explorerwin\explorer.exe "C:\explorerwin\explorer.exe" Jump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: appresolver.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: dlnashext.dllJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeSection loaded: wpdshext.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: apphelp.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: wldp.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: propsys.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: dlnashext.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: wpdshext.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: profapi.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: edputil.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: urlmon.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: iertutil.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: srvcli.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: netutils.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: sspicli.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: wintypes.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: appresolver.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: slc.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: userenv.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: sppc.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\explorerwin\pdf.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\explorerwin\explorer.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\explorerwin\explorer.exeSection loaded: version.dll
Source: C:\explorerwin\explorer.exeSection loaded: vcruntime140.dll
Source: C:\explorerwin\explorer.exeSection loaded: cryptsp.dll
Source: C:\explorerwin\explorer.exeSection loaded: rsaenh.dll
Source: C:\explorerwin\explorer.exeSection loaded: cryptbase.dll
Source: C:\explorerwin\explorer.exeSection loaded: libffi-7.dll
Source: C:\explorerwin\explorer.exeSection loaded: iphlpapi.dll
Source: C:\explorerwin\explorer.exeSection loaded: vcruntime140_1.dll
Source: C:\explorerwin\explorer.exeSection loaded: kernel.appcore.dll
Source: C:\explorerwin\explorer.exeSection loaded: uxtheme.dll
Source: C:\explorerwin\explorer.exeSection loaded: urlmon.dll
Source: C:\explorerwin\explorer.exeSection loaded: iertutil.dll
Source: C:\explorerwin\explorer.exeSection loaded: srvcli.dll
Source: C:\explorerwin\explorer.exeSection loaded: netutils.dll
Source: C:\explorerwin\explorer.exeSection loaded: secur32.dll
Source: C:\explorerwin\explorer.exeSection loaded: sspicli.dll
Source: C:\explorerwin\explorer.exeSection loaded: libcrypto-1_1.dll
Source: C:\explorerwin\explorer.exeSection loaded: libssl-1_1.dll
Source: C:\explorerwin\explorer.exeSection loaded: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll
Source: C:\explorerwin\explorer.exeSection loaded: wsock32.dll
Source: C:\explorerwin\explorer.exeSection loaded: mfplat.dll
Source: C:\explorerwin\explorer.exeSection loaded: mf.dll
Source: C:\explorerwin\explorer.exeSection loaded: mfreadwrite.dll
Source: C:\explorerwin\explorer.exeSection loaded: dxgi.dll
Source: C:\explorerwin\explorer.exeSection loaded: d3d11.dll
Source: C:\explorerwin\explorer.exeSection loaded: mfcore.dll
Source: C:\explorerwin\explorer.exeSection loaded: powrprof.dll
Source: C:\explorerwin\explorer.exeSection loaded: ksuser.dll
Source: C:\explorerwin\explorer.exeSection loaded: rtworkq.dll
Source: C:\explorerwin\explorer.exeSection loaded: umpdc.dll
Source: C:\explorerwin\explorer.exeSection loaded: tcl86t.dll
Source: C:\explorerwin\explorer.exeSection loaded: tk86t.dll
Source: C:\explorerwin\explorer.exeSection loaded: netapi32.dll
Source: C:\explorerwin\explorer.exeSection loaded: userenv.dll
Source: C:\explorerwin\explorer.exeSection loaded: logoncli.dll
Source: C:\explorerwin\explorer.exeSection loaded: samcli.dll
Source: C:\explorerwin\explorer.exeSection loaded: winmm.dll
Source: C:\explorerwin\explorer.exeSection loaded: sqlite3.dll
Source: C:\explorerwin\explorer.exeSection loaded: mswsock.dll
Source: C:\explorerwin\explorer.exeSection loaded: pdh.dll
Source: C:\explorerwin\explorer.exeSection loaded: wtsapi32.dll
Source: C:\explorerwin\explorer.exeSection loaded: wbemcomn.dll
Source: C:\explorerwin\explorer.exeSection loaded: amsi.dll
Source: C:\explorerwin\explorer.exeSection loaded: profapi.dll
Source: C:\explorerwin\explorer.exeSection loaded: sxs.dll
Source: C:\explorerwin\explorer.exeSection loaded: dnsapi.dll
Source: C:\explorerwin\explorer.exeSection loaded: rasadhlp.dll
Source: C:\explorerwin\explorer.exeSection loaded: fwpuclnt.dll
Source: C:\Users\user\Desktop\00#U2800.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: 00#U2800.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: 00#U2800.exeStatic file information: File size 103126528 > 1048576
Source: 00#U2800.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0x6226400
Source: 00#U2800.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: 00#U2800.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: 00#U2800.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: 00#U2800.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: 00#U2800.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: 00#U2800.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: 00#U2800.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: 00#U2800.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-39\Release\win32trace.pdb source: explorer.exe, 0000000B.00000003.2182240870.00000261CCBBF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000002.2185839061.00000261CCBDA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000B.00000003.2183856176.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-39\Release\win32crypt.pdb source: explorer.exe, 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmp
Source: Binary string: Initial commands are read from .pdbrc files in your home directory source: explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173772225.000002147F298000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149458667.000002147F274000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: .pdbrc source: explorer.exe, 0000000F.00000002.2163298727.0000021402000000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: D:\build-exe\project\target\release\deps\wpsz.pdb source: pdf.exe, 00000009.00000000.1848075257.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp, pdf.exe, 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: C:\src\pywin32\build\temp.win-amd64-cpython-39\Release\win32crypt.pdb!! source: explorer.exe, 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmp
Source: Binary string: D:\build-exe\project\target\release\deps\wpsz.pdb# source: pdf.exe, 00000009.00000000.1848075257.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp, pdf.exe, 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: ~/.pdbrc source: explorer.exe, 0000000F.00000002.2163298727.0000021402000000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: placed in the .pdbrc file): source: explorer.exe, 0000000F.00000003.2152998430.000002147A021000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157680273.000002147F400000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167223634.000002147A025000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F3EF000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: pdb.Pdb source: explorer.exe, 0000000F.00000002.2163298727.0000021402000000.00000004.00001000.00020000.00000000.sdmp
Source: Binary string: C:\A\31\b\bin\amd64\sqlite3.pdb source: explorer.exe, 0000000F.00000002.2177444462.00007FFDE3C71000.00000002.00000001.01000000.00000036.sdmp
Source: Binary string: -c are executed after commands from .pdbrc files. source: explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173772225.000002147F298000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149458667.000002147F274000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: The standard debugger class (pdb.Pdb) is an example. source: explorer.exe, 0000000F.00000003.2138109510.000002147A11B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141978194.000002147A11B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141435604.000002147F2C0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173860089.000002147F2C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167914861.000002147A11B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: If a file ".pdbrc" exists in your home directory or in the current source: explorer.exe, 0000000F.00000003.2157680273.000002147F400000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F3EF000.00000004.00000020.00020000.00000000.sdmp
Source: 00#U2800.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: 00#U2800.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: 00#U2800.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: 00#U2800.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: 00#U2800.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1F20C0 SetConsoleTitleW,LoadLibraryW,GetProcAddress,FreeLibrary,GetLastError,9_2_00007FF70A1F20C0
Source: win32crypt.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x256d7
Source: pythoncom39.dll.11.drStatic PE information: real checksum: 0x0 should be: 0xa5dd3
Source: win32pdh.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x16842
Source: sip.cp39-win_amd64.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x24b34
Source: dlll.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x288cb
Source: win32api.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x303a5
Source: _raw_aes.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x8efc
Source: _win32sysloader.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0xac6f
Source: _psutil_windows.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x1d3ed
Source: pdf.exe.0.drStatic PE information: real checksum: 0x0 should be: 0x4a6cc
Source: _ARC4.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0xa862
Source: pywintypes39.dll.11.drStatic PE information: real checksum: 0x0 should be: 0x224d8
Source: _pkcs1_decode.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0xd979
Source: _rust.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x66978e
Source: _pytransform.dll.11.drStatic PE information: real checksum: 0x125b11 should be: 0x129952
Source: shell.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x8c2ed
Source: _chacha20.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x6311
Source: win32trace.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x6dfc
Source: _cffi_backend.cp39-win_amd64.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x30e31
Source: win32ui.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x123856
Source: QtWidgets.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x4efb51
Source: _Salsa20.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0xe4da
Source: _portaudio.cp39-win_amd64.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x49b6f
Source: QtCore.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x26aff7
Source: QtGui.pyd.11.drStatic PE information: real checksum: 0x0 should be: 0x2629b6
Source: explorer.exe.0.drStatic PE information: section name: _RDATA
Source: mfc140u.dll.11.drStatic PE information: section name: .didat
Source: VCRUNTIME140.dll.11.drStatic PE information: section name: _RDATA
Source: _pytransform.dll.11.drStatic PE information: section name: .xdata
Source: opencv_videoio_ffmpeg490_64.dll.11.drStatic PE information: section name: .rodata
Source: opencv_videoio_ffmpeg490_64.dll.11.drStatic PE information: section name: .xdata
Source: libcrypto-1_1.dll.11.drStatic PE information: section name: .00cfg
Source: libssl-1_1.dll.11.drStatic PE information: section name: .00cfg
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: .xdata
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /4
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /19
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /31
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /45
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /57
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /70
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /81
Source: libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dll.11.drStatic PE information: section name: /92
Source: cv2.pyd.11.drStatic PE information: section name: IPPCODE
Source: cv2.pyd.11.drStatic PE information: section name: IPPDATA
Source: cv2.pyd.11.drStatic PE information: section name: _RDATA
Source: cv2.pyd.11.drStatic PE information: section name: .debug_a
Source: cv2.pyd.11.drStatic PE information: section name: .debug_i
Source: cv2.pyd.11.drStatic PE information: section name: .debug_s
Source: cv2.pyd.11.drStatic PE information: section name: .debug_l
Source: _portaudio.cp39-win_amd64.pyd.11.drStatic PE information: section name: _RDATA
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DC1510C push rcx; retf 0000h11_2_00007FF71DC1510D
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC7425 push 60F5C5F1h; iretd 15_2_00007FFDE3CC742D
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC4AEE push 6FFDC5D5h; iretd 15_2_00007FFDE3CC4AF4
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC79CF push 6FFDC5C3h; iretd 15_2_00007FFDE3CC79D5
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC7983 push 6FFDC5CAh; ret 15_2_00007FFDE3CC7989
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC4FEA push 6FFDC5C3h; iretd 15_2_00007FFDE3CC4FF0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC4F9E push 6FFDC5CAh; ret 15_2_00007FFDE3CC4FA4
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC76D3 push 6FFDC5D5h; iretd 15_2_00007FFDE3CC76D9
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3CC4640 push 60F5C5F1h; iretd 15_2_00007FFDE3CC4648
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F6F7AF push rsp; iretd 15_2_00007FFDE3F6F7B0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F6F941 push rbp; iretd 15_2_00007FFDE3F6F942
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F70241 push rbp; iretd 15_2_00007FFDE3F70242
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3F6F31A push rbp; iretd 15_2_00007FFDE3F6F31B

Persistence and Installation Behavior

barindex
Source: C:\explorerwin\explorer.exeCode function: memset,wsprintfA,CreateFileA,memset,DeviceIoControl,CloseHandle,isxdigit,isxdigit,isxdigit,isprint,memcpy,CloseHandle,strlen,memcpy, \\.\PhysicalDrive%d15_2_70A22B90
Source: C:\explorerwin\explorer.exeCode function: _snprintf,_snprintf,CreateFileA,CreateFileA,GlobalAlloc,DeviceIoControl,GlobalFree,_snprintf,CreateFileA,GlobalAlloc,GlobalAlloc,GlobalAlloc,DeviceIoControl,GlobalFree,GlobalFree,GlobalFree,CloseHandle,GlobalFree,GlobalFree,GlobalFree,GlobalFree,CloseHandle, \\.\PhysicalDrive%d15_2_70A227E0
Source: C:\Users\user\Desktop\00#U2800.exeFile created: C:\explorerwin\explorer.exeJump to dropped file
Source: C:\explorerwin\explorer.exeProcess created: "C:\explorerwin\explorer.exe"
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_bz2.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\win32com\shell\shell.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_mt19937.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32api.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\bit_generator.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtCore.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_asyncio.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_pcg64.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\unicodedata.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\linalg\_umath_linalg.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_Salsa20.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32trace.pydJump to dropped file
Source: C:\Users\user\Desktop\00#U2800.exeFile created: C:\explorerwin\dlll.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\sip.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\mfc140u.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_cffi_backend.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_uuid.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32pdh.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_queue.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_lzma.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\mtrand.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\VCRUNTIME140.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_common.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\libssl-1_1.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\fft\_pocketfft_internal.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\python39.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\select.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_philox.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_bounded_integers.cp39-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\00#U2800.exeFile created: C:\explorerwin\pdf.exeJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2\opencv_videoio_ffmpeg490_64.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\pyexpat.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\win32ui.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_sqlite3.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\core\_multiarray_umath.cp39-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\00#U2800.exeFile created: C:\explorerwin\dll.dllJump to dropped file
Source: C:\Users\user\Desktop\00#U2800.exeFile created: C:\explorerwin\explorer.exeJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2\cv2.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\pywin32_system32\pythoncom39.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\psutil\_psutil_windows.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_chacha20.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtWidgets.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32crypt.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\pywin32_system32\pywintypes39.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy.libs\libopenblas64__v0.3.23-293-gc2f4bdbb-gcc_10_3_0-2bde3a66a51006b2b53eb373ff767a3f.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\python3.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_sfc64.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\libffi-7.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_pytransform.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\libcrypto-1_1.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_pkcs1_decode.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_ARC4.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\tk86t.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_decimal.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_generator.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\_win32sysloader.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\pyaudio\_portaudio.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography\hazmat\bindings\_rust.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_socket.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\VCRUNTIME140_1.dllJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_ssl.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\core\_multiarray_tests.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_multiprocessing.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_ctypes.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtGui.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_tkinter.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_hashlib.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\_overlapped.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_raw_aes.pydJump to dropped file
Source: C:\explorerwin\explorer.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI85642\pip-20.2.3.dist-info\LICENSE.txtJump to behavior

Boot Survival

barindex
Source: C:\explorerwin\explorer.exeCode function: memset,wsprintfA,CreateFileA,memset,DeviceIoControl,CloseHandle,isxdigit,isxdigit,isxdigit,isprint,memcpy,CloseHandle,strlen,memcpy, \\.\PhysicalDrive%d15_2_70A22B90
Source: C:\explorerwin\explorer.exeCode function: _snprintf,_snprintf,CreateFileA,CreateFileA,GlobalAlloc,DeviceIoControl,GlobalFree,_snprintf,CreateFileA,GlobalAlloc,GlobalAlloc,GlobalAlloc,DeviceIoControl,GlobalFree,GlobalFree,GlobalFree,CloseHandle,GlobalFree,GlobalFree,GlobalFree,GlobalFree,CloseHandle, \\.\PhysicalDrive%d15_2_70A227E0

Hooking and other Techniques for Hiding and Protection

barindex
Source: initial sampleIcon embedded in binary file: icon matches a legit application icon: download (98).png
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBD60F0 GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,11_2_00007FF71DBD60F0
Source: C:\Users\user\Desktop\00#U2800.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\explorerwin\pdf.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\explorerwin\explorer.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_bz2.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_mt19937.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\win32com\shell\shell.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32api.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\bit_generator.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtCore.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_asyncio.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_pcg64.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\unicodedata.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\linalg\_umath_linalg.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_Salsa20.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32trace.pydJump to dropped file
Source: C:\Users\user\Desktop\00#U2800.exeDropped PE file which has not been started: C:\explorerwin\dlll.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\sip.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\mfc140u.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_cffi_backend.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_uuid.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32pdh.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_queue.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_lzma.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\mtrand.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_common.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\select.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\python39.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\fft\_pocketfft_internal.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_philox.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_bounded_integers.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\pyexpat.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2\opencv_videoio_ffmpeg490_64.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\win32ui.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_sqlite3.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\core\_multiarray_umath.cp39-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\00#U2800.exeDropped PE file which has not been started: C:\explorerwin\dll.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2\cv2.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\pywin32_system32\pythoncom39.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\psutil\_psutil_windows.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_chacha20.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtWidgets.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\win32crypt.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\pywin32_system32\pywintypes39.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\python3.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_sfc64.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_pytransform.dllJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_pkcs1_decode.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_ARC4.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_decimal.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random\_generator.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\win32\_win32sysloader.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\pyaudio\_portaudio.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography\hazmat\bindings\_rust.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_socket.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_ssl.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\core\_multiarray_tests.cp39-win_amd64.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_multiprocessing.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_ctypes.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtGui.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_tkinter.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_overlapped.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\_hashlib.pydJump to dropped file
Source: C:\explorerwin\explorer.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_raw_aes.pydJump to dropped file
Source: C:\explorerwin\explorer.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_11-16884
Source: C:\explorerwin\pdf.exeAPI coverage: 9.4 %
Source: C:\explorerwin\explorer.exeAPI coverage: 2.0 %
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE8110 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,11_2_00007FF71DBE8110
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBD7B80 FindFirstFileExW,FindClose,11_2_00007FF71DBD7B80
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF20D4 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,11_2_00007FF71DBF20D4
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBE8110 _invalid_parameter_noinfo,FindFirstFileExW,GetLastError,_invalid_parameter_noinfo,FindNextFileW,GetLastError,11_2_00007FF71DBE8110
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A06A70 GetSystemInfo,VirtualAlloc,VirtualAlloc,15_2_70A06A70
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI85642\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\AppData\
Source: C:\explorerwin\explorer.exeFile opened: C:\Users\user\
Source: explorer.exe, 0000000F.00000003.2152998430.000002147A021000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167223634.000002147A025000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeProcess information queried: ProcessInformationJump to behavior

Anti Debugging

barindex
Source: C:\explorerwin\explorer.exeThread information set: HideFromDebugger
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A20E9E4 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_00007FF70A20E9E4
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1F20C0 SetConsoleTitleW,LoadLibraryW,GetProcAddress,FreeLibrary,GetLastError,9_2_00007FF70A1F20C0
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1FD370 HeapReAlloc,GetProcessHeap,HeapAlloc,memmove,HeapFree,9_2_00007FF70A1FD370
Source: C:\explorerwin\explorer.exeProcess token adjusted: Debug
Source: C:\explorerwin\explorer.exeProcess token adjusted: Debug
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A1F7F30 RtlAddVectoredExceptionHandler,SetThreadStackGuarantee,GetLastError,9_2_00007FF70A1F7F30
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A20EB88 SetUnhandledExceptionFilter,9_2_00007FF70A20EB88
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A20E9E4 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,9_2_00007FF70A20E9E4
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBEAE98 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,11_2_00007FF71DBEAE98
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBDBA5C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,11_2_00007FF71DBDBA5C
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBDB1B0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,11_2_00007FF71DBDB1B0
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBDBC04 SetUnhandledExceptionFilter,11_2_00007FF71DBDBC04
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A95380 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort,15_2_70A95380
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AE039C IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,15_2_00007FFDE3AE039C
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3ADF798 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,15_2_00007FFDE3ADF798
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3AE0584 SetUnhandledExceptionFilter,15_2_00007FFDE3AE0584
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE3C6F3E4 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,15_2_00007FFDE3C6F3E4
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE4086264 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,15_2_00007FFDE4086264
Source: C:\Users\user\Desktop\00#U2800.exeMemory allocated: page read and write | page guardJump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\explorerwin\explorer.exeNetwork Connect: 142.250.191.129 443
Source: C:\explorerwin\explorer.exeThread register set: target process: 8636
Source: C:\explorerwin\explorer.exeThread register set: target process: 8636
Source: C:\explorerwin\explorer.exeThread register set: target process: 8636
Source: C:\Users\user\Desktop\00#U2800.exeProcess created: C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\None.pdf"Jump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeProcess created: C:\explorerwin\pdf.exe "C:\explorerwin\pdf.exe" Jump to behavior
Source: C:\explorerwin\pdf.exeProcess created: C:\explorerwin\explorer.exe "C:\explorerwin\explorer.exe" Jump to behavior
Source: C:\explorerwin\explorer.exeProcess created: C:\explorerwin\explorer.exe "C:\explorerwin\explorer.exe" Jump to behavior
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBFA030 cpuid 11_2_00007FF71DBFA030
Source: C:\Users\user\Desktop\00#U2800.exeQueries volume information: C:\explorerwin VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeQueries volume information: C:\explorerwin VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeQueries volume information: C:\explorerwin VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeQueries volume information: C:\explorerwin VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\00#U2800.exeQueries volume information: C:\explorerwin VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Hash VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Hash VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Hash VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Hash VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Hash VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\PublicKey VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\PublicKey VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Util VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PIL VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PIL VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PIL VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PIL VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins\imageformats VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins\imageformats VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins\imageformats VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins\platforms VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\plugins\platforms VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5\translations VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\Qt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\certifi VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cryptography-41.0.7.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2\misc VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\cv2 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\core VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\numpy\random VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\pip-20.2.3.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\pip-20.2.3.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\pip-20.2.3.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\pip-20.2.3.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\pip-20.2.3.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\setuptools-49.2.1.dist-info VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl8 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl8\8.4 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl8 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl8\8.5 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl8 VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\encoding VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl\msgs VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\tcl VolumeInformationJump to behavior
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\explorer.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI85642\base_library.zip VolumeInformation
Source: C:\explorerwin\pdf.exeCode function: 9_2_00007FF70A20E8C0 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,9_2_00007FF70A20E8C0
Source: C:\explorerwin\explorer.exeCode function: 15_2_00007FFDE4079710 GetUserNameW,15_2_00007FFDE4079710
Source: C:\explorerwin\explorer.exeCode function: 11_2_00007FF71DBF6560 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,11_2_00007FF71DBF6560
Source: C:\explorerwin\explorer.exeCode function: 15_2_70A70CFC GetVersion,GetCurrentThread,15_2_70A70CFC
Source: C:\explorerwin\explorer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Spearphishing Link
2
Native API
1
Bootkit
211
Process Injection
21
Masquerading
OS Credential Dumping2
System Time Discovery
Remote Services11
Archive Collected Data
21
Encrypted Channel
Exfiltration Over Other Network Medium1
Data Encrypted for Impact
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
LSASS Memory121
Security Software Discovery
Remote Desktop ProtocolData from Removable Media1
Ingress Tool Transfer
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
Disable or Modify Tools
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive2
Non-Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook211
Process Injection
NTDS1
Process Discovery
Distributed Component Object ModelInput Capture13
Application Layer Protocol
Traffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Deobfuscate/Decode Files or Information
LSA Secrets1
Account Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
Obfuscated Files or Information
Cached Domain Credentials1
System Owner/User Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
Bootkit
DCSync3
File and Directory Discovery
Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
Install Root Certificate
Proc Filesystem25
System Information Discovery
Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
DLL Side-Loading
/etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1439459 Sample: 00#U2800.exe Startdate: 10/05/2024 Architecture: WINDOWS Score: 84 51 drive.usercontent.google.com 2->51 57 Icon mismatch, binary includes an icon from a different legit application in order to fool users 2->57 59 Sigma detected: System File Execution Location Anomaly 2->59 61 Sigma detected: Files With System Process Name In Unsuspected Locations 2->61 9 00#U2800.exe 3 10 2->9         started        signatures3 process4 file5 43 C:\explorerwin\pdf.exe, PE32+ 9->43 dropped 45 C:\explorerwin\explorer.exe, PE32+ 9->45 dropped 47 C:\explorerwin\dlll.dll, PE32+ 9->47 dropped 49 C:\explorerwin\dll.dll, PE32+ 9->49 dropped 67 Drops PE files with benign system names 9->67 13 pdf.exe 2 9->13         started        15 Acrobat.exe 17 75 9->15         started        17 conhost.exe 9->17         started        signatures6 process7 process8 19 explorer.exe 1002 13->19         started        23 conhost.exe 13->23         started        25 AcroCEF.exe 105 15->25         started        file9 35 C:\Users\user\AppData\Local\...\shell.pyd, PE32+ 19->35 dropped 37 C:\Users\user\AppData\...\win32trace.pyd, PE32+ 19->37 dropped 39 C:\Users\user\AppData\Local\...\win32pdh.pyd, PE32+ 19->39 dropped 41 65 other files (none is malicious) 19->41 dropped 63 Contains functionality to infect the boot sector 19->63 65 Found pyInstaller with non standard icon 19->65 27 explorer.exe 19->27         started        31 conhost.exe 19->31         started        33 AcroCEF.exe 2 25->33         started        signatures10 process11 dnsIp12 53 drive.usercontent.google.com 142.250.191.129, 443, 49749, 49750 GOOGLEUS United States 27->53 69 System process connects to network (likely due to code injection or exploit) 27->69 71 Modifies the context of a thread in another process (thread injection) 27->71 73 Hides threads from debuggers 27->73 55 23.78.8.145, 443, 49747 AS6453US United States 33->55 signatures13

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
00#U2800.exe3%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_ARC4.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_ARC4.pyd3%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_Salsa20.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_Salsa20.pyd4%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_chacha20.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_chacha20.pyd3%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_pkcs1_decode.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_pkcs1_decode.pyd3%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_raw_aes.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_raw_aes.pyd1%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtCore.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtCore.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtGui.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtGui.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtWidgets.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\QtWidgets.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\sip.cp39-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\PyQt5\sip.cp39-win_amd64.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\mfc140u.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\mfc140u.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\win32ui.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\Pythonwin\win32ui.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\VCRUNTIME140.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\VCRUNTIME140.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\VCRUNTIME140_1.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\VCRUNTIME140_1.dll0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_asyncio.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_asyncio.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_bz2.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_bz2.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_cffi_backend.cp39-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_cffi_backend.cp39-win_amd64.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_ctypes.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_ctypes.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_decimal.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_decimal.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_hashlib.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_hashlib.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_lzma.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_lzma.pyd0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\_MEI85642\_multiprocessing.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI85642\_multiprocessing.pyd0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://crl.dhimyotis.com/certignarootca.crl00%URL Reputationsafe
http://crl.dhimyotis.com/certignarootca.crl00%URL Reputationsafe
http://crl.dhimyotis.com/certignarootca.crl0%URL Reputationsafe
http://crl.dhimyotis.com/certignarootca.crl0%URL Reputationsafe
https://wwww.certigna.fr/autorites/0m0%URL Reputationsafe
http://crl.securetrust.com/STCA.crl0%URL Reputationsafe
http://www.accv.es000%URL Reputationsafe
http://crl.securetrust.com/SGCA.crl00%URL Reputationsafe
http://ocsp.accv.es00%URL Reputationsafe
http://crl.securetrust.com/SGCA.crlrt0%Avira URL Cloudsafe
https://dmlc.github.io/dlpack/latest/python_spec.html0%Avira URL Cloudsafe
https://mahler:8092/site-updates.py0%Avira URL Cloudsafe
http://www.pcg-random.org/posts/developing-a-seed_seq-alternative.html0%Avira URL Cloudsafe
https://w3c.github.io/html/sec-forms.html#multipart-form-data0%Avira URL Cloudsafe
http://www.pcg-random.org/0%Avira URL Cloudsafe
https://www.openblas.net/0%Avira URL Cloudsafe
http://www.pcg-random.org/posts/developing-a-seed_seq-alternative.html0%VirustotalBrowse
https://dmlc.github.io/dlpack/latest/python_spec.html0%VirustotalBrowse
http://www.pcg-random.org/0%VirustotalBrowse
https://www.openblas.net/0%VirustotalBrowse
https://w3c.github.io/html/sec-forms.html#multipart-form-data0%VirustotalBrowse
http://crl.securetrust.com/SGCA.crlrt0%VirustotalBrowse
NameIPActiveMaliciousAntivirus DetectionReputation
drive.usercontent.google.com
142.250.191.129
truefalse
    high
    NameSourceMaliciousAntivirus DetectionReputation
    https://numpy.org/devdocs/release/1.20.0-notes.html#deprecationsexplorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151337033.000002147A6C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170030369.000002147A6F5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148179743.000002147A733000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170002159.000002147A6C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150038408.000002147A6F5000.00000004.00000020.00020000.00000000.sdmpfalse
      high
      http://www.scipy.org/not/real/data.txtexplorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6B3000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        https://github.com/giampaolo/psutil/issues/875.explorer.exe, 0000000F.00000002.2163859384.0000021402380000.00000004.00001000.00020000.00000000.sdmpfalse
          high
          https://cloud.google.com/appengine/docs/standard/runtimesexplorer.exe, 0000000F.00000002.2163536387.00000214021A0000.00000004.00001000.00020000.00000000.sdmpfalse
            high
            http://crl.dhimyotis.com/certignarootca.crl0explorer.exe, 0000000F.00000002.2174434845.000002147F4E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154570329.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmpfalse
            • URL Reputation: safe
            • URL Reputation: safe
            unknown
            https://web.archive.org/web/20090514091424/http://brighton-webs.co.uk:80/distributions/rayleigh.aspexplorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpfalse
              high
              http://repository.swisssign.com/0explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpfalse
                high
                http://docs.python.org/library/unittest.htmlexplorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#explorer.exe, 0000000F.00000003.2143512645.0000021477DF7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2087401912.0000021477E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143762194.0000021477E81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477DDC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477E48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149245662.0000021477DFB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2165299038.0000021477E83000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    http://crl.securetrust.com/SGCA.crlrtexplorer.exe, 0000000F.00000003.2137967740.000002147F7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137847675.000002147F72B000.00000004.00000020.00020000.00000000.sdmpfalse
                    • 0%, Virustotal, Browse
                    • Avira URL Cloud: safe
                    unknown
                    http://goo.gl/zeJZl.explorer.exe, 0000000F.00000002.2163859384.0000021402380000.00000004.00001000.00020000.00000000.sdmpfalse
                      high
                      https://www.apache.org/licenses/LICENSE-2.0explorer.exe, 0000000B.00000003.1953659387.00000261CCBE3000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        https://dmlc.github.io/dlpack/latest/python_spec.htmlexplorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147134776.000002147A8A6000.00000004.00000020.00020000.00000000.sdmpfalse
                        • 0%, Virustotal, Browse
                        • Avira URL Cloud: safe
                        unknown
                        https://github.com/pypa/packagingexplorer.exe, 0000000F.00000002.2172011668.000002147AB20000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169112523.000002147A490000.00000004.00001000.00020000.00000000.sdmpfalse
                          high
                          http://www.opensource.org/licenses/mit-license.phpexplorer.exe, 0000000F.00000002.2163775231.0000021402300000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F4CB000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://personal.math.ubc.ca/~cbm/aands/page_379.htmexplorer.exe, 0000000F.00000003.2145146599.000002147F187000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142943087.000002147F16D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143119134.000002147F185000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://tools.ietf.org/html/rfc3610explorer.exe, 0000000F.00000003.2141232934.000002147A968000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171543382.000002147A988000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156575809.000002147F6F0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142428414.000002147A981000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpfalse
                                high
                                http://crl.dhimyotis.com/certignarootca.crlexplorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpfalse
                                • URL Reputation: safe
                                • URL Reputation: safe
                                unknown
                                http://curl.haxx.se/rfc/cookie_spec.htmlexplorer.exe, 0000000F.00000002.2163730600.00000214022C0000.00000004.00001000.00020000.00000000.sdmpfalse
                                  high
                                  http://arxiv.org/abs/1805.10941.explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    http://json.orgexplorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmpfalse
                                      high
                                      https://numpy.org/devdocs/release/1.20.0-notes.html#deprecations0explorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170030369.000002147A6F5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150038408.000002147A6F5000.00000004.00000020.00020000.00000000.sdmpfalse
                                        high
                                        http://httpbin.org/explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156310082.000002147F1A2000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          https://www.youtube.com/c/NeuralNineexplorer.exe, 0000000F.00000002.2172721648.000002147AED0000.00000004.00001000.00020000.00000000.sdmpfalse
                                            high
                                            http://mathworld.wolfram.com/NegativeBinomialDistribution.htmlexplorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpfalse
                                              high
                                              https://pypi.org/project/numpy-financial0yexplorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                high
                                                https://pypi.org/project/numpy-financial0zexplorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                  high
                                                  https://pypi.org/project/numpy-financial0wexplorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                    high
                                                    https://pypi.org/project/numpy-financial0xexplorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                      high
                                                      https://wwww.certigna.fr/autorites/0mexplorer.exe, 0000000F.00000002.2174434845.000002147F4E3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174602010.000002147F52A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154570329.000002147F4E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F519000.00000004.00000020.00020000.00000000.sdmpfalse
                                                      • URL Reputation: safe
                                                      unknown
                                                      https://pypi.org/project/numpy-financial0uexplorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                        high
                                                        https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/readerexplorer.exe, 0000000F.00000003.2143512645.0000021477DF7000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2087401912.0000021477E7D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143762194.0000021477E81000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477DDC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138301396.0000021477E48000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149245662.0000021477DFB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2165299038.0000021477E83000.00000004.00000020.00020000.00000000.sdmpfalse
                                                          high
                                                          https://pypi.org/project/numpy-financial0vexplorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                            high
                                                            https://www.itl.nist.gov/div898/software/dataplot/refman2/auxillar/powpdf.pdfexplorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              high
                                                              http://mail.python.org/pipermail/python-dev/2012-June/120787.html.explorer.exe, 0000000F.00000002.2163775231.0000021402300000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                high
                                                                https://httpbin.org/explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156310082.000002147F1A2000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  high
                                                                  https://github.com/pyca/cryptography/workflows/CI/badge.svg?branch=mainexplorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                    high
                                                                    https://numpy.org/devdocs/release/1.20.0-notes.html#deprecationsusarrexplorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170030369.000002147A6F5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150038408.000002147A6F5000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                      high
                                                                      https://numpy.org/doc/stable/reference/random/index.htmlexplorer.exe, 0000000F.00000002.2176162075.000002147F950000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                        high
                                                                        http://www.pcg-random.org/posts/developing-a-seed_seq-alternative.htmlexplorer.exe, 0000000F.00000003.2146158257.000002147A9D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171716827.000002147A9D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140303857.000002147A9D4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                        • 0%, Virustotal, Browse
                                                                        • Avira URL Cloud: safe
                                                                        unknown
                                                                        https://metacpan.org/pod/distribution/Math-Cephes/lib/Math/Cephes.pod#i0:-Modified-Bessel-function-oexplorer.exe, 0000000F.00000003.2145146599.000002147F187000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142943087.000002147F16D000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143119134.000002147F185000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          high
                                                                          http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155025061.000002147F470000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154103568.000002147F470000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F3EF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153698660.000002147F46F000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                            high
                                                                            https://cryptography.io/en/latest/installation/explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                              high
                                                                              http://mathworld.wolfram.com/CauchyDistribution.htmlexplorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                high
                                                                                https://github.com/pypa/setuptools/issues/417#issuecomment-392298401explorer.exe, 0000000F.00000002.2171747782.000002147A9E0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  https://wiki.debian.org/XDGBaseDirectorySpecification#stateexplorer.exe, 0000000F.00000002.2165836340.0000021479DB9000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                    high
                                                                                    http://crl.securetrust.com/STCA.crlexplorer.exe, 0000000F.00000003.2137967740.000002147F7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137847675.000002147F72B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                    • URL Reputation: safe
                                                                                    unknown
                                                                                    http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0explorer.exe, 0000000F.00000002.2174540689.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156670444.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153992483.000002147F4F9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                      high
                                                                                      https://github.com/python/cpython/pull/12302explorer.exe, 0000000B.00000003.1956032668.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        http://www.cert.fnmt.es/dpcs/explorer.exe, 0000000F.00000003.2136544835.000002147F872000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156388017.000002147F437000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136181653.000002147F817000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                          high
                                                                                          https://askubuntu.com/questions/697397/python3-is-not-supporting-gtk-moduleexplorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155250205.000002147A197000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            http://www.accv.es00explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155424273.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140521903.000002147F4D2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139093209.000002147F4CB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149904205.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174434845.000002147F4D3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F4CB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            • URL Reputation: safe
                                                                                            unknown
                                                                                            http://www.rfc-editor.org/info/rfc7253explorer.exe, 0000000F.00000002.2175099944.000002147F6D5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150833143.000002147F6D1000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://github.com/pyca/cryptography/issuesexplorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                high
                                                                                                https://pypi.org/project/numpy-financial0explorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                  high
                                                                                                  https://web.archive.org/web/20080221202153/https://www.math.hmc.edu/~benjamin/papers/CombTrig.pdfexplorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    https://mahler:8092/site-updates.pyexplorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151337033.000002147A6C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170002159.000002147A6C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    • Avira URL Cloud: safe
                                                                                                    low
                                                                                                    https://optimized-einsum.readthedocs.io/en/stable/explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A8C6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144823824.000002147A8C5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144510409.000002147A8B2000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                      high
                                                                                                      https://cryptography.io/explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                        high
                                                                                                        https://pyperclip.readthedocs.io/en/latest/index.html#not-implemented-errorexplorer.exe, 0000000F.00000002.2176884692.000002147FF60000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                          high
                                                                                                          http://www.firmaprofesional.com/cps0explorer.exe, 0000000F.00000003.2137365771.000002147F86F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141819586.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174939212.000002147F621000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156730575.000002147F621000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2175929087.000002147F86F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136265305.000002147F8A1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149830605.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169824492.000002147A667000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                            high
                                                                                                            https://mouseinfo.readthedocs.ioexplorer.exe, 0000000F.00000002.2163435004.0000021402100000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                              high
                                                                                                              http://crl.securetrust.com/SGCA.crl0explorer.exe, 0000000F.00000003.2152165654.000002147F6FB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152006230.000002147F613000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142798938.000002147F614000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                              • URL Reputation: safe
                                                                                                              unknown
                                                                                                              http://www.google.com/index.htmlexplorer.exe, 0000000F.00000003.2141819586.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6B3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149830605.000002147A667000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169824492.000002147A667000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                high
                                                                                                                http://repository.swisssign.com/r1explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150833143.000002147F6D1000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                  high
                                                                                                                  http://tip.tcl.tk/48)explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2141435604.000002147F2C0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139550490.000002147F264000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173860089.000002147F2C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140052775.000002147F270000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                    high
                                                                                                                    https://github.com/python/cpython/blob/3.7/Objects/listsort.txtexplorer.exe, 0000000F.00000003.2148940178.000002147A87C000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143655152.000002147A877000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170538643.000002147A87D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                      high
                                                                                                                      http://pracrand.sourceforge.net/RNG_engines.txtexplorer.exe, 0000000F.00000003.2143655152.000002147A864000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170484790.000002147A865000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                        high
                                                                                                                        https://w3c.github.io/html/sec-forms.html#multipart-form-dataexplorer.exe, 0000000F.00000003.2139505452.000002147A1CF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2137389439.000002147A1CC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168400237.000002147A1CF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                        • 0%, Virustotal, Browse
                                                                                                                        • Avira URL Cloud: safe
                                                                                                                        unknown
                                                                                                                        https://stat.ethz.ch/~stahel/lognormal/bioscience.pdfexplorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                          high
                                                                                                                          https://cryptography.io/en/latest/changelog/explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                            high
                                                                                                                            https://mail.python.org/mailman/listinfo/cryptography-devexplorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                              high
                                                                                                                              https://pypi.org/project/numpy-financialexplorer.exe, 0000000F.00000002.2176360352.000002147FA50000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                high
                                                                                                                                https://www.openblas.net/explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A927000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                • 0%, Virustotal, Browse
                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                unknown
                                                                                                                                https://github.com/pypa/setuptools/issues/1024.explorer.exe, 0000000F.00000002.2171909009.000002147AAA0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  https://github.com/asweigart/pyperclip/issues/550pexplorer.exe, 0000000F.00000002.2163435004.0000021402100000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                    high
                                                                                                                                    http://ocsp.accv.es0explorer.exe, 0000000F.00000002.2174540689.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156530027.000002147F5BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2154046947.000002147F588000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156670444.000002147F4FA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155058857.000002147F5BA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153992483.000002147F4F9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138862087.000002147F4D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150467163.000002147F587000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                    • URL Reputation: safe
                                                                                                                                    unknown
                                                                                                                                    http://docs.python.org/3/library/pprint.html#pprint.pprintexplorer.exe, 0000000F.00000003.2149219365.000002147A03A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089873794.000002147A5E1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2167348102.000002147A03B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089906356.0000021479E34000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2089763777.000002147A1AC000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                      high
                                                                                                                                      http://digitalassets.lib.berkeley.edu/sdtr/ucb/text/34.pdfexplorer.exe, 0000000F.00000003.2143655152.000002147A864000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170484790.000002147A865000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                        high
                                                                                                                                        https://twitter.com/explorer.exe, 0000000F.00000003.2148432403.000002147F19F000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136791228.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144344031.000002147F46B000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151451570.000002147F4B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156310082.000002147F1A2000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                          high
                                                                                                                                          https://stackoverflow.com/questions/4457745#4457745.explorer.exe, 0000000F.00000002.2163859384.0000021402380000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                            high
                                                                                                                                            https://numpy.org/devdocs/release/1.20.0-notes.html#deprecationsftexplorer.exe, 0000000F.00000003.2139702598.000002147A6AF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2138479613.000002147A663000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136322454.000002147A652000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146568159.000002147A6BF000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151337033.000002147A6C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170002159.000002147A6C8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143582001.000002147A6B5000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2149506197.000002147A6BF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                              high
                                                                                                                                              http://www.quovadisglobal.com/cpsexplorer.exe, 0000000F.00000003.2157116193.000002147A199000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                high
                                                                                                                                                http://www.pcg-random.org/explorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                • 0%, Virustotal, Browse
                                                                                                                                                • Avira URL Cloud: safe
                                                                                                                                                unknown
                                                                                                                                                https://numpy.org/devdocs/release/1.25.0-notes.htmlexplorer.exe, 0000000F.00000003.2143655152.000002147A877000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                  high
                                                                                                                                                  https://github.com/pydata/bottleneckexplorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2144187429.000002147A944000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                    high
                                                                                                                                                    https://img.shields.io/pypi/v/cryptography.svgexplorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                      high
                                                                                                                                                      https://people.eecs.berkeley.edu/~wkahan/ieee754status/IEEE754.PDFexplorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170183828.000002147A7A0000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                        high
                                                                                                                                                        http://google.com/mail/explorer.exe, 0000000F.00000003.2145146599.000002147F194000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170231800.000002147A7DA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147892239.000002147A7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156152506.000002147A7D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155304271.000002147A7D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                          high
                                                                                                                                                          http://pyparsing.wikispaces.comexplorer.exe, 0000000F.00000003.2139478910.000002147A612000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                            high
                                                                                                                                                            http://mathworld.wolfram.com/GammaDistribution.htmlexplorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                              high
                                                                                                                                                              https://www.itl.nist.gov/div898/handbook/eda/section3/eda3663.htmexplorer.exe, 0000000F.00000003.2145823616.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139187721.000002147F1B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2173568946.000002147F1C4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171619290.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148531382.000002147F1C2000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140703420.000002147F1C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152403876.000002147A9BD000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2148910112.000002147A9BC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146996116.000002147A9B4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139932990.000002147A9A4000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2139814748.000002147A964000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                high
                                                                                                                                                                http://www.cert.fnmt.es/dpcs/Cexplorer.exe, 0000000F.00000003.2136181653.000002147F817000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                  high
                                                                                                                                                                  https://tools.ietf.org/html/rfc5297explorer.exe, 0000000F.00000003.2139326997.000002147F6CA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2150774518.000002147F6DB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155330030.000002147F6F9000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                    high
                                                                                                                                                                    https://pypi.org/project/threadpoolctl/explorer.exe, 0000000F.00000003.2142620400.000002147A8A6000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2145562268.000002147A927000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2143354975.000002147A921000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2171210176.000002147A928000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                      high
                                                                                                                                                                      https://github.com/pypa/packagingEI85642explorer.exe, 0000000F.00000002.2172011668.000002147AB20000.00000004.00001000.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2169112523.000002147A490000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                        high
                                                                                                                                                                        https://cryptography.ioexplorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                          high
                                                                                                                                                                          http://google.com/mailexplorer.exe, 0000000F.00000003.2144344031.000002147F424000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2140602458.000002147A189000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156388017.000002147F437000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2151612243.000002147F430000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2174405440.000002147F444000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2157889584.000002147A18A000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2153732175.000002147F435000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2168085705.000002147A18E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                            high
                                                                                                                                                                            https://pypi.org/project/cryptography/explorer.exe, 0000000B.00000003.1953776464.00000261CCBD8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                              high
                                                                                                                                                                              http://csrc.nist.gov/publications/nistpubs/800-38D/SP-800-38D.pdfexplorer.exe, 0000000F.00000003.2138658019.000002147A6F3000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000002.2170231800.000002147A7DA000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142297981.000002147A796000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2147892239.000002147A7C1000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2146464575.000002147A79E000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2156152506.000002147A7D9000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2152165654.000002147F6FB000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2155304271.000002147A7D8000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2136608283.000002147F6DC000.00000004.00000020.00020000.00000000.sdmp, explorer.exe, 0000000F.00000003.2142185412.000002147A788000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                high
                                                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                                                • 75% < No. of IPs
                                                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                23.78.8.145
                                                                                                                                                                                unknownUnited States
                                                                                                                                                                                6453AS6453USfalse
                                                                                                                                                                                142.250.191.129
                                                                                                                                                                                drive.usercontent.google.comUnited States
                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                Joe Sandbox version:40.0.0 Tourmaline
                                                                                                                                                                                Analysis ID:1439459
                                                                                                                                                                                Start date and time:2024-05-10 10:37:17 +02:00
                                                                                                                                                                                Joe Sandbox product:CloudBasic
                                                                                                                                                                                Overall analysis duration:0h 10m 10s
                                                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                                                Report type:full
                                                                                                                                                                                Cookbook file name:default.jbs
                                                                                                                                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                Number of analysed new started processes analysed:18
                                                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                                                Technologies:
                                                                                                                                                                                • HCA enabled
                                                                                                                                                                                • EGA enabled
                                                                                                                                                                                • AMSI enabled
                                                                                                                                                                                Analysis Mode:default
                                                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                                                Sample name:00#U2800.exe
                                                                                                                                                                                renamed because original name is a hash value
                                                                                                                                                                                Original Sample Name: 2024 - SM Entertainment ASIA.pdf .exe
                                                                                                                                                                                Detection:MAL
                                                                                                                                                                                Classification:mal84.evad.winEXE@25/1074@4/2
                                                                                                                                                                                EGA Information:
                                                                                                                                                                                • Successful, ratio: 100%
                                                                                                                                                                                HCA Information:
                                                                                                                                                                                • Successful, ratio: 87%
                                                                                                                                                                                • Number of executed functions: 75
                                                                                                                                                                                • Number of non-executed functions: 234
                                                                                                                                                                                Cookbook Comments:
                                                                                                                                                                                • Found application associated with file extension: .exe
                                                                                                                                                                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                                                                                                                                                • Excluded IPs from analysis (whitelisted): 104.122.47.18, 23.220.206.57, 23.220.206.48, 54.144.73.197, 34.193.227.236, 107.22.247.231, 18.207.85.246, 172.64.41.3, 162.159.61.3
                                                                                                                                                                                • Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, geo2.adobe.com
                                                                                                                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                                • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                                                                                                • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                                • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                                • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                                                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                                No simulations
                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                23.78.8.14555678_70USD.xlsGet hashmaliciousUnknownBrowse
                                                                                                                                                                                  https://1drv.ms/u/s!AvRvEmgJ5d9kgly3z-uh2_ANgH5hGet hashmaliciousUnknownBrowse
                                                                                                                                                                                    April Doc_fdp.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                      XCIlhzFXdplpXdhQXCyywBkGlU.ps1Get hashmaliciousNetSupport RATBrowse
                                                                                                                                                                                        https://www.dropbox.com/scl/fi/5r8uxa49x6mxtzyj6eule/pdf.zip?rlkey=bgar34hwvlq9j03y0pskhparp&dl=1Get hashmaliciousUnknownBrowse
                                                                                                                                                                                          No context
                                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                          AS6453US55678_70USD.xlsGet hashmaliciousUnknownBrowse
                                                                                                                                                                                          • 23.78.8.145
                                                                                                                                                                                          https://1drv.ms/u/s!AvRvEmgJ5d9kgly3z-uh2_ANgH5hGet hashmaliciousUnknownBrowse
                                                                                                                                                                                          • 23.78.8.145
                                                                                                                                                                                          Aimmy.zipGet hashmaliciousUnknownBrowse
                                                                                                                                                                                          • 23.78.9.173
                                                                                                                                                                                          April Doc_fdp.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                          • 23.78.8.145
                                                                                                                                                                                          XCIlhzFXdplpXdhQXCyywBkGlU.ps1Get hashmaliciousNetSupport RATBrowse
                                                                                                                                                                                          • 23.78.8.145
                                                                                                                                                                                          TsDTSDr8mU.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                          • 64.86.213.105
                                                                                                                                                                                          https://www.steam.workshopslist.com/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                          • 23.78.8.100
                                                                                                                                                                                          EdO1baKdpe.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                                                          • 80.231.55.226
                                                                                                                                                                                          https://www.msn.com/en-us/autos/enthusiasts/what-s-the-difference-between-a-shelby-mustang-and-a-regular-mustang/ar-AA1ntM5Z?ocid=entnewsntp&pc=U531&cvid=8b8aa9e3e14d4164a6a2181020104694&ei=36Get hashmaliciousUnknownBrowse
                                                                                                                                                                                          • 23.218.224.156
                                                                                                                                                                                          No context
                                                                                                                                                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                          C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_ARC4.pydprank.exeGet hashmaliciousDiscord Token StealerBrowse
                                                                                                                                                                                            SecuriteInfo.com.FileRepMalware.5539.23420.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                              SecuriteInfo.com.FileRepMalware.5539.23420.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                SecuriteInfo.com.MacOS.ReverseShell-C.30585.8425.exeGet hashmaliciousPython Stealer, Discord Token StealerBrowse
                                                                                                                                                                                                  MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zipGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                    MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zipGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                      SecuriteInfo.com.FileRepMalware.7114.13860.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                        SecuriteInfo.com.FileRepMalware.7114.13860.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                          SecuriteInfo.com.W64.ABRisk.PVEG-3846.30817.29399.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                            SecuriteInfo.com.Trojan.GenericKD.70641791.20493.31768.exeGet hashmaliciousPython Stealer, CStealerBrowse
                                                                                                                                                                                                              C:\Users\user\AppData\Local\Temp\_MEI85642\Crypto\Cipher\_Salsa20.pydprank.exeGet hashmaliciousDiscord Token StealerBrowse
                                                                                                                                                                                                                SecuriteInfo.com.FileRepMalware.5539.23420.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  SecuriteInfo.com.FileRepMalware.5539.23420.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                    SecuriteInfo.com.MacOS.ReverseShell-C.30585.8425.exeGet hashmaliciousPython Stealer, Discord Token StealerBrowse
                                                                                                                                                                                                                      MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zipGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                        MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zipGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                          SecuriteInfo.com.FileRepMalware.7114.13860.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                            SecuriteInfo.com.FileRepMalware.7114.13860.exeGet hashmaliciousPython StealerBrowse
                                                                                                                                                                                                                              SecuriteInfo.com.W64.ABRisk.PVEG-3846.30817.29399.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                SecuriteInfo.com.Trojan.GenericKD.70641791.20493.31768.exeGet hashmaliciousPython Stealer, CStealerBrowse
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):292
                                                                                                                                                                                                                                  Entropy (8bit):5.202516355822968
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:Dtw/+q2Pwkn2nKuAl9OmbnIFUt86tw6pmWZmw+6tw6pNVkwOwkn2nKuAl9OmbjLJ:Dtw/+vYfHAahFUt86tw6UW/+6tw6jV50
                                                                                                                                                                                                                                  MD5:6328A54C84C37944ACF29A615843B381
                                                                                                                                                                                                                                  SHA1:FED7DB5215200100722B281CA67ABA2B2B66A89A
                                                                                                                                                                                                                                  SHA-256:D99E6436F96830D4B955FE1BDC852BDA78C6FD3A2E0ACD4F3748A2B3B531D5EC
                                                                                                                                                                                                                                  SHA-512:F9E47B08D6567120FB9B5D56FDF3D3B07A4671A0199411B84A3D2BC94433FA8F0273DBA7D031D6EB89EA641DF83B2191BC5F44068ACFF3B9B659E438C58B2281
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Preview:2024/05/10-10:38:15.782 1dcc Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/05/10-10:38:15.783 1dcc Recovering log #3.2024/05/10-10:38:15.783 1dcc Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):292
                                                                                                                                                                                                                                  Entropy (8bit):5.202516355822968
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:Dtw/+q2Pwkn2nKuAl9OmbnIFUt86tw6pmWZmw+6tw6pNVkwOwkn2nKuAl9OmbjLJ:Dtw/+vYfHAahFUt86tw6UW/+6tw6jV50
                                                                                                                                                                                                                                  MD5:6328A54C84C37944ACF29A615843B381
                                                                                                                                                                                                                                  SHA1:FED7DB5215200100722B281CA67ABA2B2B66A89A
                                                                                                                                                                                                                                  SHA-256:D99E6436F96830D4B955FE1BDC852BDA78C6FD3A2E0ACD4F3748A2B3B531D5EC
                                                                                                                                                                                                                                  SHA-512:F9E47B08D6567120FB9B5D56FDF3D3B07A4671A0199411B84A3D2BC94433FA8F0273DBA7D031D6EB89EA641DF83B2191BC5F44068ACFF3B9B659E438C58B2281
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Preview:2024/05/10-10:38:15.782 1dcc Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/MANIFEST-000001.2024/05/10-10:38:15.783 1dcc Recovering log #3.2024/05/10-10:38:15.783 1dcc Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache/000003.log .
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):336
                                                                                                                                                                                                                                  Entropy (8bit):5.148756431536105
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:DtwdMVyq2Pwkn2nKuAl9Ombzo2jMGIFUt86twdA1Zmw+6twdWRkwOwkn2nKuAl97:DtwdQyvYfHAa8uFUt86twdu/+6twdWRs
                                                                                                                                                                                                                                  MD5:5325028D5053B2643D1949A7008C8C99
                                                                                                                                                                                                                                  SHA1:99D6BA96EA546CE3F5D298FB2AEC788C156FE2EE
                                                                                                                                                                                                                                  SHA-256:EAC0FA886BD472359F8F989419C53A377763BC280BD32D6153A3A221DDB6BC85
                                                                                                                                                                                                                                  SHA-512:B5D21C394D4D1B1B85A6D28913FCA2C28D7381967C9C4916EE7CA083C9CA41FA10E7EE118098988B093CD19959007620BDE4E9634A1ACB9351DBA728085C58BC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Preview:2024/05/10-10:38:15.880 1ec4 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/05/10-10:38:15.882 1ec4 Recovering log #3.2024/05/10-10:38:15.882 1ec4 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):336
                                                                                                                                                                                                                                  Entropy (8bit):5.148756431536105
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:DtwdMVyq2Pwkn2nKuAl9Ombzo2jMGIFUt86twdA1Zmw+6twdWRkwOwkn2nKuAl97:DtwdQyvYfHAa8uFUt86twdu/+6twdWRs
                                                                                                                                                                                                                                  MD5:5325028D5053B2643D1949A7008C8C99
                                                                                                                                                                                                                                  SHA1:99D6BA96EA546CE3F5D298FB2AEC788C156FE2EE
                                                                                                                                                                                                                                  SHA-256:EAC0FA886BD472359F8F989419C53A377763BC280BD32D6153A3A221DDB6BC85
                                                                                                                                                                                                                                  SHA-512:B5D21C394D4D1B1B85A6D28913FCA2C28D7381967C9C4916EE7CA083C9CA41FA10E7EE118098988B093CD19959007620BDE4E9634A1ACB9351DBA728085C58BC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Preview:2024/05/10-10:38:15.880 1ec4 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/MANIFEST-000001.2024/05/10-10:38:15.882 1ec4 Recovering log #3.2024/05/10-10:38:15.882 1ec4 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb/000003.log .
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):475
                                                                                                                                                                                                                                  Entropy (8bit):4.955329463162928
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:YH/um3RA8sqZcKnfsBdOg2HZOgcaq3QYiubInP7E4T3y:Y2sRdsUngdMHkL3QYhbG7nby
                                                                                                                                                                                                                                  MD5:6359A207532EF5FBAB942FEABA33C0A0
                                                                                                                                                                                                                                  SHA1:3335886798E8E3A30406A612BA85648D26FB15E7
                                                                                                                                                                                                                                  SHA-256:D16F0F305803F63559D5B3D7899074BDE55A01272A86E7C232542D30557B3B1B
                                                                                                                                                                                                                                  SHA-512:7C51089C7F3C70B8725140649ECEE9F1214C6CB5CF77B49F9C25C1923538B4C9BD95DD215F49025862CF21DCD0015BD6ED85AB8D2A17D0E4AD81C378FD35A4C6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13359890308811312","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":419421},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.4","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:modified
                                                                                                                                                                                                                                  Size (bytes):475
                                                                                                                                                                                                                                  Entropy (8bit):4.955329463162928
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:YH/um3RA8sqZcKnfsBdOg2HZOgcaq3QYiubInP7E4T3y:Y2sRdsUngdMHkL3QYhbG7nby
                                                                                                                                                                                                                                  MD5:6359A207532EF5FBAB942FEABA33C0A0
                                                                                                                                                                                                                                  SHA1:3335886798E8E3A30406A612BA85648D26FB15E7
                                                                                                                                                                                                                                  SHA-256:D16F0F305803F63559D5B3D7899074BDE55A01272A86E7C232542D30557B3B1B
                                                                                                                                                                                                                                  SHA-512:7C51089C7F3C70B8725140649ECEE9F1214C6CB5CF77B49F9C25C1923538B4C9BD95DD215F49025862CF21DCD0015BD6ED85AB8D2A17D0E4AD81C378FD35A4C6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Preview:{"net":{"http_server_properties":{"servers":[{"isolation":[],"server":"https://armmf.adobe.com","supports_spdy":true},{"alternative_service":[{"advertised_alpns":["h3"],"expiration":"13359890308811312","port":443,"protocol_str":"quic"}],"isolation":[],"network_stats":{"srtt":419421},"server":"https://chrome.cloudflare-dns.com","supports_spdy":true}],"supports_quic":{"address":"192.168.2.4","used_quic":true},"version":5},"network_qualities":{"CAESABiAgICA+P////8B":"4G"}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4320
                                                                                                                                                                                                                                  Entropy (8bit):5.257570843352786
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7dxxf:etJCV4FiN/jTN/2r8Mta02fEhgO73gox
                                                                                                                                                                                                                                  MD5:34658E3935C1328F769008CAD9DC965B
                                                                                                                                                                                                                                  SHA1:A1C8F927177824139A287977AF08411B527F594C
                                                                                                                                                                                                                                  SHA-256:F6742991563F6F5E22EDEBA4941390F12D758DB58F77834C311B5C2227AAD50C
                                                                                                                                                                                                                                  SHA-512:D700A32FDDACA9B32DDCBDCCB8725D134E5246A2174FB50247A2F9D20B6783AC40A56FAEEE509059297128667DFF77538A717871DE574A1C287DD3A8ECB36C78
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Preview:*...#................version.1..namespace-['O.o................next-map-id.1.Pnamespace-158f4913_074a_4bdf_b463_eb784cc805b4-https://rna-resource.acrobat.com/.0>...r................next-map-id.2.Snamespace-fd2db5bd_ef7e_4124_bfa7_f036ce1d74e5-https://rna-v2-resource.acrobat.com/.1O..r................next-map-id.3.Snamespace-cd5be8d1_42d2_481d_ac0e_f904ae470bda-https://rna-v2-resource.acrobat.com/.2.\.o................next-map-id.4.Pnamespace-6070ce43_6a74_4d0a_9cb8_0db6c3126811-https://rna-resource.acrobat.com/.3....^...............Pnamespace-158f4913_074a_4bdf_b463_eb784cc805b4-https://rna-resource.acrobat.com/..|.^...............Pnamespace-6070ce43_6a74_4d0a_9cb8_0db6c3126811-https://rna-resource.acrobat.com/n..Fa...............Snamespace-fd2db5bd_ef7e_4124_bfa7_f036ce1d74e5-https://rna-v2-resource.acrobat.com/DQ..a...............Snamespace-cd5be8d1_42d2_481d_ac0e_f904ae470bda-https://rna-v2-resource.acrobat.com/i.`do................next-map-id.5.Pnamespace-de635bf2_6773_4d83_ad16_
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):324
                                                                                                                                                                                                                                  Entropy (8bit):5.185274139924775
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:DtwKupyq2Pwkn2nKuAl9OmbzNMxIFUt86twKjKz1Zmw+6twKPlRkwOwkn2nKuAlG:DtwK2yvYfHAa8jFUt86twKWZ/+6twKPP
                                                                                                                                                                                                                                  MD5:16FDA8E1D095700FDEA284A5E89F4B58
                                                                                                                                                                                                                                  SHA1:CC16F4331FD6FDEED3E82D530D0A34906ABEAC10
                                                                                                                                                                                                                                  SHA-256:91224F2820AFF7AF93A28B72A5E5E4E39F146FE5A2D83BD096BD9C37A6804A3B
                                                                                                                                                                                                                                  SHA-512:524271994674E508C4BD6F07050D904EAFA80D1DC458C4EAC5A4F9682492B9C576EEBAAF91D8A8FBF0725375F6A4F7FAC8101CB9BF21CE271149E8452A3451AB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:2024/05/10-10:38:16.158 1ec4 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/05/10-10:38:16.244 1ec4 Recovering log #3.2024/05/10-10:38:16.274 1ec4 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):324
                                                                                                                                                                                                                                  Entropy (8bit):5.185274139924775
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:DtwKupyq2Pwkn2nKuAl9OmbzNMxIFUt86twKjKz1Zmw+6twKPlRkwOwkn2nKuAlG:DtwK2yvYfHAa8jFUt86twKWZ/+6twKPP
                                                                                                                                                                                                                                  MD5:16FDA8E1D095700FDEA284A5E89F4B58
                                                                                                                                                                                                                                  SHA1:CC16F4331FD6FDEED3E82D530D0A34906ABEAC10
                                                                                                                                                                                                                                  SHA-256:91224F2820AFF7AF93A28B72A5E5E4E39F146FE5A2D83BD096BD9C37A6804A3B
                                                                                                                                                                                                                                  SHA-512:524271994674E508C4BD6F07050D904EAFA80D1DC458C4EAC5A4F9682492B9C576EEBAAF91D8A8FBF0725375F6A4F7FAC8101CB9BF21CE271149E8452A3451AB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:2024/05/10-10:38:16.158 1ec4 Reusing MANIFEST C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/MANIFEST-000001.2024/05/10-10:38:16.244 1ec4 Recovering log #3.2024/05/10-10:38:16.274 1ec4 Reusing old log C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage/000003.log .
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:PC bitmap, Windows 3.x format, 107 x -152 x 32, cbSize 65110, bits offset 54
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):65110
                                                                                                                                                                                                                                  Entropy (8bit):1.2991030501698626
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:+ZkVH7k1ET2xeZi16VqGU0qa+7xXCFq7G8126+72UImTiYxn6Gl+rJl2uPb59hFm:+o7xNqLa+1X7G7pn6C+rC2b5I
                                                                                                                                                                                                                                  MD5:03626C238502731800E840D638586372
                                                                                                                                                                                                                                  SHA1:E263110394AF7BA8A72AD9B861DECD61465550D1
                                                                                                                                                                                                                                  SHA-256:C9D355622ABB91942AB437A3EFDEE80263E5489B8F92790D9B1C15E37B2D7EE1
                                                                                                                                                                                                                                  SHA-512:44B8ED3AD9E4B2312654C0E2CCAFFDF7D6A117F1515E65DD4E637DB63F11F401CA79F6C1032DDD39A830D009CF9F5B2BB651EE9AF45A4C609C362AF67BD7AC60
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:BMV.......6...(...k...h..... ...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 15, database pages 21, cookie 0x5, schema 4, UTF-8, version-valid-for 15
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):86016
                                                                                                                                                                                                                                  Entropy (8bit):4.444948326379383
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:yezci5tuiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rBs3OazzU89UTTgUL
                                                                                                                                                                                                                                  MD5:2D426D63A929178F12410442970388A2
                                                                                                                                                                                                                                  SHA1:807D71B01C14E9EDE888D8110287AA597CC91640
                                                                                                                                                                                                                                  SHA-256:7C9A6E817A2ADB5D7330D2991432F8D192F70FBF934237366D74E83E5D62C923
                                                                                                                                                                                                                                  SHA-512:10567B83DE1568305116B6238E2A374C650B8332CBCA0AEAA973E5FFD1B527707BA7CA993C04D7263DB307F0988D7A3B3CA0DC32A7D43511743446B1A408E8FC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................c.......1........T...U.1.D............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:SQLite Rollback Journal
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8720
                                                                                                                                                                                                                                  Entropy (8bit):3.776054331304576
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:7MOp/E2ioyVZioy9oWoy1Cwoy1JKOioy1noy1AYoy1Wioy1hioybioyhoy1noy1S:7FpjuZFEXKQowb9IVXEBodRBk/
                                                                                                                                                                                                                                  MD5:1B31DB4B775C2D7A2CEE3C6EC2562786
                                                                                                                                                                                                                                  SHA1:E5F5160619421C85EBB9AB95DD932952F48AF13C
                                                                                                                                                                                                                                  SHA-256:77F06E90F6190DBDCCFE2E31BAE24659A0572B3C97B553E20EC91646147AE111
                                                                                                                                                                                                                                  SHA-512:9C7E0B6380227272156ACF437A3B1D67E050F111E01F85CA58528804B775F4BF0E1F02B77CEBD5521AB092FD55D73F8F4D907F7AD962D5FFEA49CF03FA107CD0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:.... .c.......t...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................T...[...b...r...t...}.....L..............................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):295
                                                                                                                                                                                                                                  Entropy (8bit):5.338775917827841
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJM3g98kUwPeUkwRe9:YvXKXe9LKEZc0vIGMbLUkee9
                                                                                                                                                                                                                                  MD5:8EDD8EE6A3FEC12EC697498D775C80F6
                                                                                                                                                                                                                                  SHA1:1172799442C957233D3BAD523BC274CCF9A06232
                                                                                                                                                                                                                                  SHA-256:EFCC11B4354A6216E6FE7139A7912FC31D8351ED42D4C95F533CB7F31D6A83D8
                                                                                                                                                                                                                                  SHA-512:322546813776D74FC4F56516BBB1F5FF6CC0493C46A22A5B4284BDCDABCCE9AA659FCE7899DE0F97524884229BE116F1B60E5D60F1F5D0A4C4FF5210535D0780
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"ACROBAT_READER_MASTER_SURFACEID","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):294
                                                                                                                                                                                                                                  Entropy (8bit):5.285422871404613
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfBoTfXpnrPeUkwRe9:YvXKXe9LKEZc0vIGWTfXcUkee9
                                                                                                                                                                                                                                  MD5:1887661AB201C745958CC0D61B2777B9
                                                                                                                                                                                                                                  SHA1:F5905DACB4908005407EC1B25DB2975ECA4AF62E
                                                                                                                                                                                                                                  SHA-256:07B83753508763094FC7371E977F60252824B35488F827F91364D61B92E495BD
                                                                                                                                                                                                                                  SHA-512:360F925F2378B699329BEA572D1021B72FB3DF13AD95DC240800C0B91F06986A30B5D36254F0154F7F46A2F6DE5D2646A7FC542FDFD4CF2AD5824CB0D400EF3F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_FirstMile_Home_View_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):294
                                                                                                                                                                                                                                  Entropy (8bit):5.263834544669474
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfBD2G6UpnrPeUkwRe9:YvXKXe9LKEZc0vIGR22cUkee9
                                                                                                                                                                                                                                  MD5:01AE527FD6A173825357D2F28CBD0E42
                                                                                                                                                                                                                                  SHA1:1821C5C1C9E654CDFC7F1D4B1293BD217E88327F
                                                                                                                                                                                                                                  SHA-256:E76437CBE96D8CCBA328FC76909A00EE0CFD28533D6D79BF61E25C3BCE8F3453
                                                                                                                                                                                                                                  SHA-512:9C94DCADC0B0C007D9C7EC932294238E13A15E4E83AB3B3F286A9DE65BBD5CD11290B987F502E81773740BAD05D61275BCFBFD6565FA930DFB279A78C65E6D27
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_FirstMile_Right_Sec_Surface","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):285
                                                                                                                                                                                                                                  Entropy (8bit):5.3249237058303915
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfPmwrPeUkwRe9:YvXKXe9LKEZc0vIGH56Ukee9
                                                                                                                                                                                                                                  MD5:A29C946254920FCD3C6EC38E8AF8A8B7
                                                                                                                                                                                                                                  SHA1:FC935C1E051B7EB951B223E8018614E09827B16F
                                                                                                                                                                                                                                  SHA-256:F194B0301C632416220B20E0AFA6DB3469C1A7C85D9152C37EBC880E48830A24
                                                                                                                                                                                                                                  SHA-512:570035023776D5A5116C7F23AF5094D07BCC822A612D26D31D66031EE1EA8D116216F3D9B2AEBD17772A9619DB8D8F5E67BFD1F31DA89019FC7FFA6BE44ED190
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_READER_LAUNCH_CARD","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):292
                                                                                                                                                                                                                                  Entropy (8bit):5.282598776742798
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfJWCtMdPeUkwRe9:YvXKXe9LKEZc0vIGBS8Ukee9
                                                                                                                                                                                                                                  MD5:DAE473181FF2728F8D95FCA194151ADB
                                                                                                                                                                                                                                  SHA1:8ECAAAAA9299192FD1DB38E644884F1A58ECC19B
                                                                                                                                                                                                                                  SHA-256:97C7FC845D167A9A8CE2964BA8AD8BBA2A31A3D69D5FFBCC7B0902B5927052F4
                                                                                                                                                                                                                                  SHA-512:1C71F03FC142E9B1E6EAFB768CFE59E74DECCF122658D0F6D04DBF9484B31894152FC8C338240DF67A38F21F067D860B8E2234B1316569C53252DD6E87C662D8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_Convert_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):289
                                                                                                                                                                                                                                  Entropy (8bit):5.269023789227987
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJf8dPeUkwRe9:YvXKXe9LKEZc0vIGU8Ukee9
                                                                                                                                                                                                                                  MD5:278D0D5E6090F5753E380051553056C8
                                                                                                                                                                                                                                  SHA1:1E6DDF483328CB1F5B5B52BF3FD6C62A9C29E7B8
                                                                                                                                                                                                                                  SHA-256:3A4765E1A293B8C775D3AE1725EDCA1C77EDC92BA710C1E8CB98B9B9CAAF0C36
                                                                                                                                                                                                                                  SHA-512:CF2EA8749DB40163ED98C8F856DA00559D0FD032335C7BD6EE5008E7F84E541BBBBD8F76EB014D22DCDA4BB0FA3FD08CFD1E05C413AFAF66092C3D8B7D24F76B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):292
                                                                                                                                                                                                                                  Entropy (8bit):5.273258846259875
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfQ1rPeUkwRe9:YvXKXe9LKEZc0vIGY16Ukee9
                                                                                                                                                                                                                                  MD5:7897C493885B46D79F393F6D1DCEC123
                                                                                                                                                                                                                                  SHA1:2A99F174A371A2E18A78852114B8F4A562734114
                                                                                                                                                                                                                                  SHA-256:C871F960227273E4B59EF1252EC480E2546270E64F3D882C4482FCB9DF210686
                                                                                                                                                                                                                                  SHA-512:9748816414C31D88CA084153A82A633BBF2BE92EAA95C5441707794D4BA5D2E597D3C79CA22F44826F6B7CAA06286BD328B32DE5BBD1F217AFDF0EFCAB3314CB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_Disc_LHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):289
                                                                                                                                                                                                                                  Entropy (8bit):5.278781320854625
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfFldPeUkwRe9:YvXKXe9LKEZc0vIGz8Ukee9
                                                                                                                                                                                                                                  MD5:EEFF1C20698E7E1EE5C7966561DC439C
                                                                                                                                                                                                                                  SHA1:95EF716FAF2975DA65A095A0AF965F04676E7132
                                                                                                                                                                                                                                  SHA-256:9EDEB0D235DD0870A5E921F93E631FACC7327B769937F3569221C7DE6EE8C251
                                                                                                                                                                                                                                  SHA-512:DF0121320644924190F686B88D248F4039F750EC3CBD12BAB82D7A0CD081976E71DA3253D4AD482EE06FC82755EE9307B3E5762DF103C9B34EA26F20B6847B83
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_Edit_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1372
                                                                                                                                                                                                                                  Entropy (8bit):5.734453218033675
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:Yv6XgBzvwKLgENRcbrZbq00iCCBrwJo++ns8ct4mFJN4:Yvn4EgigrNt0wSJn+ns8cvFJS
                                                                                                                                                                                                                                  MD5:87CDE70193BA88D2D312416475A7C76C
                                                                                                                                                                                                                                  SHA1:9F8AD2AA3F79FDC09371664E4597ECEEA7337973
                                                                                                                                                                                                                                  SHA-256:202112F9927B665B171D70E44019B39BC5961537A8F6C8A50C2C850A7DC35696
                                                                                                                                                                                                                                  SHA-512:27CA8BAABFFA9C6375E78136D2BC1728F533487AA22A67C8488B9B5A1A8D139DBA91BD823425386942FAB4BE7CA2520DC19FD411DDC8E248C2B4E96B8326F997
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_Home_LHP_Trial_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_Home_LHP_Trial_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"79887_247329ActionBlock_0","campaignId":79887,"containerId":"1","controlGroupId":"","treatmentId":"acc56846-d570-4500-a26e-7f8cf2b4acad","variationId":"247329"},"containerId":1,"containerLabel":"JSON for DC_Reader_Home_LHP_Trial_Banner","content":{"data":"eyJjdGEiOnsidHlwZSI6ImJ1dHRvbiIsInRleHQiOiJUcnkgQWNyb2JhdCBQcm8ifSwidWkiOnsidGl0bGVfc3R5bGluZyI6eyJmb250X3NpemUiOiIxNSIsImZvbnRfc3R5bGUiOiIwIn0sImRlc2NyaXB0aW9uX3N0eWxpbmciOnsiZm9udF9zaXplIjoiMTMiLCJmb250X3N0eWxlIjoiLTEifSwidGl0bGUiOiJGcmVlIDctZGF5IHRyaWFsIiwiZGVzY3JpcHRpb24iOiJHZXQgdW5saW1pdGVkIGFjY2VzcyB0byBwcmVtaXVtIFBERiBhbmQgZS1zaWduaW5nIHRvb2xzLiIsImJ
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):289
                                                                                                                                                                                                                                  Entropy (8bit):5.27549144014596
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfYdPeUkwRe9:YvXKXe9LKEZc0vIGg8Ukee9
                                                                                                                                                                                                                                  MD5:FFBF9EEB6A96906D2C7CD578557B5BD2
                                                                                                                                                                                                                                  SHA1:BCF3022BC569EB068F23E81F1DC97006A571CB2C
                                                                                                                                                                                                                                  SHA-256:0B502408744DB042A6FC0057A2D79EAA533F2021144DA4AA5C8A719AFFB2066F
                                                                                                                                                                                                                                  SHA-512:13F56AFF05D6EE4723DC5ADF55AEA3E9C27A033E40C01B272046C916E3FC7ABC2F0C4172CA469D73F1C03AF9D535DF987EDAFEBA84709395FF7B3F6E1DFBAE9F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_More_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1395
                                                                                                                                                                                                                                  Entropy (8bit):5.774216534598089
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:Yv6XgBzv/rLgEGOc93W2JeFmaR7CQzttgBcu141CjrWpHfRzVCV9FJNA:YvnXHgDv3W2aYQfgB5OUupHrQ9FJe
                                                                                                                                                                                                                                  MD5:B8875DE630770DC6D5A830A0EC7902DC
                                                                                                                                                                                                                                  SHA1:26320F80C694F87A52648A40B39F53021A0CB37D
                                                                                                                                                                                                                                  SHA-256:867AA45CDAA97297DE84370527CF32DE5B801B18A973372FD2CEFB64B40650C7
                                                                                                                                                                                                                                  SHA-512:0BA5CD6D1E62B65C1198F081CAB624AB1E4C1AE1BFD9DDD23B4D518CA22F55C589545B2B390E594AD60D5DB049DB7DBE0E190C7543766829C6F2C07D7B5B37B5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_RHP_Banner","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"DC_Reader_RHP_Banner"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"57802_176003ActionBlock_0","campaignId":57802,"containerId":"1","controlGroupId":"","treatmentId":"d0374f2d-08b2-49b9-9500-3392758c9e2e","variationId":"176003"},"containerId":1,"containerLabel":"JSON for Reader DC RHP Banner","content":{"data":"eyJjdGEiOnsidHlwZSI6ImJ1dHRvbiIsInRleHQiOiJGcmVlIDctRGF5IFRyaWFsIiwiZ29fdXJsIjoiaHR0cHM6Ly9hY3JvYmF0LmFkb2JlLmNvbS9wcm94eS9wcmljaW5nL3VzL2VuL3NpZ24tZnJlZS10cmlhbC5odG1sP3RyYWNraW5naWQ9UEMxUFFMUVQmbXY9aW4tcHJvZHVjdCZtdjI9cmVhZGVyIn0sInVpIjp7InRpdGxlX3N0eWxpbmciOnsiZm9udF9zaXplIjoiMTQiLCJmb250X3N0eWxlIjoiMyJ9LCJkZXNjcmlwdGlvbl9zdHlsaW5nIjp7ImZvbnRfc2l6ZSI6IjEyIiwiZm9udF9zdHlsZSI6IjMifSwidGl0
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):291
                                                                                                                                                                                                                                  Entropy (8bit):5.259206981530162
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfbPtdPeUkwRe9:YvXKXe9LKEZc0vIGDV8Ukee9
                                                                                                                                                                                                                                  MD5:68CBEEB933F3D7EA838568CD86AEE161
                                                                                                                                                                                                                                  SHA1:FFB8F2EA3835B2BE10E2D74081DC6FFC3227A59E
                                                                                                                                                                                                                                  SHA-256:A67A1C45CD7CD21EB8F698594C7BF8B3E4FA765A24276FCB93AF9258D724FBAD
                                                                                                                                                                                                                                  SHA-512:7B8B644AE6021015665B8794AC935F2F5E5C86937BC23D83D31FA01941E4168C6E950384DA571F7C36357616F5A9FC966D5385E22A17E999FB4807310EA9F73F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_RHP_Intent_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):287
                                                                                                                                                                                                                                  Entropy (8bit):5.263815064685115
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJf21rPeUkwRe9:YvXKXe9LKEZc0vIG+16Ukee9
                                                                                                                                                                                                                                  MD5:85463368B6644A76CA161C8DF0E2F545
                                                                                                                                                                                                                                  SHA1:26A7FAFA89C2699AD23BC4AA23A67C8B007648DF
                                                                                                                                                                                                                                  SHA-256:DD5D028BFDC5853A5253DA437DADB2EECF4D080C5933FD50FBAAB27D65135498
                                                                                                                                                                                                                                  SHA-512:04ABBFC8BA5857B3768477A020F5C23993952E083ACBCE3548FCCDA4EBDB5FAD14B915F3613F89035374BD7C7875664A12DC2B509DF7C42334F523FAD971E20E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_RHP_Retention","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):289
                                                                                                                                                                                                                                  Entropy (8bit):5.282604046429232
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfbpatdPeUkwRe9:YvXKXe9LKEZc0vIGVat8Ukee9
                                                                                                                                                                                                                                  MD5:A23C9A0D6C5CEF0B00C68BD86ED9CD22
                                                                                                                                                                                                                                  SHA1:23152FE064EC2017A0C6BE8CC505FB1ABD874DEA
                                                                                                                                                                                                                                  SHA-256:6B3948AF35E0AC8B123208A949F75D6DBD1DF37F3633C4D5516F678F541E8090
                                                                                                                                                                                                                                  SHA-512:4FB90A0989AE19BE49A042F84A6299FB9A8043BBEAE7E56BBAADD8FC33AE55AD4149570FF1536AA5EAB37E3EEAB298E29AB405937CB70664F50A75B226E7C6CE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_Sign_LHP_Banner","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):286
                                                                                                                                                                                                                                  Entropy (8bit):5.239354641769436
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:YEQXJ2HXHUnrBdxLc39VoZcg1vRcR0YHUoAvJfshHHrPeUkwRe9:YvXKXe9LKEZc0vIGUUUkee9
                                                                                                                                                                                                                                  MD5:7188D1C843FB9ADCF7E923D064437CBE
                                                                                                                                                                                                                                  SHA1:BE297B7C7F431442E0A9734435C98C3393B2BF26
                                                                                                                                                                                                                                  SHA-256:BA068882CDA045828775406624EC8064A8E637D42DA6B8CCE0E1BF6F70D0B456
                                                                                                                                                                                                                                  SHA-512:A8982DD087F2686AE9DCF192E1B0ECB5131998513519D67061F6F1E161A7968542EB0221987FE1415882147EEB256591D215AADB85E22D9802CC6AD16A780D6F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"DC_Reader_Upsell_Cards","surfaceObj":{"SurfaceAnalytics":{},"containerMap":{}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):782
                                                                                                                                                                                                                                  Entropy (8bit):5.36700037356608
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:YvXKXe9LKEZc0vIGTq16Ukee1+3CEJ1KXd15kcyKMQo7P70c0WM6ZB/uhWk:Yv6XgBzvu168CgEXX5kcIfANhx
                                                                                                                                                                                                                                  MD5:8234131BABF58C829F9B20E8E8F0B00F
                                                                                                                                                                                                                                  SHA1:5E86BAE5AA09BD3177E36FEE04D76C7CA0381BCD
                                                                                                                                                                                                                                  SHA-256:55D0FE1F953AF77C8C6A2E6E060E59C8BC3470E507AE3B7FB7CC014DE493D1FB
                                                                                                                                                                                                                                  SHA-512:CA294F524613A8A912CDFAE8A632396E4E0554E1F1E4F38D5D5EEFADA9A07E75A24C5F228281FC07000E4D6F8026B64583052B1FF419DD228F8198B5BCBC41F6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"analyticsData":{"responseGUID":"01ce2b4a-d10e-47e4-a1f8-acb8b5c8bf4d","sophiaUUID":"BB455677-E4C2-45EB-A908-4974DBA96F4C"},"encodingScheme":true,"expirationDTS":1715508697491,"statusCode":200,"surfaceID":"Edit_InApp_Aug2020","surfaceObj":{"SurfaceAnalytics":{"surfaceId":"Edit_InApp_Aug2020"},"containerMap":{"1":{"containerAnalyticsData":{"actionBlockId":"20360_57769ActionBlock_0","campaignId":20360,"containerId":"1","controlGroupId":"","treatmentId":"3c07988a-9c54-409d-9d06-53885c9f21ec","variationId":"57769"},"containerId":1,"containerLabel":"JSON for switching in-app test","content":{"data":"eyJ1cHNlbGxleHBlcmltZW50Ijp7InRlc3RpZCI6IjEiLCJjb2hvcnQiOiJicm93c2VyIn19","dataType":"application\/json","encodingScheme":true},"endDTS":1735804679000,"startDTS":1715330302521}}}}
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4
                                                                                                                                                                                                                                  Entropy (8bit):0.8112781244591328
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:e:e
                                                                                                                                                                                                                                  MD5:DC84B0D741E5BEAE8070013ADDCC8C28
                                                                                                                                                                                                                                  SHA1:802F4A6A20CBF157AAF6C4E07E4301578D5936A2
                                                                                                                                                                                                                                  SHA-256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
                                                                                                                                                                                                                                  SHA-512:65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:....
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:JSON data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2814
                                                                                                                                                                                                                                  Entropy (8bit):5.140242076362016
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:YJdjscKCh4AwCibNnlmyps6PjcOszaNV3ayscY2PYYDCrseStgYjwj0StZ3z2DB4:YJTQhbews6V/tdDCQXCLcXjP00Mjn69I
                                                                                                                                                                                                                                  MD5:EB7B485F5F463B15CB841AED4880CE37
                                                                                                                                                                                                                                  SHA1:6AC7F24661927A18960B43A2069A424B5BBEB4C8
                                                                                                                                                                                                                                  SHA-256:9F5A231F79541838CADE06A36986F8E88DE83F21F08FF7A3141123BD6B319B04
                                                                                                                                                                                                                                  SHA-512:34F8C085259D0FD073459DF0032D2C1F59ED2EEBD730EA4CDC3E322B5975267807EE4D6D04C58C82810AF9AE40C87E4287096C7E26DE049CB4DADB73CF2C4251
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:{"all":[{"id":"DC_Reader_Disc_LHP_Banner","info":{"dg":"ffc110c051654265b6eb1415b8966310","sid":"DC_Reader_Disc_LHP_Banner"},"mimeType":"file","size":289,"ts":1715330302000},{"id":"DC_Reader_Home_LHP_Trial_Banner","info":{"dg":"d115aedcb066744b3af62448eec3854c","sid":"DC_Reader_Home_LHP_Trial_Banner"},"mimeType":"file","size":1372,"ts":1715330302000},{"id":"Edit_InApp_Aug2020","info":{"dg":"5b588e54afe289b7c9f243b63e82972f","sid":"Edit_InApp_Aug2020"},"mimeType":"file","size":782,"ts":1715330302000},{"id":"DC_Reader_RHP_Banner","info":{"dg":"79342e76bc66ff985742eb04963271d1","sid":"DC_Reader_RHP_Banner"},"mimeType":"file","size":1395,"ts":1715330302000},{"id":"DC_Reader_Disc_LHP_Retention","info":{"dg":"614c9872a285e293cf16216b1a9c25f5","sid":"DC_Reader_Disc_LHP_Retention"},"mimeType":"file","size":292,"ts":1715330302000},{"id":"DC_Reader_More_LHP_Banner","info":{"dg":"6599c6f4145cda1bc9ece4bbc373bd69","sid":"DC_Reader_More_LHP_Banner"},"mimeType":"file","size":289,"ts":1715330302000},
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3040000, file counter 25, database pages 3, cookie 0x2, schema 4, UTF-8, version-valid-for 25
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):12288
                                                                                                                                                                                                                                  Entropy (8bit):1.1883037792180078
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:TGufl2GL7msEHUUUUUUUUpyCKrSvR9H9vxFGiDIAEkGVvplyCKD:lNVmswUUUUUUUUpyL+FGSItpyj
                                                                                                                                                                                                                                  MD5:42D7B11F1270B02EEBE31DCAFEF33973
                                                                                                                                                                                                                                  SHA1:51ADA7D509A50265AEBE5B27CE1336B7000CA478
                                                                                                                                                                                                                                  SHA-256:27DAD1C5676D73ABD4BDB1150445E60DDE11F6F69363E4AE68499D18D9202357
                                                                                                                                                                                                                                  SHA-512:EFAF71F2621932EF318401075D7F3E89E312CCE8E19606981523C45422D10B61091A06D4B803B636FD4B29D719769D68A339AB3EC60D674ACEF37202D428070F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:SQLite format 3......@ ..........................................................................c.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:SQLite Rollback Journal
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8720
                                                                                                                                                                                                                                  Entropy (8bit):1.6075701291265594
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:7M7KUUUUUUUUUUpyCK/vR9H9vxFGiDIAEkGVvLqFl2GL7msh:7ZUUUUUUUUUUpyXFGSIthKVmsh
                                                                                                                                                                                                                                  MD5:A7D14949CAA3C9608E40634E1C09E0C4
                                                                                                                                                                                                                                  SHA1:C914781A8966F1D5D8388AD6AAAAA26613534A7D
                                                                                                                                                                                                                                  SHA-256:944EBEAE867534F0B95C1DC3482B39A6A11C09F6C659C584C453370310F0FEC0
                                                                                                                                                                                                                                  SHA-512:4B8D8AD4A2AC858D06CDE0D27FC2AE1EE02D7449DFDA64445F3E9271DDEBE3645AD12D6B0887205FD481284F0AEC99FCDD5DE4D014076F91DB618E5200C09B98
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:.... .c.....;.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................f.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):246
                                                                                                                                                                                                                                  Entropy (8bit):3.524398495091119
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EeydNaNWlPwlYH:Qw946cPbiOxDlbYnuRK+ri4lYH
                                                                                                                                                                                                                                  MD5:A0BD9F561787BD4D929617AE4BEC2304
                                                                                                                                                                                                                                  SHA1:5F9A7F9EF9DE4377B96310D721F9F64831AF6EA0
                                                                                                                                                                                                                                  SHA-256:32CBC3340B4432EC2B030E109BC75F4F3531881EDD915AE367E57EE847A13E9C
                                                                                                                                                                                                                                  SHA-512:5CECC07D2D78F243B1583697B01E0F05AAAA67412D962A67CFF8794C4F05037A9E61895319CD26937603600D7A7A167325FECC046E3D9B88536C00D95BC8E23D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:..E.r.r.o.r. .2.7.1.1...T.h.e. .s.p.e.c.i.f.i.e.d. .F.e.a.t.u.r.e. .n.a.m.e. .(.'.A.R.M.'.). .n.o.t. .f.o.u.n.d. .i.n. .F.e.a.t.u.r.e. .t.a.b.l.e.......=.=.=. .L.o.g.g.i.n.g. .s.t.o.p.p.e.d.:. .1.0./.0.5./.2.0.2.4. . .1.0.:.3.8.:.3.0. .=.=.=.....
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):11264
                                                                                                                                                                                                                                  Entropy (8bit):4.6989965032233245
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:v9VD9daQ2iTrqT+y/ThvQ0I1uLfcC75JiC4Rs89EcYyGDPM0OcX6gY/7ECFV:39damqT3ThITst0E5DPKcqgY/79X
                                                                                                                                                                                                                                  MD5:56976443600793FF2302EE7634E496B3
                                                                                                                                                                                                                                  SHA1:018CE9250732A1794BBD0BDB8164061022B067AA
                                                                                                                                                                                                                                  SHA-256:10F461A94C3D616C19FF1A88DEC1EFEA5194F7150F5D490B38AC4E1B31F673DD
                                                                                                                                                                                                                                  SHA-512:A764C636D5D0B878B91DC61485E8699D7AA36F09AA1F0BD6AF33A8652098F28AEB3D7055008E56EBFC012BD3EA0868242A72E44DED0C83926F13D16866C31415
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 3%, Browse
                                                                                                                                                                                                                                  Joe Sandbox View:
                                                                                                                                                                                                                                  • Filename: prank.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.5539.23420.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.5539.23420.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.MacOS.ReverseShell-C.30585.8425.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zip, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zip, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.7114.13860.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.7114.13860.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.W64.ABRisk.PVEG-3846.30817.29399.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.Trojan.GenericKD.70641791.20493.31768.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........."...L...L...L......L.q.M...L..M...L...M...L.q.I...L.q.H...L.q.O...L...D...L...L...L.......L...N...L.Rich..L.........PE..d....y.e.........." ...#............P........................................p............`.........................................P(.......(..d....P.......@...............`..,...."...............................!..@............ ...............................text............................... ..`.rdata..,.... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......(..............@..@.reloc..,....`.......*..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):13824
                                                                                                                                                                                                                                  Entropy (8bit):5.047528837102683
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:SF/1nb2eqCQtkluknuz4ceS4QDuEA7cqgYvEP:o2P6luLtn4QDHmgYvEP
                                                                                                                                                                                                                                  MD5:30F13366926DDC878B6D761BEC41879E
                                                                                                                                                                                                                                  SHA1:4B98075CCBF72A6CBF882B6C5CADEF8DC6EC91DB
                                                                                                                                                                                                                                  SHA-256:19D5F8081552A8AAFE901601D1FF5C054869308CEF92D03BCBE7BD2BB1291F23
                                                                                                                                                                                                                                  SHA-512:BDCEC85915AB6EC1D37C1D36B075AE2E69AA638B80CD08971D5FDFD9474B4D1CF442ABF8E93AA991F5A8DCF6DB9D79FB67A9FE7148581E6910D9C952A5E166B4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 4%, Browse
                                                                                                                                                                                                                                  Joe Sandbox View:
                                                                                                                                                                                                                                  • Filename: prank.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.5539.23420.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.5539.23420.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.MacOS.ReverseShell-C.30585.8425.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zip, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: MDE_File_Sample_1e64554c1e3e257c1c52d34ca908eb9958a6bbf7.zip, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.7114.13860.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.FileRepMalware.7114.13860.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.W64.ABRisk.PVEG-3846.30817.29399.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  • Filename: SecuriteInfo.com.Trojan.GenericKD.70641791.20493.31768.exe, Detection: malicious, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........\Y..2...2...2......2.i.3...2...3...2...3...2.i.7...2.i.6...2.i.1...2...:...2...2...2.......2...0...2.Rich..2.........PE..d....y.e.........." ...#............P.....................................................`..........................................8.......9..d....`.......P..L............p..,....3...............................1..@............0...............................text...h........................... ..`.rdata.......0......................@..@.data...8....@.......,..............@....pdata..L....P......................@..@.rsrc........`.......2..............@..@.reloc..,....p.......4..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):13312
                                                                                                                                                                                                                                  Entropy (8bit):5.0513840905718395
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:7XF/1nb2eqCQtkXnFYIrWjz0YgWDbu5Do0vdvZt49lkVcqgYvEMN:L2P6XTr0zXgWDbui0vdvZt49MgYvEMN
                                                                                                                                                                                                                                  MD5:CDF7D583B5C0150455BD3DAD43A6BF9B
                                                                                                                                                                                                                                  SHA1:9EE9B033892BEB0E9641A67F456975A78122E4FA
                                                                                                                                                                                                                                  SHA-256:4CA725A1CB10672EE5666ED2B18E926CAAE1A8D8722C14AB3BE2D84BABF646F6
                                                                                                                                                                                                                                  SHA-512:96123559D21A61B144E2989F96F16786C4E94E5FA4DDA0C018EAA7FEFFA61DD6F0ADFA9815DF9D224CDEBE2E7849376D2A79D5A0F51A7F3327A2FAA0A444CE9C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 3%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........\Y..2...2...2......2.i.3...2...3...2...3...2.i.7...2.i.6...2.i.1...2...:...2...2...2.......2...0...2.Rich..2.........PE..d....y.e.........." ...#............P.....................................................`..........................................8.......9..d....`.......P..d............p..,....2...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...8....@.......*..............@....pdata..d....P.......,..............@..@.rsrc........`.......0..............@..@.reloc..,....p.......2..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):12800
                                                                                                                                                                                                                                  Entropy (8bit):5.1050594710160535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:/PTF1siKeai1dqmJo0qVVLf/+NJSC6sc9kJ9oPobXXXP4IIYOxDmO8jcX6gRth2h:/LsiHfq5poUkJ97zIDmOucqgRvE
                                                                                                                                                                                                                                  MD5:7918BFE07DCB7AD21822DBAAA777566D
                                                                                                                                                                                                                                  SHA1:964F5B172759538C4E9E9131CE4BB39885D79842
                                                                                                                                                                                                                                  SHA-256:C00840D02ADA7031D294B1AB94A5F630C813AAE6897F18DD66C731F56931868E
                                                                                                                                                                                                                                  SHA-512:D4A05AB632D4F0EB0ED505D803F6A5C0DBE5117D12BA001CE820674903209F7249B690618555F9C061DB58BED1E03BE58AD5D5FE3BC35FC96DF27635639ABF25
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 3%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............l...l...l......l.q.m...l..m...l...m...l.q.i...l.q.h...l.q.o...l...d...l...l...l.......l...n...l.Rich..l.................PE..d....y.e.........." ...#............P.....................................................`.........................................P8..p....8..d....`.......P...............p..,....3...............................1..@............0...............................text............................... ..`.rdata.......0......................@..@.data...h....@.......*..............@....pdata.......P.......,..............@..@.rsrc........`......................@..@.reloc..,....p.......0..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):36352
                                                                                                                                                                                                                                  Entropy (8bit):6.55587798283519
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:Of+7nYpPMedFDlDchrVX1mEVmT9ZgkoD/PKDkGuF0U390QOo8VdbKBWmuTLg4HPy:WqWB7YJlmLJ3oD/S4j990th9VTsC
                                                                                                                                                                                                                                  MD5:4B032DA3C65EA0CFBDEB8610C4298C51
                                                                                                                                                                                                                                  SHA1:541F9F8D428F4518F96D44BB1037BC348EAE54CF
                                                                                                                                                                                                                                  SHA-256:4AEF77E1359439748E6D3DB1ADB531CF86F4E1A8E437CCD06E8414E83CA28900
                                                                                                                                                                                                                                  SHA-512:2667BF25FD3BF81374750B43AFC5AEFF839EC1FF6DFC3FDD662F1D34A5924F69FC513EA3CD310991F85902A19ADA8B58DED9A9ED7B5D631563F62EA7F2624102
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 1%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........."...L...L...L......L.q.M...L..M...L...M...L.q.I...L.q.H...L.q.O...L...D...L...L...L.......L...N...L.Rich..L.........PE..d....y.e.........." ...#.H...H......P.....................................................`.................................................,...d...............................4... ...................................@............`...............................text....F.......H.................. ..`.rdata..d6...`...8...L..............@..@.data...8...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..4...........................@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):153
                                                                                                                                                                                                                                  Entropy (8bit):3.680458675741643
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/FjlAlHekRL21MUZNJOLlI+rwtbWlMs9KIPldkORT:Cw3+SU0RIRt6koio
                                                                                                                                                                                                                                  MD5:3C45C665CFE036A7474CB4DCBB13CF40
                                                                                                                                                                                                                                  SHA1:62312DFF3C4CD38BAE8456C981601D0D89600F63
                                                                                                                                                                                                                                  SHA-256:8624033D849E670B12C9532337FCBF260F20848E044FEE7787CFE2AC92BE28DB
                                                                                                                                                                                                                                  SHA-512:21659AA452BC2493D915F0BE94F90CDD57759B1F1306AAA2836058D41E80DED24742EBD74E19420021514A6AB4150CA0B447574E96B9D3BF0BC5A8C78DAAF7AC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......fr....v.....q.t.b.a.s.e._.f.r.....q.t.s.c.r.i.p.t._.f.r.....q.t.m.u.l.t.i.m.e.d.i.a._.f.r... .q.t.x.m.l.p.a.t.t.e.r.n.s._.f.r.......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):70
                                                                                                                                                                                                                                  Entropy (8bit):4.463523104731333
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/EXlAlHekQrEuknbJB:CwjO+5JY
                                                                                                                                                                                                                                  MD5:A8D55457C0413893F746D40B637F9C93
                                                                                                                                                                                                                                  SHA1:25123615482947772176E055E4A74043B2FBCAA0
                                                                                                                                                                                                                                  SHA-256:49DF855A004A17950338AF3146466F6DF4D5852410BD0B58EA80E0D0203A9D24
                                                                                                                                                                                                                                  SHA-512:99718B948D94B292BDEDF6B247A5856BC7AC78408FCC41C980F264C2C8565125786F0289F5F993DCF11B8CDA3AFB2A1D8634B1D0BC9B34992F538F8E4086EC00
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......gd..........q.t.b.a.s.e._.g.d....................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):323590
                                                                                                                                                                                                                                  Entropy (8bit):4.568068046062524
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:OYSG8zxWSDjq73Pf6FT1f4uh50QGrRfFD54YyUY0Ou4/tnra3Z0uYhB5YHfHRRn2:O39WSD3TMQGrxFD5EUVQ
                                                                                                                                                                                                                                  MD5:0661FFABFBC50187F3BA38876B721946
                                                                                                                                                                                                                                  SHA1:EB5E7205355CFC6BCB4DF27E224079842C97B296
                                                                                                                                                                                                                                  SHA-256:204A01AC7DEB6B5BAE193AFECBD1E50D18C73BF7D94BADEB2BBFDF6123C4ED93
                                                                                                                                                                                                                                  SHA-512:65AB66CC54D65E7678FA731A5C5F2CC9D6FC217B91AD47D538440811E09A23E49CD95CE62A79E3E8C275E250AC1A0B54BD289F6DD067573876DA7AFF54381D02
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......gl_ESB..I....*.......+..&............@.......A...z...B.......C...p...D.......E......F...!...G......H.......I......P...@...Q.......R......S...5...T......U...+...V.......W...a...X.......Y...N...]..o....t..,................F.......p..............4....;..LI...;..bD...;.......;.......;.......;..cJ...M..o1...O..G....O..e.......U....}..oY...m..o........D..(5...X..+;..6/..+;...~..+;......+O..6...+O...N..1......E@...?..F.......H4..'...HY......H...3`..I......I@......IA......IC..0...J...P...J...1...J...0...J.......K...:...LD..2...L...3...PS..:A..R... d..T.......Zr..Rd..[`......[`.....\...WK..\...RR.._...X..._...f...1........E...{......7M..........1.......1....q......O.......9...............*.......)....$... ...$.......[..,=...,..-....y..0X...y...~......Mx......]0.......H......:A......0....9...............E...o...E..b....E.........1.......c....%..;....%...;......3.......^......S................5..4Z...0..L....0.......0..n....0.......0..7....0.......5..9D......!g.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):83
                                                                                                                                                                                                                                  Entropy (8bit):3.880645689209568
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/YJ/dQlHekfaB21MUXmlvt:CwT0+D/UUt
                                                                                                                                                                                                                                  MD5:DD5C2C6B148F2DB3E666B859776AE129
                                                                                                                                                                                                                                  SHA1:8368F32039CC0776A1B95C9DED5FE6C9EA0D93FD
                                                                                                                                                                                                                                  SHA-256:C113D14E218D5402B616DABEA27969C6F83852676468C5EF051DDDEFB3EE0235
                                                                                                                                                                                                                                  SHA-512:2EAE33C8707407E083F6B8B05EA2C5B987646DF1553888C16D6508C5A33B2F758DDED73323622CD50324C96F51D61B7CE822F393551A30B211ABD3CC1367249F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......he....0.....q.t.b.a.s.e._.h.e.....q.t.s.c.r.i.p.t._.h.e.......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8743
                                                                                                                                                                                                                                  Entropy (8bit):5.189558605179696
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:YUM7gBwnG4Vxj4nyn9aAMOJckrL6esm/0sQ5HeK1nvEB:YBkKnZxkyn9aAMWPsm/0sQsGvEB
                                                                                                                                                                                                                                  MD5:CCD39A7C8139AD041E31B3E5D40968B4
                                                                                                                                                                                                                                  SHA1:5751BE96817BB6AE7C9DA9F1FBA7F42F31CFCC5D
                                                                                                                                                                                                                                  SHA-256:222088C9752D1CC3BAB985EF2DC77E5AE78578DCE18A61EC15B39F02E588163D
                                                                                                                                                                                                                                  SHA-512:9844C0EC65EE1C76DBA021EAC6D476A85E6C8F5BBAF4150C1EA80C0A95BEDE67B5E8F981360EF8599FCECDFCBCB83BC0B8AC44DDEFDCD85F914318030E346967
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......arB.....(.....d.0T....*.5w......Uj....!.`.....M.a[............n..t..............39....&................B<s...V..M^...e......4.O5^...r..)^......o>...........?...t.....D ......k.N.....k.N...C...n...T...I...R..........2>.................|..G.......w....T.......l..........,................^............$a......6.>...........x..K......W.b....._Xn......GN...m..~......!.....J.K.H.............pN.............P.~.....o.....W..(.......~......s.>......%c.....o.....R.z.q..........................n.h................e.....i..........:.J.1. .E.3.E.Q.I..........Untitled.....QHelp.....8.*.9.0.Q.1. .F.3... .E.D.A.Q. .'.D.*.Q.,.E.J.9.).:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.......*.9.0.Q.1. .%.F.4.'.!. .'.D./.Q.D.J.D.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....>.*.9.0.Q.1. .%.F.4.'.!. .,./.'.H.D. .A.J. .'.D.E.D.A.Q. .%.1........... Cannot create tables in file %1......QHelpCollectionHandler.....L.*.9.0.Q.1. .*.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10599
                                                                                                                                                                                                                                  Entropy (8bit):5.192287379770591
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:jhYkcd7CYBdmfIOeX3byuJRoZXlBYnEpUYR+BJqO5X9pA2NNrxC0zwRK2nMY762A:a71DQIrLuVCnEtR+DquhN5xC0zwKPYHA
                                                                                                                                                                                                                                  MD5:5538049DA3A1D1D724AB6E11D2E2EDBE
                                                                                                                                                                                                                                  SHA1:7256BE390B88A053C0252488C443BE42F6F2D92A
                                                                                                                                                                                                                                  SHA-256:CBCDD1E0BBAE332D80DDB0A286056F17C824FA28D353D7FDF12FC97D9F6FE054
                                                                                                                                                                                                                                  SHA-512:DD98CAF3A016968EEDC9106C1839DDECC2D109E9E354708BD74B35E766C6A098C1680C0B867EAD9FCE2E2A6D683BE673B8E5DF1A1B2F1AAFDB31910FF833370F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......bgB...(.(.......0T......5w... S.Uj......`.......a[....(..........t..............39..........&..........B<s...4..M^..........q...J..%..O5^...O..)^...I..o>...I...J..%.......#....t...A.8dz..$..D ....Z.k.N...<.k.N.......n.......I..............2>...p................G..."...w....................7..,................^............$a....<.6.>..........#...K...........$1.W.b....._Xn......GN...*..~....-..TH.."..!.....5.K.H..#R.........pN..."......&..P.~...@.o.....v..(.........."8..~......s.>.....o.... ..z.q..........................O.h....!t..........e....mi..'.....|.(...@.8.G.8.=.0.B.0. .<.>.6.5. .4.0. .5.,. .G.5. .4.>.:.C.<.5.=.B.0.F.8.O.B.0. .2.A.5. .>.I.5. .A.5. .8.=.4.5.:.A.8.@.0...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.........0.1.5.;.5.6.:.0.:..........Note:.....QCLuceneResultWidget.....,. .5.7.C.;.B.0.B.8. .>.B. .B.J.@.A.5.=.5.B.>..........Search Results.....QCLuceneResultWidget....... .
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7444
                                                                                                                                                                                                                                  Entropy (8bit):4.580794980254807
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:G8oS34B7n303D37Bn3Jso37cfp3Mg3H373R58noct36R9RFu:GQU7ETrxZvqTXLSoct36Pzu
                                                                                                                                                                                                                                  MD5:66722ED97BCBFD3DAE3C8264413859AB
                                                                                                                                                                                                                                  SHA1:400A93B213FCF9BBC9785881EA82ADB9F444CD6C
                                                                                                                                                                                                                                  SHA-256:ECD4283A660F2CF72849B323810D7EADD063120B6F561E05AA1243A5B280946A
                                                                                                                                                                                                                                  SHA-512:B898BAC9652D7532384ED5CC53FA62DB55D516421D13F815A3E6D5E80AD4C69555F1A7E6C51F8B0A234614824EEE01D6731458F90D40A585990F84A58B9ABE44
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......caB............%.......0T......K:^.....Uj......`.....P..YJ...V.E.4...*...........>...7........B<s.....B\>...6........+.s.....zq.......9.......vR......@.......@.......:....;.8Z....!.g.N......F................t.....D ....z.k.N.......I......^......`#.......2.......G........N...7......N......{..................K...............GN......NO...5.........K.H...@.........pN......V............q..................>...N.........~.....5..%c...:.z.q....i...4....".A.f.e.g.e.i.x. .u.n. .f.i.l.t.r.e..........Add Filter.....FilterNameDialogClass.......N.o.m. .d.e.l. .f.i.l.t.r.e.:..........Filter Name:.....FilterNameDialogClass.......S.e.n.s.e. .t...t.o.l..........Untitled.....QHelp.....`.N.o. .s.'.h.a. .p.o.g.u.t. .c.o.p.i.a.r. .e.l. .f.i.t.x.e.r. .d.e. .c.o.l...l.e.c.c.i...:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....H.N.o. .s.'.h.a. .p.o.g.u.t. .c.r.e.a.r. .e.l. .d.i.r.e.c.t.o.r.i.:. .%.1..........Cannot create directory: %1.....QHelpCollect
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):15297
                                                                                                                                                                                                                                  Entropy (8bit):4.708378368926237
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:hmv1gdEYEiNrVhTBvAn1ca1f5lwHoJr0vwuxqsP/5jxA:o1gdEvgbloCof9ixqspW
                                                                                                                                                                                                                                  MD5:ED228F0F60AE9AEC28AB9171D5AE9590
                                                                                                                                                                                                                                  SHA1:7F061CF0C699D125A5531E3480C21964452F45EA
                                                                                                                                                                                                                                  SHA-256:4AC56FC63E400943BAB13F1D4C418502138908E1D488C24AEE6131D3D17552AA
                                                                                                                                                                                                                                  SHA-512:794CC671C08BFC50980820A6389B9D0D3514619AD0A8F18EFD5554CBBF2482192DF00B9D3B05FEE45F42276E63E2375FB28E193930D426245035B4B0E3E14ED8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......cs_CZB...H.(.......(.......0T......0T......5w...0..Uj......`.......a[......a[....$.......p..........t.......t...........!..1"....T.39....T.39.......s...0......(......7/.................B<s...L..MQ......M^../q..........J..6@.0....*B.O5Q..'..O5^..(A..)Q...X..)^......o>..........+....J..6.......4....t.....8dz..5..D ....R.D ......k.A.....k.A.....k.N.....k.N.......n.."....I..........................2...21......2>..........d.............T..G...4...w...!N......&O......&....!..".......#E..,...,.......)....Q..$/...^..$................$a......6.>.. t......5...K.......K....)......5E.W.b..-.._Xa..%a._Xn..%...GA......GN...?......,9..~.......TH..3..!....*..K.H..4h.........pA...J..pN..........7..P.~.. ..o.....0..(....*..(..........3V..~....T.s.1.....s.>..._.o....0..o....1p.z.q..........'9.....#........^.........h....2................Z..e... .i..8J......(.D.o.v.o.d.e.m. .p.r.o. .t.o. .b.y. .m.o.h.l.o. .b...t.,. .~.e. .d.o.k.u.m.e.n.t.a.c.e. .j.e. .s.t...l.e. .j.e.a.t...
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4795
                                                                                                                                                                                                                                  Entropy (8bit):4.530246422531362
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:X82wNlnKfN1LMFy7LsF3ZqBFZjWo0koBLqBXXjGL0qU7UqB7zoElmP5MUu4DZIHU:XM01f7eOnoB8X2s7Vfg5Mi4beXiOUu
                                                                                                                                                                                                                                  MD5:1D09BEE1FB55A173F7EB39B9A662A170
                                                                                                                                                                                                                                  SHA1:C77F0A148262A91679F19689E4790B754D45D5D5
                                                                                                                                                                                                                                  SHA-256:6BB092552A398687119F6D52145F04BF8373977446D8F00C0DCBD56B96829F0F
                                                                                                                                                                                                                                  SHA-512:BE5A31A6135E8DB024A8B0EB20C4D8EECBF76861F83FF83B4CA97327DB74AD94BB5D77B4E0A59A33B697C32A4EACD61B8C878951F2C545385C74D99FCE56FEE1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......daB.....%.....m.0T......Uj....V.`....................k.B<s.....B\>..........6.+.s...............t.....D ....|.k.N...9...I...O..2.......G....B...N...O..............!..K...._..........GN...........@.K.H.............pN..............>.....~.....m..%c.....z.q....i..........U.n.a.v.n.g.i.v.e.t..........Untitled.....QHelp.....D.K.a.n. .i.k.k.e. .k.o.p.i.e.r.e. .s.a.m.l.i.n.g.s.f.i.l.e.n.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....6.K.a.n. .i.k.k.e. .o.p.r.e.t.t.e. .m.a.p.p.e.n.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....V.K.a.n. .i.k.k.e. .o.p.r.e.t.t.e. .i.n.d.e.k.s.t.a.b.e.l.l.e.r. .i. .f.i.l.e.n. .%.1...........&Cannot create index tables in file %1......QHelpCollectionHandler.....J.K.a.n. .i.k.k.e. .o.p.r.e.t.t.e. .t.a.b.e.l.l.e.r. .i. .f.i.l.e.n. .%.1........... Cannot create tables in file %1......QHelpCollectionHandler.....P.K.a.n. .i.k.k.e. .i.n.d.l...s.e. .s.q.l.i.t.e.-.d.a.t.a.b.a.s.e.-.d.r
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7570
                                                                                                                                                                                                                                  Entropy (8bit):4.550982634910665
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:8y/gPmmhL/7LlSivP6kBL7jb0RNUzzpld4UGG3Ik18fLP0L7fGc0OeVP8a8hiAwj:1OD7hx/Bv3oNuFX4iqgv34fZsu
                                                                                                                                                                                                                                  MD5:3B070D169E3381E2FB081172934AAD00
                                                                                                                                                                                                                                  SHA1:70886EB7EF566B296D0814BD4C2440AC176699D6
                                                                                                                                                                                                                                  SHA-256:9962523FBAE9F1E4C3B5C3C16860D059291CB30DC5EBE5A5EDA4C836A03FED1E
                                                                                                                                                                                                                                  SHA-512:271B730B5A7358E923BBBC6FA074A72DA52FA47E3B7726779EF7034200EDA09BF0E1AE4E7B11B59F76805F48DC285F6EFC245EB9C7F4A748BE82B25CEE1DDCAE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......deB..........B.%.....5.0T......K:^.....Uj....?.`.....f..YJ...V.E.4...............>............B<s...z.B\>...\........+.s...Q.zq....C..9....4..vR...B..@.......@.......:......8Z......g.N......F....>...........t.....D ......k.N.......I......^....|.`#....I..2....<..G....^...N.........................;..........K....y..........GN......NO...........,.K.H.............pN......V...................."..........>.............~........%c.....z.q....i........".F.i.l.t.e.r. .h.i.n.z.u.f...g.e.n..........Add Filter.....FilterNameDialogClass.....".N.a.m.e. .d.e.s. .F.i.l.t.e.r.s.:..........Filter Name:.....FilterNameDialogClass.......O.h.n.e. .T.i.t.e.l..........Untitled.....QHelp.....\.D.i.e. .K.a.t.a.l.o.g.d.a.t.e.i. .k.a.n.n. .n.i.c.h.t. .k.o.p.i.e.r.t. .w.e.r.d.e.n.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....\.D.a.s. .V.e.r.z.e.i.c.h.n.i.s. .k.a.n.n. .n.i.c.h.t. .a.n.g.e.l.e.g.t. .w.e.r.d.e.n.:. .%.1..........Cannot create directory: %
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                  Entropy (8bit):4.0
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4n:CwZ
                                                                                                                                                                                                                                  MD5:BCEBCF42735C6849BDECBB77451021DD
                                                                                                                                                                                                                                  SHA1:4884FD9AF6890647B7AF1AEFA57F38CCA49AD899
                                                                                                                                                                                                                                  SHA-256:9959B510B15D18937848AD13007E30459D2E993C67E564BADBFC18F935695C85
                                                                                                                                                                                                                                  SHA-512:F951B511FFB1A6B94B1BCAE9DF26B41B2FF829560583D7C83E70279D1B5304BDE299B3679D863CAD6BB79D0BEDA524FC195B7F054ECF11D2090037526B451B78
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`...
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10704
                                                                                                                                                                                                                                  Entropy (8bit):4.481291573289571
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:q9J9j7e4BQhD0h61nnKz+DJF/45ojDU9V1Wa/rmtIBMH:Wp64ShDnnKz+FhjQpWa/ytoMH
                                                                                                                                                                                                                                  MD5:9EDF433AB9EE5FC7CF7782370150B26A
                                                                                                                                                                                                                                  SHA1:A918AE15A0DF187C7789BE8599A80E279F039964
                                                                                                                                                                                                                                  SHA-256:FD16B279F8CF69077F75E94D90C9C07A2AFFF3948A579E3789F5FFB5E5F4202D
                                                                                                                                                                                                                                  SHA-512:88245F6FBAAF603A03D7EA2341411AE040791D47C9FF110C6D6CDD8165F0A8BA7A4A0DA5CD543BBE95A4E93FE3A81E95B3664E00C11791FBCB4923E3A80ABC60
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......es_ESB...(.(.....7.0T..../.5w... C.Uj......`.......a[....0..........t..............39..........&e.........B<s...D..M^..............J..%p.O5^...I..)^...1..o>.......J..%.......#....t.....8dz..$..D ......k.N.....k.N.......n.......I..............2>....................G...#...w............!.......%..,................^............$a......6.>..........#...K...........$C.W.b....._Xn......GN...|..~.......TH.."..!.....5.K.H..#f.........pN...j......'..P.~... .o........(....>....."<..~....c.s.>.....o.... ..z.q..........................u.h....!p.......*..e....Qi..'}......(.L.a. .r.a.z...n. .d.e. .e.s.t.o. .p.u.e.d.e. .s.e.r. .q.u.e. .l.a. .d.o.c.u.m.e.n.t.a.c.i...n. .a...n. .e.s.t... .s.i.e.n.d.o. .i.n.d.e.x.a.d.a...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.a.:..........Note:.....QCLuceneResultWidget.....2.R.e.s.u.l.t.a.d.o.s. .d.e. .l.a. .B...s.q.u.e.d.a..........Search Results.....QCLu
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10922
                                                                                                                                                                                                                                  Entropy (8bit):4.459946393010639
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:w4BIn67/WsmoB3r6M/eYlSbyE7DnvE7pcn9nPJZe7nOFovzcNn7Uhmio+2/p53I/:w4N19fq3n2c9Bucuhmi52/X3Qpam
                                                                                                                                                                                                                                  MD5:D520C7F85CC06C66715A2B6622BF0687
                                                                                                                                                                                                                                  SHA1:47292D068172FBC9DC0D9BE2F479E890A37CE138
                                                                                                                                                                                                                                  SHA-256:687E351C062F688AAFF6CF05218D6017B80B1A1B4238D1D30250A55EE41C5FED
                                                                                                                                                                                                                                  SHA-512:736B50BB64751B127300BCAFE88888A9D9A2081CBF934EDCFFEF6CEF0575505AFDF714273A97671ABB598AE3D23C8E55F7DCD632FB0AA219ED5F763768576E04
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......fr_FRB...(.(.....y.0T....K.5w...!1.Uj....*.`.......a[............5..t..............39....m.....'W.......S.B<s...d..M^.. ...........J..&`.O5^...+..)^......o>.......J..&.......$....t.....8dz..%..D ......k.N.....k.N...D...n.......I...........c..2>..........M.........G...$...w....K..................,................^............$a......6.>...c......$...K....'......%M.W.b....._Xn...j..GN......~.......TH..#..!.......K.H..$Z......,..pN..........'..P.~.....o........(....h.....#4..~......s.>...M.o....!..z.q...........p......L.........h...."^.......b..e.....i..(W......(.I.l. .e.s.t. .p.o.s.s.i.b.l.e. .q.u.e. .c.e.l.a. .s.o.i.t. .d... .a.u. .f.a.i.t. .q.u.e. .l.a. .d.o.c.u.m.e.n.t.a.t.i.o.n. .e.s.t. .e.n. .c.o.u.r.s. .d.'.i.n.d.e.x.a.t.i.o.n...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.e. .:..........Note:.....QCLuceneResultWidget.....2.R...s.u.l.t.a.t.s. .d.e. .l.a. .r.e.c.h.e.r.c.h.e.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10891
                                                                                                                                                                                                                                  Entropy (8bit):4.5087667371046205
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Im7gBZHx4hCTNarW6EJDvoIR765f40wqNcMi/8F/Ihon:v0fHccarW6Eh61wqNcMi/Q/won
                                                                                                                                                                                                                                  MD5:B62C74793741FC386332A59113E8D412
                                                                                                                                                                                                                                  SHA1:589CE099F2C1D92581B5CF0E17BE49A2BF0014D4
                                                                                                                                                                                                                                  SHA-256:7399A248609974773F60866C87B78EA7DFBC4F750313D692F7886CD763883C9F
                                                                                                                                                                                                                                  SHA-512:D8E1A3B3732662BA572A1387651F2625742710834BEDB41809DA47B5D23020AA1B558B64A00C10C605D1844F0544483163F4A6227CAFFA5ECDABF3BBF4E12D9B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......gl_ESB...8.(.......0T......Uj......`.....`.a[....F..........t..............1"... S.39.......s...!.............'F.........B<s...8..MQ.. ...........J..&S.0.....x.O5Q......)Q...O..o>...{.......#...J..&.......$....t.....8dz..%..D ......k.A.....k.A.......n.......I.................."...21....................G...#...w............[...!...?...........Q...?........$a....v.6.>..........$...K...........%0._Xa......GA...n..........~.......TH..#..K.H..$M.........pA...Z......'..P.~...B.o........(..........#+..~......s.1.....o....!..z.q...e.............................. ..e....wi..((......(.A. .r.a.z...n. .d.i.s.t.o. .p.o.d.e. .s.e.r. .q.u.e. .a. .d.o.c.u.m.e.n.t.a.c.i...n. .a...n.d.a. .e.s.t.e.a. .a. .i.n.d.e.x.a.r.s.e...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.a.:..........Note:.....QCLuceneResultWidget.....*.R.e.s.u.l.t.a.d.o.s. .d.a. .p.r.o.c.u.r.a..........Search Results.....QCLucene
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10284
                                                                                                                                                                                                                                  Entropy (8bit):4.674501432335502
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:RNY+rCG3e7LBqYqYseBb/FEWBgSn62TdJgDO9esYGY3DtgGh621XlZ/8kWvIMK:4+rheHYYZdBb/pgSn62T/FeVD3DGGh62
                                                                                                                                                                                                                                  MD5:5A56E9E2ED6ECE3F249D1C2A7EB3B172
                                                                                                                                                                                                                                  SHA1:D6F079F40FBB813B0293C1D2210BAE7084092FEC
                                                                                                                                                                                                                                  SHA-256:70F33B569C2942F41C6D634EA6A61CB8D80EB2C7011BAD48EF6DBAE9677960D5
                                                                                                                                                                                                                                  SHA-512:28947128FC51791CFDBFD3958FAF9B33979DB52C90AE0159EDB01FE6032284EB37BC05187162983A0435560BCEA864B008F499CDB4CE662792599FE20A37972A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......hu_HUB...(.(.......0T......5w......Uj......`.....4.a[....N..........t....".........39..........%..........B<s...8..M^...8..........J..$..O5^......)^...]..o>.......J..$......."N...t.....8dz..#g.D ......k.N...>.k.N.......n.......I..............2>..........a.........G...!...w.......................,................^............$a......6.>.........."...K....m......"..W.b...l._Xn...~..GN......~.......TH..!F.!.......K.H..!..........pN..........%..P.~...<.o........(.......... ...~......s.>...{.o.....c.z.q...K.......v......l.........h.... ........t..e....mi..%.....~.(.E.z. .a.m.i.a.t.t. .l.e.h.e.t.,. .h.o.g.y. .a. .d.o.k.u.m.e.n.t...c.i... .m...g. .i.n.d.e.x.e.l...s. .a.l.a.t.t. .v.a.n...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......M.e.g.j.e.g.y.z...s.:..........Note:.....QCLuceneResultWidget.....&.K.e.r.e.s...s.i. .e.r.e.d.m...n.y.e.k..........Search Results.....QCLuceneResultWidget.......A
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10612
                                                                                                                                                                                                                                  Entropy (8bit):4.458970627057882
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:nRxcfy71b+myBN16cbc+w45rtlTnzo7uHp3JQJ9cVu4BJ1G82g33vOVrNL/7nEF1:RR4R/fJn9JizTgnqrNL/b0hH2K
                                                                                                                                                                                                                                  MD5:3639B57B463987F6DB07629253ACD8BF
                                                                                                                                                                                                                                  SHA1:65935A67C73F19FCF6023FB95030A5ACAF9DA21C
                                                                                                                                                                                                                                  SHA-256:316FE8D0815E2B4B396895BEB38EF1A40431915B5E054DF80F4C0CD556F26E4B
                                                                                                                                                                                                                                  SHA-512:AD7CA93D93A69F273CE80BE7F2F477543B9C5F9C7E4D7448223BFF084EA956B626D6837F22D83C5E282688B938F58C29073C4B5C6F26A797F716C14FABF9FFEE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......it_ITB...(.(.....g.0T....y.5w... ..Uj....2.`.......a[............'..t..............39..........&..........B<s...j..M^...h......K...J..%..O5^...K..)^......o>...u...J..%.......#....t.....8dz..$..D ......k.N.....k.N.......n.......I..............2>.................o..G..."...w............-......./..,................^...'........$a......6.>..........#...K...........$..W.b....._Xn......GN......~.......TH.."n.!.....5.K.H..#"......>..pN..........&..P.~.....o.....~..(....p.....!...~....A.s.>.....o.... ..z.q..........................q.h....!0.......*..e....;i..'!......(.L.a. .c.a.u.s.a. .d.i. .c.i... .p.o.t.r.e.b.b.e. .e.s.s.e.r.e. .c.h.e. .l.'.i.n.d.i.c.i.z.z.a.z.i.o.n.e. .d.e.l.l.a. .d.o.c.u.m.e.n.t.a.z.i.o.n.e. ... .a.n.c.o.r.a. .i.n. .c.o.r.s.o...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......N.o.t.a.:..........Note:.....QCLuceneResultWidget.......R.i.s.u.l.t.a.t.i. .d.e.l.l.a. .r.i.c.e.r.c.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7917
                                                                                                                                                                                                                                  Entropy (8bit):5.680408580146589
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:mP6J37GcBzRjYEPEJJGTnwfJJxb7FTPjzzZBL3/q/I53:mSVqclR5s6Tnwfb7Pj/PL3/q/w3
                                                                                                                                                                                                                                  MD5:1380A9352C476071BDA5A5D4FED0B6C5
                                                                                                                                                                                                                                  SHA1:9B737ED05F80FE5D3CD8F588CCEC16BB11DD3560
                                                                                                                                                                                                                                  SHA-256:AE603B2C0D434D40CDE433FFCBA65F9EE27978A9E19316007BE7FE782A5B8B47
                                                                                                                                                                                                                                  SHA-512:EC3D68126488C3A163898BACAF7E783217868573635182CAF511ED046B4BE1F99A71FBB24DA607CCB50EDAF70893007AAEE9A6BAAE4C1CD33465A0915AA965DA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......jaB...(.(.....S.0T......5w....'.Uj......`.......a[............u..t............!.39.....................B<s......M^..............J...>.O5^...O..)^......o>.......J...............t...w.8dz.....D ......k.N.....k.N...H...n.......I...........i..2>...<......G......9..G....P..w............i..........,................^..........'.$a......6.>...5..........K............S.W.b...2._Xn......GN...@..~.......TH.....!.......K.H.............pN...........S.P.~.....o.....|..(..............~....o.s.>.....o.......z.q..................@.........h.....&....... ..e.....i........@.(0.0.0.0.0.0.0n}"_.0nO\b.0L}BN.0W0f0D0j0D0_0.0K0.0W0.0~0[0.0..).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget......l..:..........Note:.....QCLuceneResultWidget......i.}"}Pg...........Search Results.....QCLuceneResultWidget.....R0.0.0.0.0.0.0n}"_.0nO\b.0L}BN.0W0f0D0j0D0_0.0.i.}"}Pg.0LN.[.Qh0jS..`'0L0B0.0~0Y0..........VThe search results may
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5708
                                                                                                                                                                                                                                  Entropy (8bit):5.698914195742074
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:elPQHJ6L4c7LaQaFQv2QEhBL+Ejma0W40U0BzlQlcrnUSaTIdspIc18CLRSM3LBY:dHI97W1BbNz1VqqzJpoj5y5uY7OGrWFE
                                                                                                                                                                                                                                  MD5:CD15674A652C2BF435F7578E119182F8
                                                                                                                                                                                                                                  SHA1:AEA22E4A0D21396733802C7AB738DDD03737B7D6
                                                                                                                                                                                                                                  SHA-256:F11C64694E8E34E1D2C46C1A1D15D6BA9F2DB7B61DE4FDF54ECA5AB977C3E052
                                                                                                                                                                                                                                  SHA-512:88BFA112F4DBC0BFB4013CE0937E5180B4AB4A217FC8A963798C7C86532E794E4A1AD88416AE42F26A1C0631B465A5D69BFE75366E048502F5E21F4115A12F19
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......koB............%.......0T......K:^...g.Uj......`........YJ...>.E.4...........z...>..........;.B<s...K.B\>...b........+.s.....zq....[..9....F..vR......@.......@.......:....c.8Z......g.N...7..F....|...........t.....D ......k.N.......I...m..^......`#....!..2.......G....@...N.................................X..K....{.......i..GN......NO.............K.H..........S..pN...z..V...............................>...........:.~.....i..%c.....z.q....i...s......D.0. .............Add Filter.....FilterNameDialogClass.......D.0. .t...:..........Filter Name:.....FilterNameDialogClass........... ...L..........Untitled.....QHelp.....(...L... ...|.D. .....`. ... ...L.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....".....0...|. .... ... ...L.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....2...|. .%.1... ...x. .L.t...D. .... ... .................&Cannot create index tables in file %1......QHelpCollectionHandler.....,.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9673
                                                                                                                                                                                                                                  Entropy (8bit):4.622652249027856
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:TO/7kBL9wGu3wtCnlhLJUBB7oph+mZ18LgP:T8QnwcCnlhdvphpZ18LgP
                                                                                                                                                                                                                                  MD5:2B68446B69D9AA40B273D75A581D2992
                                                                                                                                                                                                                                  SHA1:8A09BD38998543B74E2673478EDD54FB4BBDD068
                                                                                                                                                                                                                                  SHA-256:CC6CB4D8C54086224672F2E49E623C8CB7C0C1CD65B8D5ECD42FC9BA3A6065BD
                                                                                                                                                                                                                                  SHA-512:F3A3D6A416B3411613B06FC3EE56625D4D4DE80087182AB0D0601E49314861ABEF97D11A15B4C0511911544A59FBC4A4A52F0CCF0FD43F763A76A8922D8E57B6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......plB.....(.......0T....T.5w......Uj... R.`.......a[...............t............2.39....H......6.......n.B<s.. ...M^..._......6.O5^...F..)^......o>...............t.....D ......k.N.....k.N.../...n.......I...W..........2>...w................G.......w............&.......:..,................^...(..... ..$a....?.6.>...$..........K......W.b....._Xn......GN...Y..~......!.....*.K.H...E....."...pN...-.........P.~...}.o........(....1..~......s.>......%c.."..o.....r.z.q............................h................e.....i..#.......N.i.e.n.a.z.w.a.n.y..........Untitled.....QHelp.....P.N.i.e. .m.o.|.n.a. .s.k.o.p.i.o.w.a... .p.l.i.k.u. .z. .k.o.l.e.k.c.j...:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....>.N.i.e. .m.o.|.n.a. .u.t.w.o.r.z.y... .k.a.t.a.l.o.g.u.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....H.N.i.e. .m.o.|.n.a. .u.t.w.o.r.z.y... .t.a.b.e.l. .w. .p.l.i.k.u. .%.1........... Cannot create tables in file
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7288
                                                                                                                                                                                                                                  Entropy (8bit):5.297177914619657
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:dBJjvfq7D6X68uBAzlp5W9+yBPZZZMM7vL0PXJL:JKrMEL0PXJL
                                                                                                                                                                                                                                  MD5:794AF445A5D7082D51BD22683449F86D
                                                                                                                                                                                                                                  SHA1:3A0C369872B112A1572AA17EEB814B168B225D98
                                                                                                                                                                                                                                  SHA-256:557B644E6DA5F1EC720EF93965617087E4D1F40B2494CC5AA524CF3796108DE7
                                                                                                                                                                                                                                  SHA-512:D42C870A16AEE7626BBE24886AD423895529A2F1A51AC2DBC303BC0E4EF9D3241FE894ECA3F7217AD408C8DCEE165CA4B89D84570357B0EB80340A3F72B0A846
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......ruB..........\.%.......0T......K:^.....Uj....L.`........YJ...X.E.4...............>............B<s.....B\>............+.s.....zq.......9....B..vR...L..@.......@....G..:......8Z......g.N......F....>...........t.....D ....R.k.N...E...I...W..^......`#....s..2.......G....^...N.........................K.......d..K............O..GN...b..NO.............K.H.............pN...P..V....................g..........>.............~........%c.....z.q....i........$...>.1.0.2.;.5.=.8.5. .D.8.;.L.B.@.0..........Add Filter.....FilterNameDialogClass.........<.O. .D.8.;.L.B.@.0.:..........Filter Name:.....FilterNameDialogClass.........5.7.K.<.O.=.=.K.9..........Untitled.....QHelp.....b...5. .C.4.0.;.>.A.L. .A.:.>.?.8.@.>.2.0.B.L. .D.0.9.;. .:.>.;.;.5.:.F.8.8. .A.?.@.0.2.:.8.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....<...5. .C.4.0.;.>.A.L. .A.>.7.4.0.B.L. .:.0.B.0.;.>.3.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....`
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10388
                                                                                                                                                                                                                                  Entropy (8bit):4.70568613551943
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:uPq7iBWseXKkVu4+Qv9zEJ1xGMaLNmBgJqdC6/MxIMt:LWcseV04Xv9zEoLNDJqdX/MxRt
                                                                                                                                                                                                                                  MD5:75C94E59F1FC5312AE25381C247AF992
                                                                                                                                                                                                                                  SHA1:E3E5F4582CC5FAFE6DF43644D11484861023C084
                                                                                                                                                                                                                                  SHA-256:F41E33E1D790BD0D3EB180F1F875BC191FE74773628F25C2CAD95E1402E66867
                                                                                                                                                                                                                                  SHA-512:959B8F4D57FC9728DD4804322333D1792D45A0EE85615B559E0CA3BD2DEA22E2C8C68C6482AE9425D29C819B0ED27473EDDC82EF4B6ECFFB2E2E7B56E1509B63
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......sk_SKB...8.(.......0T......Uj......`.....0.a[....8..........t..............1"......39.......s........... .....%..........B<s...6..MQ..............J..$-.0.......O5Q......)Q...;..o>...........G...J..$......."....t.....8dz..#..D ......k.A...2.k.A.......n..._...I.................. ...21..........e.........G...!...w....Y...........!...........=...Q............$a......6.>.........."...K....i......# ._Xa..."..GA..............~.......TH..!{.K.H.."7.........pA..........%..P.~.....o........(..........!...~....u.s.1.....o.......z.q...c..............................f..e....9i..&-......(.D...v.o.d.o.m. .m...~.e. .b.y.e. .t.o.,. .~.e. .d.o.k.u.m.e.n.t...c.i.a. .s.t...l.e. .n.i.e. .j.e. .z.i.n.d.e.x.o.v.a.n.....).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......P.o.z.n...m.k.a.:..........Note:.....QCLuceneResultWidget.....".V...s.l.e.d.k.y. .h.>.a.d.a.n.i.a..........Search Results.....QCLuceneResultWidg
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10363
                                                                                                                                                                                                                                  Entropy (8bit):4.613473842638716
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:vNBqTi7qBCVIQf54EslZ2Jy/L/BnmpP0bX3caK6q1B6/hgIlCCUb0:vjq2+UVT4ESZOYmpP0bX26q1I/yqCCUw
                                                                                                                                                                                                                                  MD5:3B0AEE27B193A8A563C5CB5C7C4FE60F
                                                                                                                                                                                                                                  SHA1:C94E832595EC765370553468F87C02DB7E7D138A
                                                                                                                                                                                                                                  SHA-256:2EC955E662407EBCD8DCDAE5AAA21E4108E0B5B0AEE0E9DB712C27072943535F
                                                                                                                                                                                                                                  SHA-512:EBC25C378126876F44279E23CA0CF06FC9E7D5F51AD7E3DBDABA7A50C81112EDC1C76F7FD0AF47E447A93C3593BB953A0C9C1FBBFC49494E6B29BF21655F690E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......slB...8.(.....E.0T......Uj......`.......a[............!..t..............1"....;.39.......s....^............$........i.B<s...,..MQ..........}...J..#..0.....Z.O5Q...[..)Q......o>...............J..$I......"W...t...C.8dz..#H.D ......k.A.....k.A.......n.......I.................. P..21....................G...!...w............?...!...3...........Q...+........$a....>.6.>.........."...K...........".._Xa......GA..............~....A..TH..!I.K.H..!..........pA...>......%..P.~...>.o........(....d..... ...~......s.1.....o.......z.q.....................................e....{i..&.....z.(.R.a.z.l.o.g. .j.e. .m.o.r.d.a. .t.o.,. .d.a. .s.e. .d.o.k.u.m.e.n.t.a.c.i.j.o. .a.e. .v.e.d.n.o. .i.n.d.e.k.s.i.r.a...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.......O.p.o.m.b.a.:..........Note:.....QCLuceneResultWidget.....".R.e.z.u.l.t.a.t.i. .i.s.k.a.n.j.a..........Search Results.....QCLuceneResultWidget.......R.e.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4629
                                                                                                                                                                                                                                  Entropy (8bit):4.68793836539357
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:BoiK0UD2wMLb7Lqlguotqbww5BLNwWjK0kHU9zuQlUVUfniqthweEIFwC18lLEGA:PXFf7pU75BWWOpcJcVqDFNz8brgyf76r
                                                                                                                                                                                                                                  MD5:32D6EE3D8EE6408A03E568B972F93BCB
                                                                                                                                                                                                                                  SHA1:582EE079DBD42000C378E0701D26405750524DBA
                                                                                                                                                                                                                                  SHA-256:EBDECA0CFEE7A9441DEB800BABFD97C63BC4E421DA885C55B3BD49725EBACD25
                                                                                                                                                                                                                                  SHA-512:24AAA30B9CB4DB82A57411FBA24A87D70D8B845AE48A6FDA633D0BE6B824B58FDD2F450C2B385F16F49E2F9C6FA0A3124FD0F28594726940F996C66F8F3216CC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......tr_TRB.....%.....[.0T......Uj......`.....$..............L.B<s.....B\>..........4.+.s...............t.....D ......k.N...5...I......2.......G....5...N..........a...............f..K....9..........GN...........@.K.H..........q..pN...t..........>...z.~...../..%c.....z.q....i..........B.a._.l.1.k.s.1.z..........Untitled.....QHelp.....J.K.o.l.e.k.s.i.y.o.n. .d.o.s.y.a.s.1. .k.o.p.y.a.l.a.n.a.m.1.y.o.r.:. .%.1..........Cannot copy collection file: %1.....QHelpCollectionHandler.....2.D.i.z.i.n. .o.l.u._.t.u.r.u.l.a.m.1.y.o.r.:. .%.1..........Cannot create directory: %1.....QHelpCollectionHandler.....\.%.1. .d.o.s.y.a.s.1.n.d.a. .d.i.z.i.n. .t.a.b.l.o.l.a.r.1. .o.l.u._.t.u.r.u.l.a.m.1.y.o.r...........&Cannot create index tables in file %1......QHelpCollectionHandler.....N.%.1. .d.o.s.y.a.s.1.n.d.a. .t.a.b.l.o.l.a.r. .o.l.u._.t.u.r.u.l.a.m.1.y.o.r........... Cannot create tables in file %1......QHelpCollectionHandler.....P.S.q.l.i.t.e. .v.e.r.i.t.a.b.a.n.1. .s...r...c...
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9750
                                                                                                                                                                                                                                  Entropy (8bit):5.281035122342072
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:eMp79BCN+u8hhbHbny+HJouHgei50JBSfDvbetpP/RIkT:eIhgNgBbny+phiS3SfDDetpP/RRT
                                                                                                                                                                                                                                  MD5:90A776917D534B65942063C319573CDC
                                                                                                                                                                                                                                  SHA1:5DF3B213D985A3BBDB476B37B7780D7D7DF17E41
                                                                                                                                                                                                                                  SHA-256:497CFC473684692EE44D7A3795E8FB2270C57069FD9EB98A615DD29AB9BE8A7C
                                                                                                                                                                                                                                  SHA-512:B34A019716B50CE8E1E20AC32756B3B0D5802971F7A04F4BDDE2418DA551AFB9742B79E934979DB6FAB9DAC05D7D26A3B19ABA77158321F8D9AAB08AEBBD455A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......uk_UAB...(.(.....?.0T......5w......Uj......`.......a[...............t............K.39....u....."..........B<s...8..M^...j......y...J..!..O5^...Y..)^......o>...o...J..":...... <...t...E.8dz..!3.D ....".k.N.....k.N...d...n.......I..............2>...>......o.........G.......w............E.......e..,................^...S........$a......6.>...'...... y..K........... ..W.b....._Xn......GN...p..~.......TH...4.!.....9.K.H.............pN..........#].P.~...~.o.....N..(....b.........~......s.>.....o.....o.z.q..........................U.h.............D..e.....i..#.......(...@.8.G.8.=.>.N. .F.L.>.3.>. .<.>.6.5. .1.C.B.8. .B.5.,. .I.>. .4.>.:.C.<.5.=.B.0.F.V.O. .4.>.A.V. .V.=.4.5.:.A.C.T.B.L.A.O...).........M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget.........@.8.<.V.B.:.0.:..........Note:.....QCLuceneResultWidget.....". .5.7.C.;.L.B.0.B.8. .?.>.H.C.:.C..........Search Results.....QCLuceneResultWidget....... .5.7
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6441
                                                                                                                                                                                                                                  Entropy (8bit):5.790303416386852
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:pB37nBD4H5PCyLDxLSzJPduYx9vja/FIgH9yIFqfs:rTZ4HUAD1S1JFe/F59PFqfs
                                                                                                                                                                                                                                  MD5:9297A6905B8B1823BF7E318D9138A104
                                                                                                                                                                                                                                  SHA1:3DB992A1B3BBCAF314B7EA4A000D6334D7492A52
                                                                                                                                                                                                                                  SHA-256:C02AAA20923F18ADDAB520BE5CB84EFD4C723396BDC24B4C9A72D406F101C7B4
                                                                                                                                                                                                                                  SHA-512:01F12CEE0AE456D78942A6049E1C77F94B406C8FFB4A5944DE15E54D1C760CDBA13279530A8F29B1443D1BBC647D3AF5436AAD8C43EB3944316C48300B3827E4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......zhB......I....L.0T......Uj......`.......a[...............t....P..@....Z.......<.........39.......s....2.................B<s......MQ..........9...J......31.....0.......O5Q......)Q...^..o>...........(...........J...V...........t.....8dz.....D ....Z.k.A.....k.A.......n.......I...........t..w................!...........o.......D...Q...E........$a......6.>...h...............%._Xa......GA..........._..TH...r.........pA.............P.~.....o.....].~.q.............~......o.....h.z.q...........H..0q....................i........2..S.u...y.`.Q.v.S.V.S..f/V.N:..e.hckcW(..}"_.0............M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget......l..............Note:.....QCLuceneResultWidget......d.}"~.g...........Search Results.....QCLuceneResultWidget.....,d.}"~.g.N_..^vN.[.et..V.N:..e.hckcW(..}"_............VThe search results may not be complete since the documentation is still being indexed!.....QCLuceneResultWidget..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9301
                                                                                                                                                                                                                                  Entropy (8bit):5.80411750798786
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:4bgIXwsL78BQp4dRDP0ludqODa/wkB/tTWn5dJ6mO8IZiT9Dzz/wI3HyRWqUqS:lI/oS4dR5c/tTWn5/EZA9D/w+H8WqUqS
                                                                                                                                                                                                                                  MD5:47C3328D3918CF627112BB6C50E30B86
                                                                                                                                                                                                                                  SHA1:05705603AB3F28402A6C103E1C41DDFF21D140C0
                                                                                                                                                                                                                                  SHA-256:3697F1660D7F2AC9B37AC33CD1C7ECAE08ADBD26710E7E0076497CCDDC8BC830
                                                                                                                                                                                                                                  SHA-512:8DE1C3C5A48965CF6D8AA545DA9F0A5C00AE124F3E4153597915E7C0F4CAE1E26723270F58A47AA9FFA4AAF30E6EBA522D4EBAD27DECF17EF108E353E611980E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......zh_TWB......I....[.%.......0T......0T......Uj......Uj....R.`.....>.a[....................g..t....7..@......................39.......s................... .........B<s.....B<s.....B\>......MQ..........[...J...]..31.....+.s...c.0.....U.O5Q......)Q...C..o>.......................J...............t...3...t.....8dz.....D ....R.D ......k.A.....k.A.....k.N...'...n.......I.......I...........[..2....x..G........N......w................!...........:...........Q...&...............$a......6.>...I.......L.......$..K......................_Xa...y..GA...O..GN...........$..........TH...I.K.H................ Y..pA...K..pN.............P.~.....o.....D.~.q......>.............~......~........%c.. ..o.....!.z.q...........#..0q....................i..!Y....(..g.S..f/V.p.N.W(^.z.e.N.v.}"_.uvN-0............M(The reason for this might be that the documentation is still being indexed.).....QCLuceneResultWidget......P..;............Note:.....QCLuceneResultWidget......d.\.}Pg...........Sea
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):146
                                                                                                                                                                                                                                  Entropy (8bit):3.6255640074603277
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/IrLlAlHekfK/gp1MUXaMlI+rwtbWlMiayIPldkOgn:CwDrC+TYIUrIRt6HoiHn
                                                                                                                                                                                                                                  MD5:5A46979B45C67DD6312F33CCEA2ED7BC
                                                                                                                                                                                                                                  SHA1:4C56836B1FB10D9903B299CBCB925947D515B4C8
                                                                                                                                                                                                                                  SHA-256:BB246AABD501E14CED8B1FFC1369E3D5D26567AAE62B3EAD4D94C22FB77C3471
                                                                                                                                                                                                                                  SHA-512:BDBA4E1731CF254E95B0F1337410937C765E96FBB1D42F1D053033E1511FEE6F50C02705F781F4DAA0347E2299DC78A5A9942AC4EA343ED1F8F401F9ACD961E4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......hu....v.....q.t.b.a.s.e._.h.u.....q.t.s.c.r.i.p.t._.h.u.....q.t.m.u.l.t.i.m.e.d.i.a._.h.u... .q.t.x.m.l.p.a.t.t.e.r.n.s._.h.u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):153
                                                                                                                                                                                                                                  Entropy (8bit):3.5752972123113778
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/EbFlAlHeke5zOp1MUWLt7KlI+rwtbWlMj5FKIPldkOA9kk:CwDM+35aIUW5SIRt6Q50oi9Gk
                                                                                                                                                                                                                                  MD5:2BB8C94D420D3BC344C79A01043BDC89
                                                                                                                                                                                                                                  SHA1:3FBA773D58E6D3699C20AB41AEE6801E71E2DDAE
                                                                                                                                                                                                                                  SHA-256:9117AAC2D07BC86DFA55A29B8825ED27C7093300FCC90E143E135E00E85F09D7
                                                                                                                                                                                                                                  SHA-512:C6B13655AFB206B0056F5656B4A9BF33CC267FCC928F6973258131CFA6443970510226FE45A041E5AA988809E17D0B11C7458F4A241C71521EDED186596C6055
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......it....v.....q.t.b.a.s.e._.i.t.....q.t.s.c.r.i.p.t._.i.t.....q.t.m.u.l.t.i.m.e.d.i.a._.i.t... .q.t.x.m.l.p.a.t.t.e.r.n.s._.i.t.......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):146
                                                                                                                                                                                                                                  Entropy (8bit):3.599979504080125
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/il/lAlHekd6hY1MUV6JAlI+rwtbWlMgel3UlIPldkOG:Cwz4+pjUGAIRt6qVUloiB
                                                                                                                                                                                                                                  MD5:8A1EE3433304838CCD0EBE0A825E84D8
                                                                                                                                                                                                                                  SHA1:2B3476588350C5384E0F9A51FF2E3659E89B4846
                                                                                                                                                                                                                                  SHA-256:23457CE8E44E233C6F85D56A4EE6A2CECD87C9C7BDDE6D8B8A925902EED1CD9C
                                                                                                                                                                                                                                  SHA-512:2D8ACD668DF537E98B27161F9FA49828EB2EB6E9CF41DB38E7F5D31F610D150CD1B580A8AE9B472A4DFDE4D4BF983C24A56293BB911CF5879368664E4D4CF3D2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......ja....v.....q.t.b.a.s.e._.j.a.....q.t.s.c.r.i.p.t._.j.a.....q.t.m.u.l.t.i.m.e.d.i.a._.j.a... .q.t.x.m.l.p.a.t.t.e.r.n.s._.j.a
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):146
                                                                                                                                                                                                                                  Entropy (8bit):3.652277257665055
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/rrr/lAlHekcQ/01MUUQMlI+rwtbWlMhQGlIPldkORn:CwCC+1Q/UUpIRt6SBloimn
                                                                                                                                                                                                                                  MD5:7B2659AF52B824EAC6C169CDD9467EE9
                                                                                                                                                                                                                                  SHA1:5727109218B222E3B654A8CC9933E970EB7C2118
                                                                                                                                                                                                                                  SHA-256:4CC1AF37E771F0A43898849CFF2CD42A820451B8D2B2E88931031629D781DB05
                                                                                                                                                                                                                                  SHA-512:E9475AC80BDBBEFF54F2724A2B6BA76992F18FD1913FD8EE1540A99FD7A112B79FED5A130B6AC6D7460E4420C06354FC6E4CF7770A7C6CBD3EAC1BDAF0082DE5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......ko....v.....q.t.b.a.s.e._.k.o.....q.t.s.c.r.i.p.t._.k.o.....q.t.m.u.l.t.i.m.e.d.i.a._.k.o... .q.t.x.m.l.p.a.t.t.e.r.n.s._.k.o
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):165383
                                                                                                                                                                                                                                  Entropy (8bit):4.805977227348512
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:i5v3+zmayloj6yJjhnBAbnrKnGrhA7WgdXclIsooY9i:SvOzAloj6yJ9BA7riGr+7WKXc+s5ui
                                                                                                                                                                                                                                  MD5:8992B652D1499F5D2F12674F3F875A35
                                                                                                                                                                                                                                  SHA1:E22766A49612F79156C550D83C6C230345DDA433
                                                                                                                                                                                                                                  SHA-256:47EB5F97467DF769261421D54A5BEA1131C9FB9B6388791D38BB6574335B64BF
                                                                                                                                                                                                                                  SHA-512:9B8B6DBFF432F2A46C14BC183A6BAF84ACBF02BF2C5BB8C306C6538FBD9BE1C0A9015BD46728F2F652F9163AFC56B1E16D16EB95D8F7728F3C562AE9F4F1AE1E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......ltB..0X...*..)C...+...|......P....@..9....A..9....B..:....C..:....D..;....E..;....F..<6...G..<....H..=)...I..=....P..>q...Q..>....R..?....S..@f...T..@....U..A\...V..B....W..B....X..C....Y..Cy...]..k....t..........t>......th......t.......pd...;..J'...;.._h...;.......;...{...;..J....;...)...M..l....O...R...O...............}..l9...m..lo......^S..(5..P{..+;..4...+;......+;......+O..4...+O......1...^...E@..?p..F...C...H4......HY......H.......I...D...I@..s...IA..t...IC...2..J.......J....Y..J.......J.......K...9...LD...`..L.......PS......R.......T...q...Zr...`..[`......[`..&@..\....e..\....b.._......._....P..1........E..........5........L..1...O...1...PP......7......../...........$.......$.......,.......y.......y..........K^..............x......8................L...E.......E.......E..*....................%..:....%.........0U.....W......Zo.....^....5.......0..I....0...F...0...|...0.......0.......0..+\...5...}.......... D...g.. D......+....j..,.......,.......<U...+..<U
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):89
                                                                                                                                                                                                                                  Entropy (8bit):4.156834975253888
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/HzllldQlHekbxplUp1MUTJ+b:Cwv+DIUEb
                                                                                                                                                                                                                                  MD5:19F1B919BB531E9E12E7F707BEBD8497
                                                                                                                                                                                                                                  SHA1:46E82683CEA28D877C73A5CE02F965BB1130FC62
                                                                                                                                                                                                                                  SHA-256:03467738042A15676E504BA02CB326DCDB773B171FADA3CD62B7A0E0564314A0
                                                                                                                                                                                                                                  SHA-512:901D7B26CAC7A4D0FFDB39A1D25767B5BC71BED4AFBE788D70BF19D4C58A8295167111675AB45E743FDF4768AF874D69417414C01CF23D5C525A3F6C8BF7D21F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......lv....0.....q.t.b.a.s.e._.l.v.....q.t.s.c.r.i.p.t._.l.v........)....
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):161
                                                                                                                                                                                                                                  Entropy (8bit):3.8693516202048612
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/5J/p/lAlHekHp/7KlI+rwtbWlM6Tl/z21MUPp/FOlIPldkOjehB:Cwr+26IRt6nFURkloiT
                                                                                                                                                                                                                                  MD5:D71EA9FEFD97464B178235150EC8759E
                                                                                                                                                                                                                                  SHA1:61026FE602FD1B8B442A0D341C6BD759EEC75488
                                                                                                                                                                                                                                  SHA-256:BD7DD0C2CAB119A973DC10C3BFF7499D9728B928B541F86056921B30C8DB78E6
                                                                                                                                                                                                                                  SHA-512:ECD76A7D8B8D733E635B2BFEA90A4CD387B83D9D8A4EB6D299F59FF22AAA8D617A4C886A825A1CDDD901925C7839E2C18BDD4E0CD84152641922B66B62663F77
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......pl....v.....q.t.b.a.s.e._.p.l.....q.t.m.u.l.t.i.m.e.d.i.a._.p.l.....q.t.s.c.r.i.p.t._.p.l... .q.t.x.m.l.p.a.t.t.e.r.n.s._.p.l............,..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):70334
                                                                                                                                                                                                                                  Entropy (8bit):4.732724622610353
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:OKGUuWW+WHjS0gMBd483+Y7bDPs4RHBloLUIltlzAJnx4nnliM1OPlOibLG:JGUuWPuSgm0Jn+n4Mhj
                                                                                                                                                                                                                                  MD5:6656500F7A28EF820AE9F97FD47FB5BB
                                                                                                                                                                                                                                  SHA1:CC112B9C9513BCF7497F3417168B4C8A9F7640A9
                                                                                                                                                                                                                                  SHA-256:2C1E7BBF5168A64B43752DD4C547601C0BDE6D610F8671FA3E3AF38597E84783
                                                                                                                                                                                                                                  SHA-512:5C3CBFCF86AF6B4D949C1D914CD379E512E73BA350AF661033A386EE7FB981FBFCB43D9A35FDE7656E17BB09F64F1469F84867A780573C3359D645269461D5A6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......pt_PTB...(...*...9...+...e...]..6....;.......;..-....;..;`...;..};...;.......M..6....O... ...O...w...........}..7....m..7B..........+;......+;..8S..+;..>...+O......+O..8#..H4......H.......J......K.......LD...)..L....}..PS...l..Zr...B..[`...;..[`.....\...kU.._......._.......1...?...............8...............E............,..................p........0...............v...........%...O...%..G........4...0.......0..:....0..y....0..|....0.......0...X...5.......5...... D..=... D..Kn..+....L..,...>...,......<U..z...<U......<.......F...>...F.......H5...4..H5..=...H5..K...H5......f....p..f...1...f...;...f...I...f...|H..f.......f.......l....................b......<...............>.......L ...........`......`..._.......A......2....e...g...e..>D...e..LW................y...,.*.y.....*.y..o..*.y.....*.T..L..*.0..'..*.0....+F...y..+F......+f......+f...C..+.z..0..+.....d.+....p0.+.....R.+.z..0U.+.....u.+....8..+....Ct.+....L..+....y..+.....Z.+......+...pc.+.....+....0..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):164
                                                                                                                                                                                                                                  Entropy (8bit):3.984562388316898
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/oZlAlHekF8Op1MUNKJKlI+rwtbWlM4KKIPldkOSxRMugB:CwY+GIUgcIRt61oihM3
                                                                                                                                                                                                                                  MD5:F7A8C75408B9A34A2B185E76F51B7B85
                                                                                                                                                                                                                                  SHA1:065E987139C5FB809A6F9CDF3845BCD79707FDBB
                                                                                                                                                                                                                                  SHA-256:6492B267608C6FB76907BD8FCFC8F1EF57E9F4EBBC2E81ACA81715A88388F94A
                                                                                                                                                                                                                                  SHA-512:E768C5B438EC899801B22B1325F2244ACCC5E7C2EC5D270F510BC3CBC2D9A0536949C026DB7FB5862835E506A9F2020DEB2CC4001E7011FF974324542734F855
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......ru....v.....q.t.b.a.s.e._.r.u.....q.t.s.c.r.i.p.t._.r.u.....q.t.m.u.l.t.i.m.e.d.i.a._.r.u... .q.t.x.m.l.p.a.t.t.e.r.n.s._.r.u........)......,..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):157
                                                                                                                                                                                                                                  Entropy (8bit):3.7731953311404336
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/3xRlAlHekE8lgp1MUM8lMlI+rwtbWlM5UllyIPldkOfll6kchn:CwS0+t8CIUM86IRt6KUlsoi2CVh
                                                                                                                                                                                                                                  MD5:24C179481B5EF574F33E983A62A34D53
                                                                                                                                                                                                                                  SHA1:0A67F1ED8CA4A5182F504806F8D47D499789F2D2
                                                                                                                                                                                                                                  SHA-256:B6ADFFD889FF96BF195CB997327E7D7005A815CAD67823FA6915A19C2D9BB668
                                                                                                                                                                                                                                  SHA-512:4757F3693120DAB2FBB7BCF1734EA20B3E3D9056B4B4E934A3129D660CFDC6C58B230459DB55912AF24AD5692BD221830BE0FF91E41D3EECD9439E79AC23FFE6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......sk....v.....q.t.b.a.s.e._.s.k.....q.t.s.c.r.i.p.t._.s.k.....q.t.m.u.l.t.i.m.e.d.i.a._.s.k... .q.t.x.m.l.p.a.t.t.e.r.n.s._.s.k...........
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):228428
                                                                                                                                                                                                                                  Entropy (8bit):4.726953418955661
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:9zQH0hOtgmiAZu0eeAEv+v49JnnSmICgr3n7jhCQUeinqyU5UggtRLGrQ2LZO+Y1:RpUsSpGr36wsR
                                                                                                                                                                                                                                  MD5:D35A0FE35476BE8BD149CEE46E42B5E9
                                                                                                                                                                                                                                  SHA1:9F3C85C115A283E5230D1EEAD84C8CB73A71FA03
                                                                                                                                                                                                                                  SHA-256:C44E0313A9414CC0E490B65B0C036FA11BCA959353B228886547BC2C8492034F
                                                                                                                                                                                                                                  SHA-512:BEEB1751882AF081E80BE93F7464D4C6322B724EFA2CBD3E1CBE709181D380C1C57E770FA962BB706D6FCF4A8CB393E3F6E187C1F604F8CEEFB201CA3200BD1C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......slB..<....*.......+.......@...C...A.......B...<...C.......D...2...E.......F...d...G.......H...W...I.......P.......Q.......R.......S...x...T.......U...n...V...%...W.......X.......Y.......]..g~...t...V.......f..................................;..G....;..[....;...q...;..ia...;... ...M..g....O.......O.......[..,e...........}..g....m..h........Q..(5......+;..2...+;...b..+;...i..+O..2...+O...4..1......E@......F.......H4......HY...%..H.......I.......I@......IA...9..IC......J...6...J.......J.......J...^...K...7...LD......L....n..PS...U..R.......T....=..Zr......[`...V..[`......\...!,..\...8U.._..."b.._.../h..1.......E...9......4...............5........e...................$...<...$..Z....[.......,.......y...L...y..].......H.......@.......J.......6........~..........E...O...E..+....E...~..............,1...%..8r...%...........^..............................5.......0..Gx...0.......0..P....0..h....0.......0.......5...^.......... D...... D......+....`..,.......,...-...<U
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):65851
                                                                                                                                                                                                                                  Entropy (8bit):4.7906769989650515
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:4u6DkpgyKmRmG15mGM6iFPi6Q/qTlOQZY2dKN8gKw:4u6DotUG1sGMZPi6Q/qTlO2Y2YKw
                                                                                                                                                                                                                                  MD5:0E85E0E0E7DDFE3D4BDE302F27047F9C
                                                                                                                                                                                                                                  SHA1:AE59348E0C2E4F86F99DA6CF5DAB3B7E92504B7C
                                                                                                                                                                                                                                  SHA-256:4B4B6FF7FD237C9DA0301B4946132E68653D15EB5FAF38E4C5FBFEBB12DD97F7
                                                                                                                                                                                                                                  SHA-512:8CAAB6C61E9FA26A3A289A9E4DC515D157B3092D6D4ED43861220261BD2B7CC79B35B52F9ADE4EF558B5385B37EAC14575420DD55C475F435BB95B6C1E2561B6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`...B.......*.......+...i...]..6....;.......;..-f...;..:;...;..t....;.......M..64...O.......O...........q...}..6\...m..6........(..+;......+;..7...+;..=...+O......+O..7c..H4......H.......J.......K....F..LD...+..L.......PS...N..Zr......[`...7..[`...N..\...h4.._....J.._....k..1...>...............7........}......D............,...........*......i....................................%.......%..Fc.......6...0.......0..9....0..q....0..t....0.......0.......5.......5...... D..<}.. D..I...+.......,...=X..,.......<U..r...<U...n..<.......F...=...F....F..H5......H5..<...H5..J4..H5......f.......f...1V..f...:f..f...H;..f...t&..f.......f.......l..................8......;z..............<.......Je.......6...`...&...`...!.......9......1....e.......e..=....e..J..............g...y.....*.y.../.*.y..h..*.y.....*.T..J..*.0..'[.*.0...K.+F...q..+F.....+f......+f...A..+.z../..+.......+....i`.+.....X.+.z../..+.....S.+....7..+....Bi.+....K..+....q..+.......+......+...i..+.....+....0..F0i.....G.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):110
                                                                                                                                                                                                                                  Entropy (8bit):3.630483009136986
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/7zl9lAlHekDN/01MULV4LlI+rwtbWlM+N:Cw5+wUGRIRt6n
                                                                                                                                                                                                                                  MD5:16CDF5B9D48B0F795D532A0D07F5C3A0
                                                                                                                                                                                                                                  SHA1:6E403C9096B3051973E2B681DFEBBC8DD024830D
                                                                                                                                                                                                                                  SHA-256:F574A2CFD4715885C3DBDF5AE60995252673BD94FDAA9586F7E0586F6C1AC0EE
                                                                                                                                                                                                                                  SHA-512:36A0431368010157EA8A45DCB00458076CCFFC08B37E443DEBD1AAD4A30C6080803337725A7A3DCBF2B410DC7BE89CEAF6C07C46F876E4EF5B08159E3BF38E6D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......tr....R.....q.t.b.a.s.e._.t.r.....q.t.s.c.r.i.p.t._.t.r.....q.t.m.u.l.t.i.m.e.d.i.a._.t.r
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):164
                                                                                                                                                                                                                                  Entropy (8bit):4.021402900389864
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/ZlRlAlHekCczOp1MUKUt7KlI+rwtbWlM/cFKIPldkONRMugB:CwUl0+rjIUKUcIRt6M/oioM3
                                                                                                                                                                                                                                  MD5:9B101363343847FE42167183320C03F0
                                                                                                                                                                                                                                  SHA1:F0DF2CFF913E588B7CADFDABBF69F4F632B2F96A
                                                                                                                                                                                                                                  SHA-256:F1621E680E1642F9463E4B07E7E78B50F9A7BDB7C321D7302039CB3405CBDEA4
                                                                                                                                                                                                                                  SHA-512:DA14FDF8DB514902733CAAC492293873351C595EBBE0ACB0849BECE24AB822602EE64D01051F1426CD1FC13A95D8607302CF9B515D9806FDD3BD047087DE447C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......uk....v.....q.t.b.a.s.e._.u.k.....q.t.s.c.r.i.p.t._.u.k.....q.t.m.u.l.t.i.m.e.d.i.a._.u.k... .q.t.x.m.l.p.a.t.t.e.r.n.s._.u.k........)......,..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):117347
                                                                                                                                                                                                                                  Entropy (8bit):5.8593733369029195
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:51dXW89nqEFu54aekvRzHHSVuf8j2+/xc3lhnbsfdAoz/w:v9qEFeLekvRznSVHJG3lhn+djY
                                                                                                                                                                                                                                  MD5:0D02F0DE5A12BCB338B7042DFBDAACF3
                                                                                                                                                                                                                                  SHA1:B7C10D249D8986AD8C6939B370407D07227A39F5
                                                                                                                                                                                                                                  SHA-256:28CDE75D7B32C81FEF1D4630C37B79A61DEC24B357632FF00D6365A57D8BE43B
                                                                                                                                                                                                                                  SHA-512:21F02EBA36B4411921EA3C70310B8E454E8FC2B8F09957FD6A63B71689DC381F7A5E2C3BDF2810734D659AB43D8A7BD46EF6436ECC52F75C71B5F5C313365444
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......zhB..+....*.......+.......@.......A...8...B.......C.......D.......E...V...F.......G...L...H.......I...9...P.......Q...e...R...^...S.......T...T...U.......V...|...W.......X...o...Y.......]..4 ...;...2...;..,....;..8....;.......;.......M..4H...O.......O...........#...}..4p...m..4........N..(5......+;...f..+;..6Y..+;..<...+O...8..+O..6'..1......E@......F....Y..H4..."..HY..J...H.......I.......J.......J.......K....5..LD..._..L......PS...V..Q....6..R...N...W..../..Zr.....[`.....[`......\...lU.._......._....L..1...<........j......6...............B........I...$..K....$.......,...g...y...3.......A......r...........................9..L7......;w...E..5b...E...G.......5...%.......%..D........`......*........................0.......0..8W...0..}y...0...6...0.......0.......5.......5...... D..:... D..J...+....R..,...;...,......<U..~...<U......<......F...;...F......H5...i..H5..:...H5..Jk..H5...w..VE...[..f....u..f...0X..f...9...f...E...f.......f.......f....j..g....A..l.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):141
                                                                                                                                                                                                                                  Entropy (8bit):3.7198292994386235
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4C/0N6xg/Rl/gl+kNXDelHrwtbWlMwTolIPldkOfDn:CwOO2+g6Mt63oloiUn
                                                                                                                                                                                                                                  MD5:ED4135D705AEF3D97F8BF6B8FF11F09C
                                                                                                                                                                                                                                  SHA1:308E2B8F74B863A61AD0B68F4A18ED06965EBEAA
                                                                                                                                                                                                                                  SHA-256:751ECDA0C33E061D91241268357FBD2F6B7F70A1116E714F28D22EFD61EC7A1A
                                                                                                                                                                                                                                  SHA-512:B6E6D00553A9C427130129B9D30E862028E549F372A832F0F05747C8E2A79E443F4932EC3AE177537C8BA00D26B5B6CB97D5B35426AB5229F6A468CA485BE0B1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......zh_TW....n.....q.t.b.a.s.e._.z.h._.T.W...$.q.t.m.u.l.t.i.m.e.d.i.a._.z.h._.T.W...&.q.t.x.m.l.p.a.t.t.e.r.n.s._.z.h._.T.W
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):160017
                                                                                                                                                                                                                                  Entropy (8bit):5.35627970915292
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:XGlAMfkX1M0RdaCkR8lfv8vtc8EFrVYA2I4AJZWEWgHg1C8COvzHKHC6Jp9NV0V7:XUr0RACkIwDEpV1Lgf1ubtw3Bb
                                                                                                                                                                                                                                  MD5:A7E4D0BA0FC5DF07F62CC66EC9878979
                                                                                                                                                                                                                                  SHA1:21FD131B23BDD1BBA7BBB86F3ED5C83876F45638
                                                                                                                                                                                                                                  SHA-256:E03FE68D83201543698FD7FE267DD5DFC5BFD195147E74FF2F19AC3491401263
                                                                                                                                                                                                                                  SHA-512:D9E6B10506FCF20B5B783F011908083D9DF6C5DF88E21B10D07F53A01AD6506A4B921C85335A25BAE54E27BAD7D01B6E240D58FDEEAABC7FF32014EC120C2ECF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......arB..2....*.......+.......@.......A.......B..._...C......D.......E......F.......G... ...H...D...I...h...P...C...Q...g...R......S.......T.......U.......V...x...W......X.......Y.......]..'=...s......t...........]...........;..'....;..(....;.......;.......M..'e...O.......O...9...........}..'........C...=......m..'....t..........!o..(5...Z..+;..5u..+;..c...+O......1...!...D@...8..E@.....H4...,..HY..QI..H.......IC......J....1..J.......J.......LD......L.......PS......QR...R..R...V2..T.......U....]..X.......Zr.....[`......\....t..]x......_......._.......yg......1...6....E..8V..............C............................$..RN...[...0...,.......y.......y...................K...........9..R....E.."............z.......................%..F;...D...[..................................!....5.......0...I...0.......0...5...0..#....5.......5...p..............W}.. D..(... D..P=..+.......<U......<U......<.......H5..(...H5..P...L.......VE......VE......V....B..f...JJ..f.......f.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):165337
                                                                                                                                                                                                                                  Entropy (8bit):5.332219158085151
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:9ULiyUxPoT6qx+J7FJlaaMJnxjqxq+0Uiff0mbVeb7wiEwYuYqDKBkKHMXHCIMll:9ULpIVFnpwUiEujw27ncUQUz
                                                                                                                                                                                                                                  MD5:660413AD666A6B31A1ACF8F216781D6E
                                                                                                                                                                                                                                  SHA1:654409CDF3F551555957D3DBCF8D6A0D8F03A6C5
                                                                                                                                                                                                                                  SHA-256:E448AC9E3F16C29EB27AF3012EFE21052DAA78FABFB34CD6DFF2F69EE3BD3CDB
                                                                                                                                                                                                                                  SHA-512:C6AE4B784C3D302D7EC6B9CE7B27DDAF00713ADF233F1246CD0475697A59C84D6A86BAA1005283B1F89FCC0835FD131E5CF07B3534B66A0A0AA6AC6356006B8F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......bg_BGB../....*..,....+..."...@...]...A.......B.......C.......D...P...E...!...F.......G.......H.......I.......P.......Q.......R...A...S...e...T.......U.......V.......W...1...X...U...Y...y...]..,....s...,...t...................P...;..+....;..-E...;..!....;..+....M..,Y...O...,...O...........*...}..,............=...Q...m..,....t...|......>...(5..1...+;..<...+;..o...+O...r..1...>...D@......E@......H4......HY..[...H.......IC......J....E..J....X..J.......LD......L....L..PS......QR.."...R...`...T....X..U.......X.......Zr...q..[`...`..\.......]x......_......._....T..yg.....1...=....E..?...............L(.......(...............'...$..\....[.......,...I...y...!...y...................S...........9..]%...E..5p...........z..!q...................%..O....D..................D.....8......:......?....5...&...0.......0.. ....0...c...0..5....5.......5..................b:.. D..-... D..Z...+.......<U......<U...0..<.......H5..-...H5..[...L.......VE..#a..VE..;...V.......f...T...f...!..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):210159
                                                                                                                                                                                                                                  Entropy (8bit):4.666388181115542
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:P/DVhdlafzvZfeW+6kXEVjSVPzC3ceKdP2:xYf7UW+WjwP2
                                                                                                                                                                                                                                  MD5:B383F6D4B9EEA51C065E73ECB95BBD23
                                                                                                                                                                                                                                  SHA1:DD6C2C4B4888B0D14CEBFC86F471D0FC9B07FE42
                                                                                                                                                                                                                                  SHA-256:52E94FCC9490889B55812C5433D009B44BDC2DC3170EB55B1AF444EF4AAE1D7F
                                                                                                                                                                                                                                  SHA-512:9401940A170E22CE6515E3C1453C563D93869A3C3686C859491A1F8795520B61BF3F0BFE4687A7380C0CC0C75E25559354FDB5CEF916AF4C5B6CD9661464A54A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......caB..7....*.......+.../...@..:P...A..:t...B..:....C..:....D..;=...E..<....F..<Z...G..<~...H..<....I..<....P..>....Q..>....R..?....S..?R...T..?v...U..?....V..?....W..@....X..@<...Y..@`...]../....s..1....t..........2s......#p...;.......;../....;..W....;..e+...M../3...O.......O..9.......J....}../]......8....=..9....m../....t..9Y.......S..(5..lB..+;.._...+;...=..+O..U...1.......D@..:...E@..?...H4...J..HY..~...H..."...IC...0..J....W..J....0..J.......LD..!...L...!f..PS..)...QR.."...R.......T...9~..U...9...U...z...X...>...Zr..E...[`...e..\...LD..]x..7U.._......._...M...yg..f...1...a....E..c....7.........U.......p........b.......4.......K...$.......[.......,.......y.......y...................^...........9...:...E...s...... (...z..":.......d......!....%..tQ...D.."......."......2......ve.....y...........5..#H...0...\...0..W+...0..';...0.......5..(....5..........)s.......... D..0w.. D..}...+...1...<?..5x..<U......<U..5...<...6@..H5..0...H5..~...L...9...VE..$...V...SV..f.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174701
                                                                                                                                                                                                                                  Entropy (8bit):4.87192387061682
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:5WjuhX0CVRaakGjW9E8SSOQfX/JlwVOMxrboRPqWxXfQvO7zjBf:5iFGj1QfXr8Gd
                                                                                                                                                                                                                                  MD5:C57D0DE9D8458A5BEB2114E47B0FDE47
                                                                                                                                                                                                                                  SHA1:3A0E777539C51BB65EE76B8E1D8DCE4386CBC886
                                                                                                                                                                                                                                  SHA-256:03028B42DF5479270371E4C3BDC7DF2F56CBBE6DDA956A2864AC6F6415861FE8
                                                                                                                                                                                                                                  SHA-512:F7970C132064407752C3D42705376FE04FACAFD2CFE1021E615182555F7BA82E7970EDF5D14359F9D5CA69D4D570AA9DDC46D48CE787CFF13D305341A3E4AF79
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......cs_CZB..3p...*..F....+.......@..!....@..Ef...A..!....A..E....B.."1...B..E....C.."U...C..E....D.."....D..F....E..#p...E..F)...F..#....F..FP...G..#....G..Fw...H..$....H..F....I..$6...I..F....P..&%...P..Gr...Q..&I...Q..G....R..&....R..G....S..&....S..H....T..&....T..H8...U..'....U..H_...V..'Z...V..H....W..'~...W..H....X..'....X..H....Y..'....Y..H....]..,....]..,....s.......t...9...............*...;.......;..+....;..1B...;......;..?x...;..N....;..iY...;..s3...M..,B...M..,....O.......O...w...O..rr...........}..,j...}..-....... 5...=.. ....m..,....m..-8...t.. .......ay..(5..TT..+;...A..+;..B...+;..u...+O......+O..=a..1...a...D@.."...E@..&m..E@..G...F...J...H4...=..HY..`...H.......I...J...IC......J....-..J.......J.......LD......L....(..PS.....QR.."S..R...e...T.... ..U......X.......Zr...g..[`......\......]x......_......._......._...v...yg......1...C....E..E...............=.......Q........................s...$..a....[.......,.......y.......y...y..............G..........
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181387
                                                                                                                                                                                                                                  Entropy (8bit):4.755193800761075
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:XzswP2UvZ5aZ9jFTkmq/gnBNW/+PcWrqm2Vliz0DGdaS4KSLZjwTTgwUR0toT:j3m27AjCT
                                                                                                                                                                                                                                  MD5:859CE522A233AF31ED8D32822DA7755B
                                                                                                                                                                                                                                  SHA1:70B19B2A6914DA7D629F577F8987553713CD5D3F
                                                                                                                                                                                                                                  SHA-256:7D1E5CA3310B54D104C19BF2ABD402B38E584E87039A70E153C4A9AF74B25C22
                                                                                                                                                                                                                                  SHA-512:F9FAA5A19C2FD99CCD03151B7BE5DDA613E9C69678C028CDF678ADB176C23C7DE9EB846CF915BC3CC67ABD5D62D9CD483A5F47A57D5E6BB2F2053563D62E1EF5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......daB..4....*..h....+......@...f...A.......B.......C.......D...U...E.......F...v...G.......H.......I.......P.......Q.......R...6...S...Z...T...~...U.......V.......W..."...X...F...Y...j...]..+....s.......t..................-...;..+....;..,....;../....;..;....M..+....O.......O...r...........}..,............=...8...m..,0...t...c......T...(5..B...+;..NH..+;..~H..+O..,...1...UP..D@......E@......H4...E..HY..j...H.......IC...#..J....J..J.......J.......LD......L....1..PS...B..QR......R...o...T.......U.......X.......Zr......[`...W..\....}..]x...[.._....-.._.......yg...e..1...O....E..R....7..........-!......]............................$..k....[...7...,.......y...c...y.................j4...........9..l8...E..p............z...;..................%..a....D...~.............-.....L......OH.....Uz...5.......0.......0...U...0.......0..p....5...7...5..L$..............p... D..-... D..i...+....@..<U.....<U.....<....S..H5..-2..H5..j$..L....B..VE.. ...VE..P...V...*...f...e...f.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):220467
                                                                                                                                                                                                                                  Entropy (8bit):4.626295310482312
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:7w8go8+ph6JVB8XVXYWpSNEeg8+vaD+p4N8DDiEKugwGZulh15ce4M+4NsPYXCZW:88h8Sj286tTiDD
                                                                                                                                                                                                                                  MD5:40760A3456C9C8ABE6EA90336AF5DA01
                                                                                                                                                                                                                                  SHA1:B249AA1CBF8C2636CE57EB4932D53492E4CE36AC
                                                                                                                                                                                                                                  SHA-256:553C046835DB9ADEF15954FA9A576625366BA8BFD16637038C4BCD28E5EBACE1
                                                                                                                                                                                                                                  SHA-512:068E55F39B5250CC937E4B2BD627873132D201D351B9351BE703CD9B95D3BAFB4BD649CB4DF120A976D7C156DA679758D952CAC5E0523107244E517D323BC0C5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......de_DEB..7....*.......+..3....@..R....A..R....B..S....C..S@...D..S....E..T]...F..T....G..T....H..T....I..U#...P..W....Q..W6...R..W....S..W....T..W....U..W....V..XG...W..Xk...X..X....Y..X....]..2%...s..J$...t..9R......J.......B....;..1....;..3....;..q....;.......M..2O...O.......O..X@......ia...}..2y......Q....=..Q....m..2....t..Q...........(5......+;..ev..+;......+O..oh..1....4..D@..R...E@..WZ..H4..4...HY...[..H...AY..IC..>o..J...>...J.......J...>6..LD..@A..L...@...PS..I...QR..#...R....h..T...W...U...Xh..U....~..X...]...Zr..e(..[`..)...\...j...]x..O..._....K.._...lI..yg...U..1...f....E..i....7..........o.......wG......6.......6.......8....$...n...[..8....,..9....y.......y..=................3......>....9.......E..."......?_...z..#d.......0......A%...%..z....D..A.......B......KP......2.............^...5..B....0.......0..p....0..F....0...}...5..G....5..........H........... D..3}.. D...O..+...Q...<?..Ti..<U......<U..T...<...U)..H5..3...H5......L...X...VE..%j..V...l..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):16
                                                                                                                                                                                                                                  Entropy (8bit):4.0
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:j2wZC4n:CwZ
                                                                                                                                                                                                                                  MD5:BCEBCF42735C6849BDECBB77451021DD
                                                                                                                                                                                                                                  SHA1:4884FD9AF6890647B7AF1AEFA57F38CCA49AD899
                                                                                                                                                                                                                                  SHA-256:9959B510B15D18937848AD13007E30459D2E993C67E564BADBFC18F935695C85
                                                                                                                                                                                                                                  SHA-512:F951B511FFB1A6B94B1BCAE9DF26B41B2FF829560583D7C83E70279D1B5304BDE299B3679D863CAD6BB79D0BEDA524FC195B7F054ECF11D2090037526B451B78
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`...
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):165170
                                                                                                                                                                                                                                  Entropy (8bit):4.679910767547088
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:JVwzuvb+Ta64KQd84arHX5pxiVhA8QlOD/BnFNa8NsvsfFsfcoZtIx6F:JVwSTG4KqVaLX5pEVK7OJFczstgRtIx8
                                                                                                                                                                                                                                  MD5:C7C58A6D683797BFDD3EF676A37E2A40
                                                                                                                                                                                                                                  SHA1:809E580CDBF2FFDA10C77F8BE9BAC081978C102B
                                                                                                                                                                                                                                  SHA-256:4FFDA56BA3BB5414AB0482D1DDE64A6F226E3488F6B7F3F11A150E01F53FA4C8
                                                                                                                                                                                                                                  SHA-512:C5AED1A1AA13B8E794C83739B7FDDEAFD96785655C287993469F39607C8B9B0D2D8D222ECD1C13CF8445E623B195192F64DE373A8FB6FE43743BAF50E153CDA5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......es_ESB../....*..*,...+...y...@.......A.......B.......C.......D...v...E...=...F.......G.......H.......I.......P.......Q... ...R...k...S.......T.......U.......V...1...W...U...X...y...Y.......]..+....s.......t...................c...;..+....;..,....;...%...;..#....;..-....M..+....O.......O...............}..,............=...]...m..,/...t..........A...(5..3...+;..<...+;..o...+O..!b..1...Ap..D@......E@...D..H4...-..HY..[F..H.......IC...%..J....L..J.......J.......LD......L....O..PS......QR..!...R...`K..T.......U....&..X.......Zr.....[`...h..\......]x...|.._....Y.._....A..yg......1...=....E..?a......!.......K........G...............R...$..\Q...[.......,...z...y.......y..................+............9..\....E..2............z.. ....................%..ON...D........................:......=B.....A....5...7...0.......0......0.."....0...,...0..3....5...}...5...Y..............a... D..-!.. D..Z6..+....0..<U...h..<U......<.......H5..-M..H5..Z...L.......VE.."...VE..>...V......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179941
                                                                                                                                                                                                                                  Entropy (8bit):4.720938209922096
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:lvdTgO2Yl97ZWnbgTLt/Tf9IlqAeiy5uWkYGM0wNCdRjSK2YUlUs:lvdkA9vh5uWkY0MK2YXs
                                                                                                                                                                                                                                  MD5:8472CF0BF6C659177AD45AA9E3A3247C
                                                                                                                                                                                                                                  SHA1:7B5313CDA126BB7863001499FB66FB1B56C255FC
                                                                                                                                                                                                                                  SHA-256:E47FE13713E184D07FA4495DDE0C589B0E8F562E91574A3558A9363443A4FA72
                                                                                                                                                                                                                                  SHA-512:DE36A1F033BD7A4D6475681EDC93CC7B0B5DCB6A7051831F2EE6F397C971B843E1C10B66C4FB2EFF2A23DC07433E80FBF7B95E62C5B93E121AB5AD88354D9CB8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......fiB..38...*..ct...+......@.......A.......B.......C...@...D.......E...]...F.......G.......H.......I...#...P.......Q...6...R.......S.......T.......U.......V...G...W...k...X.......Y.......]..*....s...T...t.......................;..*....;..+....;..&....;..3....M..+!...O.......O...e...........}..+K...........=.......m..+w...t..........J...(5..9...+;..:y..+;..mW..+O..$...1...KY..D@......E@...Z..H4...l..HY..X&..H.......IC......J.......J...."..J......LD.....L.......PS...'..QR.. L..R...]...T.......U.......X.......Zr......[`......\.......]x......_....k.._....>..yg.. /..1...;....E..>....7..{(......%.......J........T.......&.......U...$..Y[...[......,...s...y.......y...a.......}......d...........9..Y....E..k'...........z...........V..........%..M....D...Q.......{......d.....A......E......K....5.......0.......0..&J...0.......0..k....5...*...5..I9.............._:.. D..,O.. D..W...+....9..<U...G..<U...*..<.......H5..,y..H5..W...H5......L....5..VE..!u..VE..E...V..."{..f.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):166167
                                                                                                                                                                                                                                  Entropy (8bit):4.685212271435657
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:CLZ1w8McowCppcPwL5pYFw+G00QsbLckCiWxvq+sjs06oFm:C91wxcowspc4L5pUw+cz39CiQ7tloFm
                                                                                                                                                                                                                                  MD5:1F41FF5D3A781908A481C07B35998729
                                                                                                                                                                                                                                  SHA1:ECF3B3156FFE14569ECDF805CF3BE12F29681261
                                                                                                                                                                                                                                  SHA-256:EDB32A933CEF376A2636634E14E2977CED6284E4AA9A4AC7E2292F9CA54C384A
                                                                                                                                                                                                                                  SHA-512:A492E8AC88095A38A13549C18C68E1F61C7054AB9362C2B04C65B93E48E4A07941C8DA6950BAE79041094623E0ED330CA975110FDE8248B4D9380B9F729AD891
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......fr_FRB../....*..-....+.......@.......A.......B.......C...?...D.......E...\...F.......G.......H.......I..."...P.......Q...5...R.......S.......T.......U.......V...F...W...j...X.......Y.......]..+....s...=...t.......................;..+....;..,....;.......;..$b...;.......M..,....O.......O...5...........}..,3...........=.......m..,]...t..........A...(5..5j..+;..<T..+;..o...+O.."+..1...B\..D@......E@...Y..H4...8..HY..[{..H.......IC......J.......J.......J.......LD...|..L.......PS...?..QR..!...R...`j..T.......U....[..X.......Zr.....[`...)..\......]x......_....7.._.......yg...i..1...=Q...E..?@......"Y......K............................$..\....[...^...,...'...y.......y...+.......o....../c.......Y...9..\....E..6(...........z..!................j...%..OC...D...+.......[......a.....;......>......B....5.......0.......0...m...0..#....0.......0..6....5.......5..................a... D..-Y.. D..Ze..+....]..<U...;..<U......<.......H5..-...H5..Z...L.......VE.."...VE..?...V......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):189580
                                                                                                                                                                                                                                  Entropy (8bit):4.630160941635514
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:SiaI3C87jhakhR0VGkw7ys7CskUH6y4e6IFB4xyMuhvDnJGhFaCo527arBbm07LZ:S2yGjh17yGqxTXhvQoejJd8FUjVgk
                                                                                                                                                                                                                                  MD5:EB1FB93B0BE51C2AD78FC7BA2F8B9F42
                                                                                                                                                                                                                                  SHA1:24F7FF809E2F11C579CD388FEA5A4C552FF8D4D0
                                                                                                                                                                                                                                  SHA-256:63B439DD44139AA3AED54C2EBE03FA9BC77F22C14ED8FBA8EFF2608445BB233D
                                                                                                                                                                                                                                  SHA-512:E13770AEF33B6666ED7D54E03EE20CA291D4167D673BA6C61D8E64CDD5F7FFE0A9521B95AF67BE719BF263932ECF16E2B2D0B5F3404F9BCD7879114FCC6FC474
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......gd_GBB..2....*...u...+......@.......A...B...B.......C.......D.. ....E.. ....F..!&...G..!J...H..!n...I..!....P..#m...Q..#....R..#....S..$....T..$$...U..$H...V..$....W..$....X..$....Y..%....]../....s...'...t...................F...;.......;../....;..=V...;..G....M../G...O.......O...k......$....}../o.......i...=.......m../....t..........[...(5..M...+;..@...+;..x...+O..:...1...\7..D@...f..E@..#...H4...p..HY..be..H.......IC......J.......J....R..J.......LD......L.......PS......QR..#l..R...g...T.......U.......X....\..Zr......[`......\...&...]x......_....C.._...'t..yg..?...1...BM...E..D.......;.......R'.......t.......@.......?...$..c....[......,...i...y.......y...Y.......f.......+...........9..c....E...............z.."....................%..U....D..................G.....UB.....W......\]...5.......0.......0..<....0...;...0.......5.......5..ij..............h... D..0... D..aC..+....K..<U.....<U...~..<.......H5..0...H5..a...L....1..VE..$...VE..X...V...8|..f...Z...f...=..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):138690
                                                                                                                                                                                                                                  Entropy (8bit):5.515748942553918
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:XSue8Z7T3iJsqBejt/zNHSLzdetY2ZISfC/S:XSueK3w7Ijt8zUtYAISfC/S
                                                                                                                                                                                                                                  MD5:DEAF87D45EE87794AB2DC821F250A87A
                                                                                                                                                                                                                                  SHA1:DB39C6BAA443AA9BB208043EF7FB7E3403C12D90
                                                                                                                                                                                                                                  SHA-256:E1EBCA16AFE8994356F81CA007FBDB9DDF865842010FE908923D873B687CAD3F
                                                                                                                                                                                                                                  SHA-512:276FCE81249EFFE19E95607C39F9ACB3A4AFA3F90745DA21B737A03FEA956B079BCA958039978223FD03F75AC270EC16E46095D0C6DDA327366C948EC2D05B9C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......he_ILB../....*......+..Sw...@......A......B.......C.......D...X...E.......F.../...G...O...H...o...I......P.......Q.......R...I...S...i...T......U......V.......W.......X.../...Y...O...]..$....s......t..X:.......4......`Y...;..$....;..%....;.......;...5...;.......M..$....O...6...O..s............}..%-...........=...m...m..%k...t..........^..(5......+;..2...+;..^...+O...N..1.......D@......E@...(..H4..T...HY..L...H..._...IC..\...J...\...J.......J...\j..LD..^...L...^o..PS..fl..QR......R...Q...T...su..U...s...X...x3..Zr..~...[`..L\..\.......]x....._......._....o..yg...(..1...3....E..5C.......z......?V......U.......U.......W....$..M....[..W....,..X....y.......y..\........a..............\@...9..NO...E...?......]s...z...G.......(......^....%..B^...D.._......._.................... ..........5..`/...0.......0...L...0......0..d(...0......5..ek...5..........fB......R... D..&O.. D..K...+...l...<U......<U..p)..<...p...H5..&w..H5..La..L...s...VE......VE......V.....
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):160494
                                                                                                                                                                                                                                  Entropy (8bit):4.831791320613137
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:BmOMZadV9n51xXeQvjOiIzz7/Vs9Db3ihuJNvMfWxBNlYzYbTrIkfwb03l24cNKu:HkWa5pg0MahBHDd
                                                                                                                                                                                                                                  MD5:E9D302A698B9272BDA41D6DE1D8313FB
                                                                                                                                                                                                                                  SHA1:BBF35C04177CF290B43F7D2533BE44A15D929D02
                                                                                                                                                                                                                                  SHA-256:C61B67BB9D1E84F0AB0792B6518FE055414A68E44D0C7BC7C862773800FA8299
                                                                                                                                                                                                                                  SHA-512:12947B306874CF93ABA64BB46FAC48179C2D055E770D41AF32E50FFFB9F0C092F583AFCEA8B53FE9E238EF9370E9FFFBEB581270DFA1A7CB74EBE54D9BFF459F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......hu_HUB../....*.......+.......@.......A...0...B...{...C.......D.......E.......F.......G...<...H...`...I.......P...s...Q.......R.......S.......T...*...U...N...V.......W.......X.......Y.......]..+y...s.......t.......................;..+Q...;..,U...;.......;.......;..&....M..+....O.......O...U..........}..+............=.......m..+....t..........9c..(5..,...+;..;...+;..m7..+O......1...9...D@...T..E@......H4...v..HY..Y...H.......IC......J.......J.......J.......LD......L.......PS...}..QR..!...R...]...T.......U....{..X.......Zr...=..[`......\....*..]x...-.._......._......yg...M..1...<....E..>...............J........T.......(.......S...$..Z....[.......,...u...y.......y...[...............#...........9..Z....E..#&...........z..!'...................%..Mv...D..._....................32.....5......9....5.......0...h...0...E...0.......0.......0..#....5...Z...5...........G......_2.. D..,... D..W...+....W..<U......<U...B..<.......H5..,...H5..X{..L....)..VE.."...VE..6l..V....*.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):161172
                                                                                                                                                                                                                                  Entropy (8bit):4.680034416311688
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:eSfxfdO4BKJb0td5pqCOIUP/PFIM7gxGQ9sRrFM6QJ4m8ihkM:eSfxFO4BKJb0td5pnOrvCqg9mRK4IkM
                                                                                                                                                                                                                                  MD5:88D040696DE3D068F91E0BF000A9EC3E
                                                                                                                                                                                                                                  SHA1:F978B265E50D14FDDE9693EC96E99B636997B74D
                                                                                                                                                                                                                                  SHA-256:7C7DC8B45BF4E41FEC60021AB13D9C7655BE007B8123DB8D7537A119EB64A366
                                                                                                                                                                                                                                  SHA-512:F042637B61C49C91043D73B113545C383BD8D9766FD4ACC21675B4FF727652D50863E72EA811553CB26DF689F692530184A6CE8FE71F9250B5A55662AFE7D923
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......it_ITB../....*.......+.......@.......A..."...B...m...C.......D.......E.......F.......G...0...H...T...I...x...P...q...Q.......R.......S.......T...(...U...L...V.......W.......X.......Y.......]..+....s...'...t...................^...;..+[...;..,g...;.......;.......;..!B...M..+....O...D...O...........(...}..+........I...=.......m..,....t..........4...(5..'...+;..<...+;..oV..+O......1...5...D@...F..E@......H4...J..HY..Z...H.......IC...L..J....s..J....j..J.......LD......L....f..PS......QR..!...R..._...T.......U....3..X.......Zr......[`...Q..\.......]x......_......._....0..yg...C..1...=....E..?o..............Kf.......h.......8.......I...$..[....[.......,...m...y...9...y...........z.......z...........9..\=...E..$u.......:...z.. k...................%..N....D..................M............0......5/...5...2...0.......0...0...0...A...0...)...0..$....5.......5...J.......a......a... D..,... D..Y...+.......<U......<U......<....v..H5..-...H5..Z...L.......VE.."c..VE..1...V....X.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):129911
                                                                                                                                                                                                                                  Entropy (8bit):5.802855391832282
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:W8YYSCjKBJ26c1Z7f25pVmuLXpxfqt7FEUWNrfQje9kWI23pKXvx:xYuKBJ01Z7u5pQuLbESUWNzAAI23pKfx
                                                                                                                                                                                                                                  MD5:608B80932119D86503CDDCB1CA7F98BA
                                                                                                                                                                                                                                  SHA1:7F440399ABA23120F40F6F4FCAE966D621A1CC67
                                                                                                                                                                                                                                  SHA-256:CBA382ACC44D3680D400F2C625DE93D0C4BD72A90102769EDFD1FE91CB9B617B
                                                                                                                                                                                                                                  SHA-512:424618011A7C06748AADFC2295109D2D916289C81B01C669DA4991499B207B781604A03259C546739A3A6CF2F8F6DFA753B23406B2E2812F5407AEE343B5CBDD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......jaB../....*...'...+..=....@.......A.......B...?...C...c...D......E......F.......G.......H..."...I...F...P.......Q...'...R...r...S......T......U.......V...8...W...\...X......Y......].."k...s...Q...t..A...............I....;.."C...;..#A...;.......;.......;.......M.."....O...B...O..[?......h....}.."........m...=.......m.."....t...........M..(5......+;......+;..WU..+O......1.......D@......E@...K..H4..>=..HY..F...H...Hr..IC..E...J...F...J.......J...E...LD..Gz..L...G...PS..O...QR......R...K!..T...Z...U...[e..X..._f..Zr..e...[`..7...\...i...]x...'.._......._...j...yg..~+..1.../....E..1?.......#......:.......?.......?n......A....$..G....[..Ap...,..B....y.......y..Ew......|...............E....9..H....E..........F....z...]..............HL...%..=R...D..H.......I!......[......J......M..........5..It...0...3...0.......0...C...0..M....0...a...5..N....5..........N.......L6.. D..#... D..E...+...U%..<U......<U..X ..<...X...H5..#...H5..FK..L...[...VE......VE......V......f.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):156799
                                                                                                                                                                                                                                  Entropy (8bit):5.859529082176036
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:rvTy18hhPekHs1iNXVExWbStnn8TExgkYOvYejZOvXx4Mmf0MwUL8smk/pDZyy:y18hJ61nMStnn8TOgknQRLWZmkxNyy
                                                                                                                                                                                                                                  MD5:082E361CBAC2E3A0849F87B76EF6E121
                                                                                                                                                                                                                                  SHA1:F10E882762DCD2E60041BDD6CC57598FC3DF4343
                                                                                                                                                                                                                                  SHA-256:0179ED1B136E1CB3F583351EAA2C545BA3D83A6EE3F82C32505926A1A5F5F183
                                                                                                                                                                                                                                  SHA-512:F378A42116924E30FA0B8FFF1D3C3CB185DC35B2746DCE2818BE7C2AA95C5DE103DF44AAC74DA969C36C557F1D4DE42AC7647EC41066247F8AD2697BDED667EA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......koB..7....*.......+.......@...K...A...o...B......C.......D...8...E.......F...U...G...y...H......I.......P......Q.......R.......S...C...T...g...U.......V.......W.......X...-...Y...Q...]..$....s...>...t...................y...;..${...;..%....;...u...;...l...M..$....O.......O...8...........}..$............=...C...m..%!...t...n..........(5...a..+;..E@..+;..l|..+O......1.......D@.....E@......H4......HY..\...H....]..IC......J.......J....8..J.......LD...a..L.......PS......QR......R...`...T.......U....^..U.......X....y..Zr......[`..y...\....A..]x......_......._....o..yg......1...FJ...E..HE...7..................Q........a.......5...........$..]....[...;...,.......y.......y...V...............!.......|...9..]....E...R...........z...4.......f.......5...%..Te...D..................D......^.............*...5...S...0.......0.......0.......0.......5.......5...........n......a... D..%... D..[...+.......<?......<U...;..<U...+..<.......H5..&...H5..\...L.......VE......V....A..f.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):153608
                                                                                                                                                                                                                                  Entropy (8bit):4.843805801051326
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:y5pmbKIhooMbGe91MrjOhmGzP6LJbWz5XIxELpU6:yObeqrjPGzeJyJLy6
                                                                                                                                                                                                                                  MD5:BD8BDC7BBDB7A80C56DCB61B1108961D
                                                                                                                                                                                                                                  SHA1:9538C4D8BB9A95C0D9DC57C7708A99DD53A32D1F
                                                                                                                                                                                                                                  SHA-256:846E047573AE40C83671C3BA7F73E27EFC24B98C82701DA0DF9973E574178BB2
                                                                                                                                                                                                                                  SHA-512:F040EC410EBFEA21145F944E71ADCAE8E5F60907D1D3716A937A9A59A48F70C6B7EAAC91C2C554F59357A7BC820CDBD17C73A4DECC20B51F68EB79EDD35C5554
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......lv_LVB.......*...B...+..y....@.......A...=...B......C......D.......E.......F...#...G...G...H...k...I.......P...~...Q......R.......S.......T...5...U...Y...V......W.......X.......Y.......]..%....s.......t...8.......n.......A...;..&....;.......;...!...;...A...;../....M..%....O.......O...............}..%...........=.......m..&....t...(......(g..(5...+..+;..4...+;..d...+O......1...(...D@...a..E@......H4..z...HY..Q...H.......IC......J....6..J.......J.......LD......L....9..PS......QR......R...U...T....S..U.......X...._..Zr......[`..r...\.......]x...*.._......._....{..yg......1...5v...E..7........(......B.......|.......|W......~r...$..R....[..~....,.......y...l...y...............................9..S....E...g...........z...z...................%..F....D........................"Z.....$......)....5.......0...\...0.......0...r...0.......0.......5...a...5..........J......V... D..&... D..P...+.......<U......<U......<.......H5..'"..H5..P...L....~..VE...R..VE..%...V......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):162982
                                                                                                                                                                                                                                  Entropy (8bit):4.841899887077422
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:sXpestp/YIFtDT8FIWYbIJmPYuIpnmxAk6mwyJNqSm9+P:sxpTDT8FIWfJmdCmxApmbnqSm9+P
                                                                                                                                                                                                                                  MD5:F9475A909A0BAF4B6B7A1937D58293C3
                                                                                                                                                                                                                                  SHA1:76B97225A11DD1F77CAC6EF144812F91BD8734BD
                                                                                                                                                                                                                                  SHA-256:CE99032A3B0BF8ABAD758895CC22837088EAD99FD2D2514E2D180693081CFE57
                                                                                                                                                                                                                                  SHA-512:8A4F1B802B6B81FF25C44251FB4A880E93E9A5FE25E36825A24BFE0EFB34E764E7E1EE585D3A56554964B7921E7813C67F12D200D6E0C5EAF4BB76B064B5C890
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......pl_PLB..0....*.."....+.......@...F...A...j...B......C.......D...3...E.......F...P...G...t...H.......I.......P.......Q.......R.......S...>...T...b...U.......V.......W.......X...(...Y...L...]..*....s.......t...r.......o.......+...;..*....;..+....;..."...;... ...M..*....O...6...O...........a...}..+...........=.......m..+G...t...G......,...(5......+;..:...+;..k...+O......1...-[..D@.....E@......H4...U..HY..WU..H.......IC......J....6..J.......J.......LD......L....%..PS......QR.. ...R...[...T....1..U.......X......Zr......[`......\.......]x...A.._......._....}..yg......1...;W...E..=........%......H....................$..Xp...[.......,.......y...i...y...........}......$R...........9..X....E..+)...........z.. E...................%..K....D...p....................&......(......-....5.......0.......0...e...0.......0..+....5...]...5...........f......]-.. D..,%.. D..V?..+....V..<U......<U......<....-..H5..,M..H5..V...L....Z..VE..!...VE..)...V.......f...P...f....K..f......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):203767
                                                                                                                                                                                                                                  Entropy (8bit):5.362551648909705
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:hn4dEJ63pdhPpy6gu5fs4MHQv6sLlxnrncF423ZL9xyuXwdcX8LZuf76CW+WeXFx:aN3pdV5fZbpItXsttRY+WSq
                                                                                                                                                                                                                                  MD5:5096AD2743BF89A334FBA6A2964300D4
                                                                                                                                                                                                                                  SHA1:405F45361A537C7923C240D51B0FF1C46621C203
                                                                                                                                                                                                                                  SHA-256:3DA6605668F9178D11A838C4515478084DCFB4F9CF22F99D7A92B492DB9C224B
                                                                                                                                                                                                                                  SHA-512:7B88B501792B5831426BAA669138192ED94CC3F8323A3DF9D5287655DC4D877706908C517AB7523AE8A283BF50B47123F13B8AE40EA2F3081C3459EDC47FC8DD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......ru_RUB..7....*...L...+...W...@..,....A..,....B..-1...C..-U...D..-....E...r...F.......G.......H../....I../8...P..1'...Q..1K...R..1....S..1....T..1....U..2....V..2\...W..2....X..2....Y..2....].......s..$c...t...'......%........r...;..-....;.......;..J....;..V....M...C...O.......O..&.......8....}...m......+3...=..+....m.......t..+.......p...(5..]@..+;..[0..+;......+O..H...1...qM..D@..-...E@..1o..H4...p..HY..xm..H....*..IC...@..J....g..J.......J.......LD......L....p..PS......QR..!...R...}...T...&...U...'...U...ki..X...+...Zr..3...[`......\...:...]x..)..._......._...;...yg..S...1...\....E..__...7.........H.......k................j.......U...$..y....[.......,.......y...k...y...............................9..y....E...O...........z..!*...................%..nW...D.................%w.....g......j~.....qw...5...H...0.......0..I....0..._...0......5.......5..................~... D../k.. D..wa..+....?..<?.."t..<U......<U.."...<...#z..H5../...H5..w...L...&...VE.."...V...F$.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):125763
                                                                                                                                                                                                                                  Entropy (8bit):4.80343609423322
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:roXDuC1u/2lUBGjJirE5tsd/aev1GIfOdvhw:OucMGjH5tbm
                                                                                                                                                                                                                                  MD5:3D60E50DCBCBD70EE699BC9B1524FCB9
                                                                                                                                                                                                                                  SHA1:0211B4911B5B74CC1A46C0FCA87D3BF5632AA44A
                                                                                                                                                                                                                                  SHA-256:D586AE2C314074CF398417FDECB40709D5478DFEB0A67C2FE60D509EE9B59ED7
                                                                                                                                                                                                                                  SHA-512:F98211867F1DBCB8A342C00E23FA5718BE6E999F7449CB8470B41BF0F527C7F78CC4D6666E28968F32E96026907156753979BFADA7E6BF4225D02A902D24906D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......sk_SKB..$x...*.......+..>....@......A......B.......C.......D...3...E...Z...F......G......H.......I.......P.......Q...D...R.......S......T.......U.......V...1...W...X...X.......Y......]...Y...t..D-......K....;...3...;.......;.......;......;...V...M.......O.._ ......l....}.......m...........T..(5...(..+;......+;..%...+O......1......E@...k..F.......H4..?I..HY..@7..H...J...I....,..IC..HT..J...H{..J...H...LD..J"..L...Jv..PS..Q...R...D...Zr..i]..[`..7...\...nB.._...o...1...&....E..(........B......19......A.......A....$..AF...[..C....,..D....y..G.......v........g......G....9..A....E..........IH...%..4.......Kf..............................5..K....0...,...0.......0.......0..Of...0.......5..P....5..........E... D...C.. D..?'..+...Y`..<U......<U..\...<...]...H5...m..H5..?...L...^...VE......f.......f...8...g.......l...aP.......................6......d....D..f(...`..f...............?....`..h5...y..H....5..j........E...e.......e..@....... ......>......oZ......l..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):194487
                                                                                                                                                                                                                                  Entropy (8bit):4.877239354585035
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:yRRhAFCvqDBitD/iDG9AOH+l4TcwZBPqHo9fd9CFRK+2IKAimxsjucV2p0ZqvRu7:yRRHs5mksWVX3lA3
                                                                                                                                                                                                                                  MD5:6CBC5D8E1EABEC96C281065ECC51E35E
                                                                                                                                                                                                                                  SHA1:4E1E6BA3772428227CB033747006B4887E5D9AD1
                                                                                                                                                                                                                                  SHA-256:6A0BF6E70E7920C2B193E76E92F78F315936955D3B06AC039D917F2E06C43281
                                                                                                                                                                                                                                  SHA-512:CE1F9EE180176153D5F523D71E0DB06F4DEA65C24E5E2CD56341CFAEE349A8E9A0F606D99F7219A35DD4516D1528C90AEA4BB87548A55392B8F2B36164D478B1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......tr_TRB..7....*.......+...-...@.......A.......B.......C...%...D.......E...F...F.......G.......H.......I.......P.. ....Q.. ....R..!D...S..!h...T..!....U..!....V.."....W.."0...X.."T...Y.."x...]..,g...s.../...t......................;..,9...;..-I...;..9@...;..E....M..,....O.......O...G...........}..,............=...\...m..,....t.........._3..(5..LJ..+;..Wt..+;...\..+O..7...1..._...D@......E@..!...H4...@..HY..t...H....2..IC...r..J......J....D..J....K..LD...$..L....x..PS......QR..!...R...x...T.......U....q..U...Y...X...."..Zr...%..[`......\....:..]x......_......._.......yg..6...1...X....E..[....7...Z......7Q......f............................$..u....[...:...,...5...y.......y...........7...............!...9..u....E...........P...z.. ........p...........%..j....D..................A.....U......Y......_....5...V...0.......0..8....0...U...0.......5.......5..~b..............z+.. D..-... D..s...+.......<?...8..<U...s..<U...p..<.......H5..-...H5..s...L.......VE.."0..V...4..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):158274
                                                                                                                                                                                                                                  Entropy (8bit):5.402056706327934
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:jXwjFVUDdMUD4TzdAhpQgO5poZHvJllEnhmdK4I77/dnPJX/imfb1jhvv3BxT8ue:jBzD4Tzaw5pCvJ8hVPdlvj3p8
                                                                                                                                                                                                                                  MD5:D6234E4E21021102B021744D5FA22346
                                                                                                                                                                                                                                  SHA1:63A14327D0CF0941D6D6B58BFA7E8B10337F557B
                                                                                                                                                                                                                                  SHA-256:51B8FF55B37DC5907D637A8DDDA12FBE816852B0244C74EB4F0FB84867A786E0
                                                                                                                                                                                                                                  SHA-512:37D24A092C5F29BACB7A4CA8207C4EEFD0F073B7E74A492402867F758084091BF1D79D2BA2B4A28B35FEF42E8023C371FDE97578F74BB2033551154E77102DE6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......uk_UAB../....*...E...+...l...@.......A.......B...G...C...k...D.......E.......F.......G.......H...*...I...N...P...=...Q...a...R.......S.......T.......U.......V...r...W.......X.......Y.......]..*y...s.......t...........;.......n...;..*Q...;..+U...;.......;...x...;..!(...M..*....O.......O...........6...}..*........E...=.......m..*....t..........3...(5..&...+;..:...+;..k0..+O...A..1...4-..D@... ..E@......H4...8..HY..W...H....2..IC...V..J....}..J.......J....%..LD...&..L....z..PS......QR.. ...R...\...T....(..U.......X.......Zr......[`..~...\.......]x......_......._....4..yg...c..1...;....E..=w.......m......I............................$..X....[...<...,.......y.......y...........M...................9..Y....E...F.......D...z.. ........P...........%..LB...D.......................-n...../......4W...5...F...0...p...0...W...0.......0...k...0.......5.......5..................^... D..+... D..V...+.......<U.../..<U......<....>..H5..+...H5..V...L....S..VE..!...VE..0...V......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Qt Translation file
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):127849
                                                                                                                                                                                                                                  Entropy (8bit):5.83455389078597
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:Fv2cHP10gOs6dcFxsJopMqOWv2WIrPFP8pa:Fh6s6iFxEodjef8pa
                                                                                                                                                                                                                                  MD5:9C6A3721D01ECAF3F952CE96F46CE046
                                                                                                                                                                                                                                  SHA1:4A944E9E31DF778F7012D8E4A66497583BFD2118
                                                                                                                                                                                                                                  SHA-256:085D29EAF9BBB788B2F2503D74A1EF963A9411CEB600441254CE49A120E1AB63
                                                                                                                                                                                                                                  SHA-512:6E2807B8785F42A26C9CCBDBA0327DD40B529B10C468593F0E74113774D1CCDAA4FD9ACE9B259B9040E1475911428ECAEA49425B0F170862CF8147D23DB48E46
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:<.d....!..`.......zh_TWB..2x...*.......+..)....@.......A.......B...j...C......D.......E......F.......G...)...H...M...I...q...P...%...Q...I...R......S......T.......U.......V...Z...W...~...X......Y.......]..!....s.......t..-...............4....;..!z...;.."|...;.......;.......M..!....O.......O..Ay......N)...}..!............=.......m.." ...t...(.........(5......+;..;...+;.._...+O......1.......D@...C..E@...m..H4..*W..HY..Pm..H...3...IC..1...J...1...J.......J...1...LD..2...L...38..PS..6...QR...T..R...T...T...A...U...A...X...E...Zr..K...[`..$...\...OW..]x......_......._...P...yg..a^..1...<....E..>....7...>.......;......Fo......+.......+.......-L...$..QR...[..-....,...F...y.......y..1J...............6......1p...9..Q....E..........2....z...........<......3....%..H....D..4W......4}....................Z...... ...5..4....0...?...0...K...0..5....0...L...5..6....5..........6.......U... D.."... D..O...+...<%..<U......<U..>...<...?:..H5..#...H5..O...L...AS..VE...M..VE......V.......f...L..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2482176
                                                                                                                                                                                                                                  Entropy (8bit):6.2460848665736535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:49152:tqBjGbVDFbsOiwXMS96M4JFH4kOIe8OC6mPQYFx0ZkV1gdrmUkyYquigD6QTrnUM:GG9Fb5iwXMS96M4JFH4kOIe8OC6mPQYL
                                                                                                                                                                                                                                  MD5:D6D51C8F5E381CBBA49D54E507A41220
                                                                                                                                                                                                                                  SHA1:86DEAAB67D3FC4E26BC81DB89FAEC720A5D8A3A4
                                                                                                                                                                                                                                  SHA-256:5A2AED6F96ABEC6905E6A36D33BC00D2C23E13F6333EA0545A32AB57B33A7C47
                                                                                                                                                                                                                                  SHA-512:3B3B386D3D0A8865348A574740473325A1A7DEAC6A9B767FBCA253E1DE90412AA76E4E9B36D9586F3307F10EE567ADB34D85BF21751E568E86EC66683131FBF0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........^...0...0...0.....0...1...0...1...0...5...0...4...0...3...0.6.1...0.i.1...0...1...0...5...0...0...0...2...0.Rich..0.........PE..d....T%e.........." .....T..........HX.......................................0&...........`.............................................L.....................#...............%................................(......8............p...o...........................text....S.......T.................. ..`.rdata..B....p.......X..............@..@.data...h...........................@....pdata........#......|#.............@..@.reloc.......%......F%.............@..B........................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2490880
                                                                                                                                                                                                                                  Entropy (8bit):6.2472271162844635
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24576:g9+rM3QiJBRL6u8dM8sjWmA5884lt9YLNsLWOl4aid:4AM3QGBRL6tdM8s458BltqoWOl3Y
                                                                                                                                                                                                                                  MD5:A931566050607D6A9FEB94CEF82672D9
                                                                                                                                                                                                                                  SHA1:405A7E907631EFEF51BEA7952D4D725B6402D5A2
                                                                                                                                                                                                                                  SHA-256:8C425D163B0C650CB8DC4662625DE4998BED2AD9A3F2E04A8664E2E72A69F845
                                                                                                                                                                                                                                  SHA-512:263A23F1346ECF1A042F3C697C8F40AEFB99E134C06EE87EDEEF47C170E7113327A9C51143AF83E4FA1589970F22C2606BF6F4BB4EBFF7BE3EE3E3ACFDE4A258
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......;~E...+O..+O..+Ovg.O{.+O-j*N}.+O$w*N}.+O-j.Nk.+O-j/Nw.+O-j(N|.+O.b*N}.+O.o*Nz.+O..*O..+O.j.Nt.+O.j+N~.+O.j)N~.+ORich..+O........PE..d....T%e.........." .........Z...............................................P&...........`..........................................:..L....;................$..x............%.........................................8................z...........................text.../........................... ..`.rdata..&...........................@..@.data....z.......\...x..............@....pdata...x....$..z....#.............@..@.reloc........%......N%.............@..B........................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5160960
                                                                                                                                                                                                                                  Entropy (8bit):6.271462104402393
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:49152:UW5QT2xZG0bqKyQAGXB6eL85ZwsmRDG1fK0YlfHpF+QlmGWSV:Yy+yB6W8y0opg2V
                                                                                                                                                                                                                                  MD5:9CDE8433816662EAEB762C8E6FE77E6B
                                                                                                                                                                                                                                  SHA1:D9D69268AF89C4134ED94C768BAEDD6ABBCE7557
                                                                                                                                                                                                                                  SHA-256:E732F15729FA69C3067DC33ABB60E241570398AA9AB3359D9FF2A9714D1A1E4C
                                                                                                                                                                                                                                  SHA-512:3F6DFC0FDC9EEB4F5D041AAF5D0420091F7230BF60796E979503D345CE9A74E0F23DD229C31207221C8509BAB1EDDE616FF9803776708A5B4097A7338D372C54
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........0..^..^..^.......^.._..^.._..^..[..^..Z..^..]..^..._..^.C._..^.._..^...[...^...^..^...\..^.Rich.^.........PE..d....T%e.........." .....(-...!......)-.......................................O...........`...........................................<.T...T.<..............@I.`k............M..O..`.8...............................8.8............@-.`............................text...8&-......(-................. ..`.rdata..V....@-......,-.............@..@.data....9....B.......A.............@....pdata..`k...@I..l....I.............@..@.reloc...O....M..P...pM.............@..B........................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):121856
                                                                                                                                                                                                                                  Entropy (8bit):6.01868599050081
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:LSid0KpCeNInvb5zytG2Unq6jYMk6hGEV13B80bXzcWR9yfP/xPP8gVjTKoI:+mTenv9XnqhkR13u07zhiPPrjTK
                                                                                                                                                                                                                                  MD5:0CA03BF820F16E28256695C42DAB56DD
                                                                                                                                                                                                                                  SHA1:35BF3D4F7112AAC0FE5BA61AD647F48B0EDBB93F
                                                                                                                                                                                                                                  SHA-256:FCF8F65A5C944D94DE8535B9D4F4235E24C8C328266BD2B0BA420EA1F8433C01
                                                                                                                                                                                                                                  SHA-512:9FE58F438921CF1DE341F4194707ECA2E4C045184493FD4715F078D0137A8B47F299072FA0128A4172EF433A41F9E9A949592DE74F72152B1A81D4A588C699BB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............}...}...}....3..}.......}.......}.......}.......}.......}.......}...}..v}.......}.......}...._..}.......}..Rich.}..........PE..d...H.#e.........." .....P..........`S.......................................0............`.........................................0...T.................................... .........................................8............`...............................text....N.......P.................. ..`.rdata...S...`...T...T..............@..@.data...0 ..........................@....pdata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5653424
                                                                                                                                                                                                                                  Entropy (8bit):6.729277267882055
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:49152:EuEsNcEc8/CK4b11P5ViH8gw0+NVQD5stWIlE7lva8iposS9j5fzSQzs7ID+AVuS:EnL8+5fiEnQFLOAkGkzdnEVomFHKnPS
                                                                                                                                                                                                                                  MD5:03A161718F1D5E41897236D48C91AE3C
                                                                                                                                                                                                                                  SHA1:32B10EB46BAFB9F81A402CB7EFF4767418956BD4
                                                                                                                                                                                                                                  SHA-256:E06C4BD078F4690AA8874A3DEB38E802B2A16CCB602A7EDC2E077E98C05B5807
                                                                                                                                                                                                                                  SHA-512:7ABCC90E845B43D264EE18C9565C7D0CBB383BFD72B9CEBB198BA60C4A46F56DA5480DA51C90FF82957AD4C84A4799FA3EB0CEDFFAA6195F1315B3FF3DA1BE47
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Q.cu...&...&...&...'...&...'...&...'...&..&...&G..'...&G..'...&...'...&...&..&G..'...&G..'...&G..'...&G..'...&G..&...&G..'...&Rich...&................PE..d....~.a.........." .....(-..X)......X,.......................................V......YV...`A..........................................:.....h.;.......?......`=..8....V..'...PU.0p..p.5.T...........................`...8............@-.P...0.:......................text....&-......(-................. ..`.rdata.......@-......,-.............@..@.data....6... <.......<.............@....pdata...8...`=..:....<.............@..@.didat..H.....?.......?.............@....rsrc.........?.......?.............@..@.reloc..0p...PU..r....T.............@..B................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1143296
                                                                                                                                                                                                                                  Entropy (8bit):6.046391318157997
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12288:Wx0ux/TOd3rXfWHZPBFwt0xVxio416yw5V4pJDipt:k04T63rX2FZq675V4p8p
                                                                                                                                                                                                                                  MD5:325B7DE1C9FA1C30849CFA24841ECE9E
                                                                                                                                                                                                                                  SHA1:59603C4EB7124B652A138DEEC9FA90ACDBB6AF20
                                                                                                                                                                                                                                  SHA-256:12713A63044ADA7D907C2678A5CC765DA01DF29104C148759BDD8B1F4353A80F
                                                                                                                                                                                                                                  SHA-512:360082ECEB86663F3A0FABFA55A1672945531E3C4E5FAEAA9A2931F5A31179C1E15AF0B23933A8B9D79AC176B50A2F1A59E4DB81D42E336DF98C0239AA5AD159
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J.E.+r..+r..+r..S...+r.:^s..+r.cBs..+r..@s..+r..^v..+r..^q..+r..^w..+r..+s..-r..^s..+r.:^{..+r.:^r..+r.:^...+r.:^p..+r.Rich.+r.........................PE..d......d.........." .........r...........................................................`.........................................P....T..Xr..h...............................\\..`...T.......................(.......8................0...........................text...P........................... ..`.rdata..............................@..@.data...............................@....pdata...............d..............@..@.rsrc...............................@..@.reloc..\\.......^..................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):101672
                                                                                                                                                                                                                                  Entropy (8bit):6.566355945650465
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:7y6+2mUD0uBFRXqYue/o+18iBH5T7heunxr98nZXR9xecbSQ2bIB0TO:7lXfRXqQw+PHLrCZh9xecbSt
                                                                                                                                                                                                                                  MD5:8697C106593E93C11ADC34FAA483C4A0
                                                                                                                                                                                                                                  SHA1:CD080C51A97AA288CE6394D6C029C06CCB783790
                                                                                                                                                                                                                                  SHA-256:FF43E813785EE948A937B642B03050BB4B1C6A5E23049646B891A66F65D4C833
                                                                                                                                                                                                                                  SHA-512:724BBED7CE6F7506E5D0B43399FB3861DDA6457A2AD2FAFE734F8921C9A4393B480CDD8A435DBDBD188B90236CB98583D5D005E24FA80B5A0622A6322E6F3987
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......!/.NeNl.eNl.eNl....gNl.l6..nNl.eNm.INl..>o.hNl..>h.uNl..>i.zNl..>l.dNl..>..dNl..>n.dNl.RicheNl.................PE..d...M8.^.........." .........^...... .....................................................`A........................................`1..4....9.......p.......P.......L..(A..........H...T...............................0............................................text...b........................... ..`.rdata...?.......@..................@..@.data...0....@.......4..............@....pdata.......P.......8..............@..@_RDATA.......`.......D..............@..@.rsrc........p.......F..............@..@.reloc...............J..............@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):44328
                                                                                                                                                                                                                                  Entropy (8bit):6.631745572973897
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:uJnUUV7xPg4RdPvv1DHkhhFAWN6srByiYzC:uaY7XN7Ih4CIiYzC
                                                                                                                                                                                                                                  MD5:21AE0D0CFE9AB13F266AD7CD683296BE
                                                                                                                                                                                                                                  SHA1:F13878738F2932C56E07AA3C6325E4E19D64AE9F
                                                                                                                                                                                                                                  SHA-256:7B8F70DD3BDAE110E61823D1CA6FD8955A5617119F5405CDD6B14CAD3656DFC7
                                                                                                                                                                                                                                  SHA-512:6B2C7CE0FE32FAFFB68510BF8AE1B61AF79B2D8A2D1B633CEBA3A8E6A668A4F5179BB836C550ECAC495B0FC413DF5FE706CD6F42E93EB082A6C68E770339A77C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........h..j...j...j....l.h....y..h...cq..a...j...[....y..o....y..m....y..p....y..k....y|.k....y..k...Richj...................PE..d...Q8.^.........." .....:...4......pA....................................................`A........................................Pk.......k..x....................l..(A......8...(b..T............................b..0............P..X............................text....9.......:.................. ..`.rdata... ...P..."...>..............@..@.data................`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..8............j..............@..B........................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):63504
                                                                                                                                                                                                                                  Entropy (8bit):5.942077983347744
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:wdBMNrExYERf8BEHZEOk6UVwTooIhsn/AyZl:fExTRfEOZEOk69TBIhsnFl
                                                                                                                                                                                                                                  MD5:05F37B6BE4CD6B5DC8F165128913CF89
                                                                                                                                                                                                                                  SHA1:04AAB6F380F40DCAE85CBE0C397356187BD7BFEB
                                                                                                                                                                                                                                  SHA-256:0ED512E410A8604821F74C84396DD61E71756DBE8E36E8A96261C707B659721A
                                                                                                                                                                                                                                  SHA-512:263726F87375A29335B4DCAEC38BB79C8F019A7240BE9AF82D52AACC93611227B77AE61D03DC05F92EDF138715E0D262901D824285A7A1CAACD30110E093D6F7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........................x.....2.......2.......2.......2.......}..................H...}.......}.......}.......}.......Rich....................PE..d....={_.........." .....^................................................... .......q....`.............................................P...`...d...................................@v..T............................v..0............p..0............................text...f].......^.................. ..`.rdata..PI...p...J...b..............@..@.data...x ..........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):85008
                                                                                                                                                                                                                                  Entropy (8bit):6.429388236002673
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:du9pb+4t6286gTWPh1avDJjNcnl8rDHiCdgoIh4Vdye:Y/4286g6PhwbJjNcnKrDHiWJIh4V7
                                                                                                                                                                                                                                  MD5:6C7565C1EFFFE44CB0616F5B34FAA628
                                                                                                                                                                                                                                  SHA1:88DD24807DA6B6918945201C74467CA75E155B99
                                                                                                                                                                                                                                  SHA-256:FE63361F6C439C6AA26FD795AF3FD805FF5B60B3B14F9B8C60C50A8F3449060A
                                                                                                                                                                                                                                  SHA-512:822445C52BB71C884461230BB163EC5DEE0AD2C46D42D01CF012447F2C158865653F86A933B52AFDF583043B3BF8BA7011CC782F14197220D0325E409AA16E22
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Y.8.8.k.8.k.8.k.@!k.8.k.H.j.8.km.uk.8.k.H.j.8.k.H.j.8.k.H.j.8.kDI.j.8.k.P.j.8.k.8.k.8.kDI.j.8.kDI.j.8.kDIMk.8.kDI.j.8.kRich.8.k........................PE..d....={_.........." .........d......t........................................p.......J....`.............................................H............P.......@..4....2.......`...... ...T...............................0...............@............................text...F........................... ..`.rdata...A.......B..................@..@.data........0......................@....pdata..4....@......................@..@.rsrc........P.......&..............@..@.reloc.......`.......0..............@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181248
                                                                                                                                                                                                                                  Entropy (8bit):6.1890394396881385
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:5Z1fKD8GVLHFSq0TTjfQxnkVt0hcspEEHS74iSTLkKAFB6Hx:5ZNRGVbCTTCnOZsuUtiSTLLA/6
                                                                                                                                                                                                                                  MD5:F3F610B10A640A09B423E1C7E327CAD1
                                                                                                                                                                                                                                  SHA1:007BF7000DF98E4591BDBFC75E7A363457C692FD
                                                                                                                                                                                                                                  SHA-256:D112AE33247D896008D79A1A5F96B98D0EAEE80D13372E64C2D88FFBD94FADF8
                                                                                                                                                                                                                                  SHA-512:28726490D1026AD6F2BBAD949B247F904E4CECEEF7011E7408C11E4FAB886E77E84317E7A14E3E86C1B7178666B06E0A774734A497F91AFFF76882756E03B6B0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........i.....C...C...C.pMC...C.}.B...C.g#C...C.}.B...C.}.B...C.}.B...C.p.B...CH}.B...C...C...C=}.B...C.pKC...C=}.B...C=}!C...C=}.B...CRich...C................PE..d.....e.........." .........@...............................................0............`..........................................g..h...xg..................H............ .......M...............................M..8............................................text...h........................... ..`.rdata..l...........................@..@.data....\.......0...v..............@....pdata..H...........................@..@.rsrc...............................@..@.reloc....... ......................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):124944
                                                                                                                                                                                                                                  Entropy (8bit):5.9205443419262895
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:0CDxolVo/PL5xOCkG0nv2OefeZN0eBet/31FIhVPz:5yo5xIGFNfeZqDFS
                                                                                                                                                                                                                                  MD5:29DA9B022C16DA461392795951CE32D9
                                                                                                                                                                                                                                  SHA1:0E514A8F88395B50E797D481CBBED2B4AE490C19
                                                                                                                                                                                                                                  SHA-256:3B4012343EF7A266DB0B077BBB239833779192840D1E2C43DFCBC48FFD4C5372
                                                                                                                                                                                                                                  SHA-512:5C7D83823F1922734625CF69A481928A5C47B6A3BCEB7F24C9197175665B2E06BD1CFD745C55D1C5FE1572F2D8DA2A1DCC1C1F5DE0903477BB927ACA22ECB26A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Y...7...7...7.......7...6...7...2...7...3...7...4...7.A.6...7...3...7...6...7.l.6...7...6...7.A.:...7.A.7...7.A....7.A.5...7.Rich..7.................PE..d....={_.........." .................^..............................................{.....`.........................................@c.......c..................`.......................T...............................0............................................text............................... ..`.rdata..Fo.......p..................@..@.data...4?.......:...r..............@....pdata..`...........................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):270352
                                                                                                                                                                                                                                  Entropy (8bit):6.520321327863571
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6144:NZvKcJQiRhmo/KmsHkD96sIlBgZnIDQVGz9qWMa3pLW1An3nS1fSajGjY+CKT2:JQiRhXKPdg5abjY+p2
                                                                                                                                                                                                                                  MD5:CE4DF4DFE65AB8DC7AE6FCDEBAE46112
                                                                                                                                                                                                                                  SHA1:CDBBFDA68030394AC90F6D6249D6DD57C81BC747
                                                                                                                                                                                                                                  SHA-256:FFBE84F0A1EAB363CA9CF73EFB7518F2ABD52C0893C7CC63266613C930855E96
                                                                                                                                                                                                                                  SHA-512:FC8E39942E46E4494356D4A45257B657495CBFA20E9D67850627E188F70B149E22603AE4801B4BA7B9A04D201B3787899D2AEE21565237D18E0AFCE9BAE33EE9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\di..............}.......u.......u.......u.......u.......t......Cm...............t.......t.......t.......t.......t......Rich............................PE..d....={_.........." .........H...............................................@......Q.....`.........................................P...P............ ...........,...........0..\...p...T...............................0...............(............................text............................... ..`.rdata..............................@..@.data...H*.......$..................@....pdata...,..........................@..@.rsrc........ ......................@..@.reloc..\....0......................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):64528
                                                                                                                                                                                                                                  Entropy (8bit):6.053762419507484
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:k8JtPzXIvBbB+TXS/NnjtQWCYDhYF7POfex7ooIhsIAKWDG4y1b:NZIvBbB+TXS9ZQVYutOfO7ooIhsI6y1b
                                                                                                                                                                                                                                  MD5:F377A418ADDEEB02F223F45F6F168FE6
                                                                                                                                                                                                                                  SHA1:5D8D42DEC5D08111E020614600BBF45091C06C0B
                                                                                                                                                                                                                                  SHA-256:9551431425E9680660C6BAF7B67A262040FD2EFCEB241E4C9430560C3C1FAFAC
                                                                                                                                                                                                                                  SHA-512:6F60BFAC34ED55FF5D6AE10C6EC5511906C983E0650E5D47DAC7B8A97A2E0739266CAE009449CCED8DFF59037E2DBFC92065FBBDFDE2636D13679E1629650280
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......v...2...2...2...;.E.6......0......9......:......1.....0...i...0.....1...2........3.....3...).3.....3...Rich2...................PE..d....={_.........." .....b..........XC.......................................0.......B....`.............................................P...P................................ ..........T...........................P...0............................................text....a.......b.................. ..`.rdata..xQ.......R...f..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):161296
                                                                                                                                                                                                                                  Entropy (8bit):6.778218368955716
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:plVImSOG2/K/clbGT5twoLPw8Eo5KZznfo9mNo+lPWiruUpzJIhH1d:plVImSOGoK/gGT1t5KhQYO+lbrbxY
                                                                                                                                                                                                                                  MD5:B5355DD319FB3C122BB7BF4598AD7570
                                                                                                                                                                                                                                  SHA1:D7688576ECEADC584388A179EED3155716C26EF5
                                                                                                                                                                                                                                  SHA-256:B9BC7F1D8AA8498CB8B5DC75BB0DBB6E721B48953A3F295870938B27267FB5F5
                                                                                                                                                                                                                                  SHA-512:0E228AA84B37B4BA587F6D498CEF85AA1FFEC470A5C683101A23D13955A8110E1C0C614D3E74FB0AA2A181B852BCEEEC0461546D0DE8BCBD3C58CF9DC0FB26F5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................-....v......v......v......v......9..................9......9......9.A....9......Rich...................PE..d....={_.........." .....z...........2...............................................o....`......................................... 6..L...l6..x............`.......\..........0...x...T..............................0...............8............................text....y.......z.................. ..`.rdata..b............~..............@..@.data........P.......2..............@....pdata.......`.......:..............@..@.rsrc................P..............@..@.reloc..0............Z..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):28688
                                                                                                                                                                                                                                  Entropy (8bit):6.04391473804357
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:yQNRlRJie+2Hb5t51ydmXc4Y5LCPxHb044YIIhkBLgXtOnYPLxDG4y8+9X:yk3bBtt5ivCp7KYIIhktgAWDG4yD
                                                                                                                                                                                                                                  MD5:E06C0C8EC05EADBEECB3083F8EC26BE6
                                                                                                                                                                                                                                  SHA1:0C7DF3E3C82F44F4B0347BE2D218FBE879770053
                                                                                                                                                                                                                                  SHA-256:91ADAC3AF53EEDB4508F554E48DFEE6E17252C28B017534124B43DF856EA84EF
                                                                                                                                                                                                                                  SHA-512:839625DA6E80AAF47D664ADEEC9805A3AF5B08FFEEE270D17353E6DCAAFF89518960D4FB8A7D35AD8B77BE94380C4266B6EFCCA2535EA0362962ABC518533228
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Antivirus:
                                                                                                                                                                                                                                  • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                  • Antivirus: Virustotal, Detection: 0%, Browse
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......4:J.p[$.p[$.p[$.y#..r[$..+%.r[$..+!.{[$..+ .x[$..+'.s[$..*%.r[$.+3%.u[$.p[%.%[$..*).r[$..*$.q[$..*..q[$..*&.q[$.Richp[$.........PE..d....={_.........." ..... ...8......X...............................................Tz....`..........................................@..`....@..x....p.......`.......V...............3..T............................3..0............0...............................text............ .................. ..`.rdata..$....0.......$..............@..@.data...h....P.......@..............@....pdata.......`.......F..............@..@.rsrc........p.......J..............@..@.reloc...............T..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):45072
                                                                                                                                                                                                                                  Entropy (8bit):6.0669375628594135
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:Pk8X1dqmzHAimN2/UMaAjoYWEXhXjxY0YEwIhJtHpWDG4ynbz:s8XPWN2/UMfhXjxYxEwIhJtH0ynbz
                                                                                                                                                                                                                                  MD5:BF495600C3D758141BED531FAABF2A4F
                                                                                                                                                                                                                                  SHA1:5F20AB7E478B30DB6D6DEE90AB23B26A219D6604
                                                                                                                                                                                                                                  SHA-256:AF74C3FC4BC87E1ED70E11A700A073DF77C4C891B6FAD17A9F019DF0D32C18FC
                                                                                                                                                                                                                                  SHA-512:ED4BCFE35FE6F471CD9FF9220AACFD89C547227A9981D98427A721F39ACCF7EBD99BA88977EE27CD353570671203D992D6D94B3DCB567E0188602DB8CE353117
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......H.................l.............................................W.......W...............................................Rich............................PE..d....={_.........." .....@...X......X................................................q....`..........................................v..X...(w...................................... W..T............................W..0............P...............................text....?.......@.................. ..`.rdata..j4...P...6...D..............@..@.data...`............z..............@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1165824
                                                                                                                                                                                                                                  Entropy (8bit):7.056444569604366
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24576:LsZDXB6wmcZzdcZ7fUoPHUEXLznTJenIGHSQt:QZDXB6wmcUfT4HHt
                                                                                                                                                                                                                                  MD5:1346EBBB668FC29F837D81A632315B08
                                                                                                                                                                                                                                  SHA1:6BA180ACD05B350D1204720661AC5CF4642A6205
                                                                                                                                                                                                                                  SHA-256:378E889970B28B2A5D561D4013F9970F8C2C8DADD5013708B9DE74C4E7F35CB0
                                                                                                                                                                                                                                  SHA-512:3A3DAF2A1FF7B8EE8826E3E17488B5B28FB5434F478C9E8480F9998DA60029B5297F09FB04CFCFA7C18AC65CA0825635CCE294B09BC116B40F4AB9C625EB7FEE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....b..........0..........p.....................................[........ .........................................+........................'...........................................`..(...................d................................text...ha.......b..................`.P`.data................f..............@.`..rdata..p............h..............@.`@.pdata...'.......(...V..............@.0@.xdata..L,...........~..............@.0@.bss....h.............................`..edata..+...........................@.0@.idata..............................@.0..CRT....X...........................@.@..tls................................@.@..reloc..............................@.0B........................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):28176
                                                                                                                                                                                                                                  Entropy (8bit):6.044141372503601
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:v59xtkKh/UpAw6rEcrgy3njs+cErLS8AIhqUCnYPLxDG4y8dJa:v1h/G6rEcrpAIe8AIhqUCWDG4yOa
                                                                                                                                                                                                                                  MD5:4AB2CEB88276EBA7E41628387EACB41E
                                                                                                                                                                                                                                  SHA1:58F7963BA11E1D3942414EF6DAB3300A33C8A2BD
                                                                                                                                                                                                                                  SHA-256:D82AB111224C54BAB3EEFDCFEB3BA406D74D2884518C5A2E9174E5C6101BD839
                                                                                                                                                                                                                                  SHA-512:B0D131E356CE35E603ACF0168E540C89F600BA2AB2099CCF212E0B295C609702AC4A7B0A7DBC79F46EDA50E7EA2CF09917832345DD8562D916D118ABA2FA3888
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........................d.....2.......2.......2.......2.......}.....................}.......}.......}.......}.......Rich....................PE..d....={_.........." .........8......................................................._....`.........................................pB..L....B..d....p.......`.......T..............03..T............................3..0............0..@............................text...p........................... ..`.rdata..x....0......."..............@..@.data........P.......>..............@....pdata.......`.......D..............@..@.rsrc........p.......H..............@..@.reloc...............R..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):78864
                                                                                                                                                                                                                                  Entropy (8bit):6.1190188793723586
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:IEup3XVzjtJVW1TEAb9/s+m+p13SrpZfLL+kn8AIhVw4yZ:CV3tUwAb9/sb+pFSrbf+knFIhVwl
                                                                                                                                                                                                                                  MD5:F5DD9C5922A362321978C197D3713046
                                                                                                                                                                                                                                  SHA1:4FBC2D3E15F8BB21ECC1BF492F451475204426CD
                                                                                                                                                                                                                                  SHA-256:4494992665305FC9401ED327398EE40064FE26342FE44DF11D89D2AC1CC6F626
                                                                                                                                                                                                                                  SHA-512:CE818113BB87C6E38FA85156548C6F207AAAB01DB311A6D8C63C6D900D607D7BEFF73E64D717F08388ECE4B88BF8B95B71911109082CF4B0C0A9B0663B9A8E99
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......b...&~..&~..&~../.;. ~......$~......*~.......~......%~......$~..}...!~..&~...~......'~......'~....W.'~......'~..Rich&~..........................PE..d....={_.........." .....x...........(.......................................`............`.............................................P............@.......0..h............P.........T...........................0...0............................................text....w.......x.................. ..`.rdata...x.......z...|..............@..@.data...............................@....pdata..h....0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):88080
                                                                                                                                                                                                                                  Entropy (8bit):5.920616385129684
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:3m5kMZ/NIX0Tv6ufGBNINckuVzzYnzo4blwip7Z0kYBjooIhsQc5y/3E:25kMLIET6OoNS1Wzyz5wq7bYRBIhsQZU
                                                                                                                                                                                                                                  MD5:11897592CF9C078A0A1633C57A7694E2
                                                                                                                                                                                                                                  SHA1:9A6DA7AAEC8E808E2FAEE476D59BC685B2DA7FBC
                                                                                                                                                                                                                                  SHA-256:F8D0AFD1FE15F19D3A3ADE2A673EB2B9ECDC7952E67C6E50D228FE9666AF2F79
                                                                                                                                                                                                                                  SHA-512:72B9A264A2D6EA5E1A3FED8BD44501FBD035708B28E40B6993CB41ED041A439EDC63CD4C23A9833CF08CF89C82B86FA9F3F5484262D6131D3E2142222EB4E88D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J...+.[.+.[.+.[.S.[.+.[.[.Z.+.[x.M[.+.[.[.Z.+.[.[.Z.+.[.[.Z.+.[QZ.Z.+.[.C.Z.+.[.+.[.+.[QZ.Z.+.[QZ.Z.+.[QZu[.+.[QZ.Z.+.[Rich.+.[........................PE..d....={_.........." ................(|..............................................FL....`.............................................P... ........`.......@.......>.......p..\...T...T...............................0...............X............................text.............................. ..`.rdata...c.......d..................@..@.data........ ......................@....pdata.......@......................@..@.rsrc........`.......0..............@..@.reloc..\....p.......:..............@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):153104
                                                                                                                                                                                                                                  Entropy (8bit):5.90943354016701
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:D48iyVD7lDkbY02l2UY1dy5B+yq7SQmHh4CZKz7MJIh47/:D48i4lQU0qdYvy5Mr7SKMv
                                                                                                                                                                                                                                  MD5:EF4755195CC9B2FF134EA61ACDE20637
                                                                                                                                                                                                                                  SHA1:D5BA42C97488DA1910CF3F83A52F7971385642C2
                                                                                                                                                                                                                                  SHA-256:8A86957B3496C8B679FCF22C287006108BFE0BB0AAFFEA17121C761A0744B470
                                                                                                                                                                                                                                  SHA-512:63AD2601FB629E74CF60D980CEC292B6E8349615996651B7C7F68991CDAE5F89B28C11ADB77720D7DBBD7700E55FDD5330A84B4A146386CF0C0418A8D61A8A71
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.....................J....<.....<.....<.....<.....s....._.................s.....s.....s.&....s.....Rich...........PE..d....={_.........." .........................................................p......Q~....`.............................................d...$........P.......@.......<.......`..........T...............................0............................................text.............................. ..`.rdata..X...........................@..@.data....k.......f..................@....pdata.......@......................@..@.rsrc........P.......$..............@..@.reloc.......`......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):63504
                                                                                                                                                                                                                                  Entropy (8bit):6.060717095838651
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:f3mRCvik7gNsdpVmagdCJaagA6hcB0DN3/looIhsSiy50P:f3SCviK4agmaa1FeDN3/lBIhsSm
                                                                                                                                                                                                                                  MD5:07392B548D2049E35981B7049DFECAC7
                                                                                                                                                                                                                                  SHA1:15914110949D98A5FA65705E27F9C11DF9E3BAB6
                                                                                                                                                                                                                                  SHA-256:879839E906969AFBFAAED0EF4B58D0D4276D9B4C483DECC883FE6B63BD9B67AD
                                                                                                                                                                                                                                  SHA-512:448272FD92A9CA6AD2DA7A156F7872E2F61EF7E7AF210C61893D4103960186EAC9118F4D8B123E8A4D953E35BF607EF13F2D46A9553F395D3E131DB8D93C4E68
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......E./...AG..AG..AG...G..AG..@F..AG..DF..AG..EF..AG..BF..AG..@F..AGZ.@F..AGm.@F..AG..@G..AG..LF..AG..AF..AG...G..AG..CF..AGRich..AG........................PE..d....={_.........." .....v...j............................................... ......_F....`.............................................P...................................... .......T........................... ...0............................................text....u.......v.................. ..`.rdata..xB.......D...z..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc.. ...........................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):22032
                                                                                                                                                                                                                                  Entropy (8bit):6.112963736472455
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:58tVSkSEVs0+cE9pHgoIhHwbnYPLxDG4y8/PmY+bE:58Ams0K1goIhHwbWDG4y9YeE
                                                                                                                                                                                                                                  MD5:C9D5A1A4B6186B5AD1242E6C5CCA31E5
                                                                                                                                                                                                                                  SHA1:40C29C4B192AB421038D7BA2F407AD52BD0E1DC5
                                                                                                                                                                                                                                  SHA-256:EEC57D615873E2065ED83DA6164774B9396B4984AD39E1C2166F2C9B45626272
                                                                                                                                                                                                                                  SHA-512:A2A3AFD56350C7DE3CA55B105928ECEB8952E9BAC08AAF171EF6644D50385AFB836FC39ABD1D9B372E65EDFFF4C6E686A084DCD03231487B96F1674401CCA290
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............w...w...w....l..w.......w.......w.......w.......w..U....w.......w...w...w..U....w..U....w..U....w..U....w..Rich.w..................PE..d....={_.........." .........(......x................................................I....`......................................... 9..L...l9..x....`.......P..d....<.......p..8...L2..T............................2..0............0..p............................text............................... ..`.rdata..L....0......................@..@.data........@.......*..............@....pdata..d....P.......,..............@..@.rsrc........`.......0..............@..@.reloc..8....p.......:..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Zip archive data, at least v2.0 to extract, compression method=store
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):842166
                                                                                                                                                                                                                                  Entropy (8bit):5.476123832091116
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24576:YHkqBcmQcosQNRs54PK4ItaVwHEfVEzooE0I:YHkqBchcosQNRs54PK4IpG
                                                                                                                                                                                                                                  MD5:0116B133B247780E1B8FC8EDAF8FCE0D
                                                                                                                                                                                                                                  SHA1:DA680817FB02F1C521430DBD61B31974DD71C0AA
                                                                                                                                                                                                                                  SHA-256:57602253FDF8F8FE4E9522C70E6082CC148AA7220774EC92231241CC5AABC88B
                                                                                                                                                                                                                                  SHA-512:9BE4B7DF4F2786312D0F8F3F63AFBE8A121C39F08129351D6E55E6775AA5055CC6CF297A379469B655708B1888650DCA2AE317D8C716BD64CBA4314058874F1E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:PK..........!...=............_bootlocale.pyca....................................@....x...d.Z.d.d.l.Z.d.d.l.Z.e.j...d...r,d.d.d...Z.nHz.e.j...W.n2..e.yh......e.e.d...rZd.d.d...Z.n.d.d.d...Z.Y.n.0.d.d.d...Z.d.S.)...A minimal subset of the locale module used at interpreter startup.(imported by the _io module), in order to reduce startup time...Don't import directly from third-party code; use the `locale` module instead!......N..winTc....................C........t.j.j.r.d.S.t.....d...S.).N..UTF-8.........sys..flags..utf8_mode.._locale.._getdefaultlocale....do_setlocale..r......_bootlocale.py..getpreferredencoding...............r......getandroidapilevelc....................C........d.S.).Nr....r....r....r....r....r....r...............c....................C........t.j.j.r.d.S.d.d.l.}.|...|...S.).Nr....r......r....r....r......localer......r....r....r....r....r....r.....................c....................C....6...|.r.J...t.j.j.r.d.S.t...t.j...}.|.s2t.j.d.k.r2d.}.|.S.).Nr......darwin..r....
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):290282
                                                                                                                                                                                                                                  Entropy (8bit):6.048183244201235
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6144:QW1H/M8fRR1jplkXURrVADwYCuCigT/Q5MSRqNb7d8iu5Np:QWN/TRJLWURrI55MWavdF0L
                                                                                                                                                                                                                                  MD5:302B49C5F476C0AE35571430BB2E4AA0
                                                                                                                                                                                                                                  SHA1:35A7837A3F1B960807BF46B1C95EC22792262846
                                                                                                                                                                                                                                  SHA-256:CF9D37FA81407AFE11DCC0D70FE602561422AA2344708C324E4504DB8C6C5748
                                                                                                                                                                                                                                  SHA-512:1345AF52984B570B1FF223032575FEB36CDFB4F38E75E0BD3B998BC46E9C646F7AC5C583D23A70460219299B9C04875EF672BF5A0D614618731DF9B7A5637D0A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:.# Issuer: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Subject: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Label: "GlobalSign Root CA".# Serial: 4835703278459707669005204.# MD5 Fingerprint: 3e:45:52:15:09:51:92:e1:b7:5d:37:9f:b1:87:29:8a.# SHA1 Fingerprint: b1:bc:96:8b:d4:f4:9d:62:2a:a8:9a:81:f2:15:01:52:a4:1d:82:9c.# SHA256 Fingerprint: eb:d4:10:40:e4:bb:3e:c7:42:c9:e3:81:d3:1e:f2:a4:1a:48:b6:68:5c:96:e7:ce:f3:c1:df:6c:d4:33:1c:99.-----BEGIN CERTIFICATE-----.MIIDdTCCAl2gAwIBAgILBAAAAAABFUtaw5QwDQYJKoZIhvcNAQEFBQAwVzELMAkG.A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv.b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAw.MDBaFw0yODAxMjgxMjAwMDBaMFcxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i.YWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYDVQQDExJHbG9iYWxT.aWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDaDuaZ.jc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavp.xy0Sy6scTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4
                                                                                                                                                                                                                                  Entropy (8bit):1.5
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:Mn:M
                                                                                                                                                                                                                                  MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                                  SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                                  SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                                  SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:pip.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):197
                                                                                                                                                                                                                                  Entropy (8bit):4.61968998873571
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:hWDncJhByZmJgXPForADu1QjygQuaAJygT2d5GeWreLRuOFEXAYeBKmJozlMHuO:h9Co8FyQjkDYc5tWreLBF/pn2mH1
                                                                                                                                                                                                                                  MD5:8C3617DB4FB6FAE01F1D253AB91511E4
                                                                                                                                                                                                                                  SHA1:E442040C26CD76D1B946822CAF29011A51F75D6D
                                                                                                                                                                                                                                  SHA-256:3E0C7C091A948B82533BA98FD7CBB40432D6F1A9ACBF85F5922D2F99A93AE6BB
                                                                                                                                                                                                                                  SHA-512:77A1919E380730BCCE5B55D76FBFFBA2F95874254FAD955BD2FE1DE7FC0E4E25B5FDAAB0FEFFD6F230FA5DC895F593CF8BFEDF8FDC113EFBD8E22FADAB0B8998
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:This software is made available under the terms of *either* of the licenses.found in LICENSE.APACHE or LICENSE.BSD. Contributions to cryptography are made.under the terms of *both* these licenses..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):11360
                                                                                                                                                                                                                                  Entropy (8bit):4.426756947907149
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:nUDG5KXSD9VYUKhu1JVF9hFGvV/QiGkS594drFjuHYx5dvTrLh3kTSEnQHbHR:UIvlKM1zJlFvmNz5VrlkTS0QHt
                                                                                                                                                                                                                                  MD5:4E168CCE331E5C827D4C2B68A6200E1B
                                                                                                                                                                                                                                  SHA1:DE33EAD2BEE64352544CE0AA9E410C0C44FDF7D9
                                                                                                                                                                                                                                  SHA-256:AAC73B3148F6D1D7111DBCA32099F68D26C644C6813AE1E4F05F6579AA2663FE
                                                                                                                                                                                                                                  SHA-512:F451048E81A49FBFA11B49DE16FF46C52A8E3042D1BCC3A50AAF7712B097BED9AE9AED9149C21476C2A1E12F1583D4810A6D36569E993FE1AD3879942E5B0D52
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:. Apache License. Version 2.0, January 2004. https://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial ow
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1532
                                                                                                                                                                                                                                  Entropy (8bit):5.058591167088024
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:MjUnoorbOFFTJJyRrYFTjzMbmqEvBTP4m96432s4EOkUTKQROJ32s3yxsITf+3tY:MkOFJSrYJsaN5P406432svv32s3EsIqm
                                                                                                                                                                                                                                  MD5:5AE30BA4123BC4F2FA49AA0B0DCE887B
                                                                                                                                                                                                                                  SHA1:EA5B412C09F3B29BA1D81A61B878C5C16FFE69D8
                                                                                                                                                                                                                                  SHA-256:602C4C7482DE6479DD2E9793CDA275E5E63D773DACD1ECA689232AB7008FB4FB
                                                                                                                                                                                                                                  SHA-512:DDBB20C80ADBC8F4118C10D3E116A5CD6536F72077C5916D87258E155BE561B89EB45C6341A1E856EC308B49A4CB4DBA1408EABD6A781FBE18D6C71C32B72C41
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Copyright (c) Individual contributors..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:.. 1. Redistributions of source code must retain the above copyright notice,. this list of conditions and the following disclaimer... 2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... 3. Neither the name of PyCA Cryptography nor the names of its contributors. may be used to endorse or promote products derived from this software. without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOS
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5292
                                                                                                                                                                                                                                  Entropy (8bit):5.115440205505611
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:DxapqZink/QIHQIyzQIZQILuQIR8vtklGovxNx6sWwCvCCcTKvIrrg9BMM6VwDjz:sJnkoBs/sqLz8cTKvIrrUiM6VwDjyeWs
                                                                                                                                                                                                                                  MD5:137D13F917D94C83137A0FA5AE12B467
                                                                                                                                                                                                                                  SHA1:01E93402C225BF2A4EE59F9A06F8062CB5E4801E
                                                                                                                                                                                                                                  SHA-256:36738E6971D2F20DB78433185A0EF7912A48544AA6FF7006505A7DC785158859
                                                                                                                                                                                                                                  SHA-512:1B22CBC6E22FA5E2BD5CC4A370443A342D00E7DD53330A4000E9A680DE80262BCA7188764E3568944D01025188291602AC8C53C971630984FBD9FA7D75AAB124
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Metadata-Version: 2.1..Name: cryptography..Version: 41.0.7..Summary: cryptography is a package which provides cryptographic recipes and primitives to Python developers...Author-email: The Python Cryptographic Authority and individual contributors <cryptography-dev@python.org>..License: Apache-2.0 OR BSD-3-Clause..Project-URL: homepage, https://github.com/pyca/cryptography..Project-URL: documentation, https://cryptography.io/..Project-URL: source, https://github.com/pyca/cryptography/..Project-URL: issues, https://github.com/pyca/cryptography/issues..Project-URL: changelog, https://cryptography.io/en/latest/changelog/..Classifier: Development Status :: 5 - Production/Stable..Classifier: Intended Audience :: Developers..Classifier: License :: OSI Approved :: Apache Software License..Classifier: License :: OSI Approved :: BSD License..Classifier: Natural Language :: English..Classifier: Operating System :: MacOS :: MacOS X..Classifier: Operating System :: POSIX..Classifier: Operating Syst
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:CSV text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):15262
                                                                                                                                                                                                                                  Entropy (8bit):5.551588665133054
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:3X6WU/ZfaigT+qJN5S60lz8R7dx6uvnpLEA:3dUxfz41txEA
                                                                                                                                                                                                                                  MD5:8670BA38E14A292198EB2A980CC5E3BF
                                                                                                                                                                                                                                  SHA1:0718CDAC8B365DCDFD4F6E17050806FFCB6545FC
                                                                                                                                                                                                                                  SHA-256:57C47616B601C0746BB999BBE68607A709D9C95322C71816373573B265F76205
                                                                                                                                                                                                                                  SHA-512:A6EEA3C49D21EF922F38CA5A8A99E517D5A19B28E20549831EED23C5773B06E2641438880B6CCEDD6982D606450021F4E5308A25F5D305E00BCDC7E60D818F41
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:cryptography-41.0.7.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..cryptography-41.0.7.dist-info/LICENSE,sha256=Pgx8CRqUi4JTO6mP18u0BDLW8amsv4X1ki0vmak65rs,197..cryptography-41.0.7.dist-info/LICENSE.APACHE,sha256=qsc7MUj20dcRHbyjIJn2jSbGRMaBOuHk8F9leaomY_4,11360..cryptography-41.0.7.dist-info/LICENSE.BSD,sha256=YCxMdILeZHndLpeTzaJ15eY9dz2s0eymiSMqtwCPtPs,1532..cryptography-41.0.7.dist-info/METADATA,sha256=NnOOaXHS8g23hDMYWg73kSpIVEqm_3AGUFp9x4UViFk,5292..cryptography-41.0.7.dist-info/RECORD,,..cryptography-41.0.7.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..cryptography-41.0.7.dist-info/WHEEL,sha256=-EX5DQzNGQEoyL99Q-0P0-D-CXbfqafenaAeiSQ_Ufk,100..cryptography-41.0.7.dist-info/top_level.txt,sha256=KNaT-Sn2K4uxNaEbe6mYdDn3qWDMlp4y-MtWfB73nJc,13..cryptography/__about__.py,sha256=uPXMbbcptt7EzZ_jllGRx0pVdMn-NBsAM4L74hOv-b0,445..cryptography/__init__.py,sha256=iVPlBlXWTJyiFeRedxcbMPhyHB34viOM10d72vGnWuE,364..cryptography/__pycache__/_
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):100
                                                                                                                                                                                                                                  Entropy (8bit):5.0203365408149025
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:RtEeX7MWcSlVlbY3KgP+tkKc/SKQLn:RtBMwlVCxWKxDQLn
                                                                                                                                                                                                                                  MD5:4B432A99682DE414B29A683A3546B69F
                                                                                                                                                                                                                                  SHA1:F59C5016889EE5E9F62D09B22AEFBC2211A56C93
                                                                                                                                                                                                                                  SHA-256:F845F90D0CCD190128C8BF7D43ED0FD3E0FE0976DFA9A7DE9DA01E89243F51F9
                                                                                                                                                                                                                                  SHA-512:CBBF10E19B6F4072C416EA95D7AE259B9C5A1B89068B7B6660B7C637D6F2437AEA8D8202A2E26A0BEC36DAECD8BBB6B59016FC2DDEB13C545F0868B3E15479CA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.42.0).Root-Is-Purelib: false.Tag: cp37-abi3-win_amd64..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):13
                                                                                                                                                                                                                                  Entropy (8bit):3.2389012566026314
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:cOv:Nv
                                                                                                                                                                                                                                  MD5:E7274BD06FF93210298E7117D11EA631
                                                                                                                                                                                                                                  SHA1:7132C9EC1FD99924D658CC672F3AFE98AFEFAB8A
                                                                                                                                                                                                                                  SHA-256:28D693F929F62B8BB135A11B7BA9987439F7A960CC969E32F8CB567C1EF79C97
                                                                                                                                                                                                                                  SHA-512:AA6021C4E60A6382630BEBC1E16944F9B312359D645FC61219E9A3F19D876FD600E07DCA6932DCD7A1E15BFDEAC7DBDCEB9FFFCD5CA0E5377B82268ED19DE225
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:cryptography.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6673920
                                                                                                                                                                                                                                  Entropy (8bit):6.582002531606852
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:98304:EzN+T+xtLlk0PPMAiGoTzeDy3x8lGBlWi9Nk:E5Y6Jk0PPMtfTzp3x8c
                                                                                                                                                                                                                                  MD5:486085AAC7BB246A173CEEA0879230AF
                                                                                                                                                                                                                                  SHA1:EF1095843B2A9C6D8285C7D9E8E334A9CE812FAE
                                                                                                                                                                                                                                  SHA-256:C3964FC08E4CA8BC193F131DEF6CC4B4724B18073AA0E12FED8B87C2E627DC83
                                                                                                                                                                                                                                  SHA-512:8A56774A08DA0AB9DD561D21FEBEEBC23A5DEA6F63D5638EA1B608CD923B857DF1F096262865E6EBD56B13EFD3BBA8D714FFDCE8316293229974532C49136460
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......QN.../.../.../...W(../......./......./......./......./...R.../...Z.../..^W.../.../...-../...",......./.../.../......./......./..Rich./..........PE..d...M7ee.........." ...&..M..........L...................................... f...........`......................................... .a.p.....a.|............Pb..............Pe.p...p.[.T.....................[.(...0.[.@............0M..............................text.....M.......M................. ..`.rdata.......0M.......M.............@..@.data........0a.......a.............@....pdata.......Pb.......b.............@..@.reloc..p....Pe.......e.............@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6756
                                                                                                                                                                                                                                  Entropy (8bit):4.965960355988947
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:cHqnQbu/POjcEYIL9GE6AUmZris46/B5aVOQOo2/nH/h5M966GMBWtReWE3uSI8G:2qQSOjIKtc6/Bb/H/h2BWtc93k
                                                                                                                                                                                                                                  MD5:EAB99B31F1FD18E46E6E081BA3B5C06E
                                                                                                                                                                                                                                  SHA1:9CA76B1097D58EF9C652AEBFBEFF32BFEC17B25B
                                                                                                                                                                                                                                  SHA-256:B05B8000C71987CD4DF824C1ED134B7FCD34617665E437B1AAEC128F93D7F1C3
                                                                                                                                                                                                                                  SHA-512:7C4EA4A28F7876249B503155187BD59BCD9CF18A80264C8892E59E9FD7F3D461C91AFC4C3C177DBA48E1DFDD0FEB5705B54B504F7DAA886A2A0B72FDDD1E80FC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:'''..OpenCV Python binary extension loader..'''..import os..import importlib..import sys....__all__ = []....try:.. import numpy.. import numpy.core.multiarray..except ImportError:.. print('OpenCV bindings requires "numpy" package.').. print('Install it via command:').. print(' pip install numpy').. raise....# TODO..# is_x64 = sys.maxsize > 2**32......def __load_extra_py_code_for_module(base, name, enable_debug_print=False):.. module_name = "{}.{}".format(__name__, name).. export_module_name = "{}.{}".format(base, name).. native_module = sys.modules.pop(module_name, None).. try:.. py_module = importlib.import_module(module_name).. except ImportError as err:.. if enable_debug_print:.. print("Can't load Python code for module:", module_name,.. ". Reason:", err).. # Extension doesn't contain extra py code.. return False.... if not hasattr(base, name):.. setattr(sys.modules[base], name, py_
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):748
                                                                                                                                                                                                                                  Entropy (8bit):5.110506159030977
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:WSolITEO+RNIdjcFMlYFXe2LirYKMLFxAe5bHMnQBwmuTD9+sXWeZKMLFxAe5biw:MlY+34jamr0L7Ae5oJP9+oJL7Ae5mU9L
                                                                                                                                                                                                                                  MD5:E8ED8F25854821C8910BCB8308507DCE
                                                                                                                                                                                                                                  SHA1:8A3AC32D3DF44794E8A834A6B6A8A1ED3F3AA5F7
                                                                                                                                                                                                                                  SHA-256:DE28C7B5213CCA148F09469916584611B3D66C1C8C432880259D6A3A92380213
                                                                                                                                                                                                                                  SHA-512:F3F36EDF288A870F5E1F14F3B1113031721E12F30BF235B0E5385711E2BF7F08D0123E6AB14600AB069D2E692D81B7ABC3692FB69EED34374FEFAB3B24F03D86
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:PYTHON_EXTENSIONS_PATHS = [.. LOADER_DIR..] + PYTHON_EXTENSIONS_PATHS....ci_and_not_headless = False....try:.. from .version import ci_build, headless.... ci_and_not_headless = ci_build and not headless..except:.. pass....# the Qt plugin is included currently only in the pre-built wheels..if sys.platform.startswith("linux") and ci_and_not_headless:.. os.environ["QT_QPA_PLATFORM_PLUGIN_PATH"] = os.path.join(.. os.path.dirname(os.path.abspath(__file__)), "qt", "plugins".. )....# Qt will throw warning on Linux if fonts are not found..if sys.platform.startswith("linux") and ci_and_not_headless:.. os.environ["QT_QPA_FONTDIR"] = os.path.join(.. os.path.dirname(os.path.abspath(__file__)), "qt", "fonts".. )..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):123
                                                                                                                                                                                                                                  Entropy (8bit):5.165836377533827
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:JSxrsr+A6+Ei7/erj5Erj+7IE3KTY5O8nkz6+Eov:arsrFEoidAM3Kk5PkBEy
                                                                                                                                                                                                                                  MD5:FCB98FFC6E408D714FC0E0555B1FB530
                                                                                                                                                                                                                                  SHA1:832A187368BED379942A0A6EF77D8057166DF7F6
                                                                                                                                                                                                                                  SHA-256:D9E401B9A67304D69C48A494A485D106B534E02BF5776211C09F09BD671B295D
                                                                                                                                                                                                                                  SHA-512:C679EB68F62D4D4361FB55BE7B052FCD3AD85BFF9DFE9ED27AFD7014C992F26851BF02E7A587AA411D08593C69A197603FAD685E976D2948F35240D5F87DC3F8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:import os....BINARIES_PATHS = [.. os.path.join(os.path.join(LOADER_DIR, '../../'), 'x64/vc14/bin')..] + BINARIES_PATHS..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):74447872
                                                                                                                                                                                                                                  Entropy (8bit):6.7006581120600375
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:393216:XZyc70qJvslvVpbgSnsQqVP7i4iA6zMMX5djMTLiAUhf1NefxzoWuDPpybh:Xen9JDMxzolpyN
                                                                                                                                                                                                                                  MD5:E758DF0FBF045DF49D75CB4463287BF2
                                                                                                                                                                                                                                  SHA1:33FEBB0F392A47BCA1197927E2581BFBD4647C96
                                                                                                                                                                                                                                  SHA-256:90577FA7AD4D992CB7FD16DFB1F36E7220A67B00A6E9C408ECB1C2331265F67F
                                                                                                                                                                                                                                  SHA-512:D0AFAFB2B319DFC4FF5B946EF4EFC3AE943E4055DDC37FDD9107CE29993FBB2C928CD88E380181954580FC6AD958B3AB97D4942DF57C9508878E89DFA057FE3A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$............x..x..x...%...x...%...x...%..3x......x..%&...x..%&...x..%&...x...%...x......{..x...[...%...x..?&..lx.."&...x..x...y..?&..bz..?&...x..?&=.x..?&...x..Rich.x..................PE..d...YP.e.........." .....fD..B=..............................................P............`...........................................:.d1....<.@.............Z.8...............\{..pV..T...................hW..(....V................D..............................text...t".......$.................. ..`IPPCODE.>A...@...B...*.............. ..`.rdata.. e....D..f...lD.............@..@.data... .....=.......<.............@....pdata..8.....Z.......H.............@..@.tls.........@t......Rb.............@...IPPDATA..M...Pt..N...Tb.............@....gfids..h.....t.......b.............@..@_RDATA........t.......b.............@..@.debug_a2....pv......\d.............@..B.debug_i0.....v......bd.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):73
                                                                                                                                                                                                                                  Entropy (8bit):4.5164686969838375
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:JSxrGSCcurj5ErAwGfnJFB:arGSLSdAAb
                                                                                                                                                                                                                                  MD5:734F2F32C81B5CEDE1098394DAB581B5
                                                                                                                                                                                                                                  SHA1:E07450D3F1924078DD09E0B1DEA8DD671DFE8801
                                                                                                                                                                                                                                  SHA-256:F4CE16721ED7F623A4DCC443BA600D1856DB610CB2C3D53C13A8CA028CC68F6D
                                                                                                                                                                                                                                  SHA-512:C0C9ADD6A1CD47F34C91B12AD369E887CFD28859824D258E1EED0C3495378DD950E214F8A540D66CD555ED8EFC810418DF3F13E09765D24D6FA26B09B44857C0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:import os....haarcascades = os.path.join(os.path.dirname(__file__), "")..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10621
                                                                                                                                                                                                                                  Entropy (8bit):4.717526275196451
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:mIntUjnLP6P7B4D7BP7Bb7BewmDraPt0C2Vqed/:m2eBNYraPt0C2V9Z
                                                                                                                                                                                                                                  MD5:3A4D80801F49E3A13903811C9E59018A
                                                                                                                                                                                                                                  SHA1:0227B9F1FB7E900777BD8951404075DF2D6D3447
                                                                                                                                                                                                                                  SHA-256:74F5FD2A142A31B0A4707B70C0BE3637F0FBF8A940EEC4372E7BA87E5A5CEDB8
                                                                                                                                                                                                                                  SHA-512:F79D2C216008FE8EC1F9C28575776C81B5FAC63B18996803B76B73EAF088800FE4E46B4C18F7CE9730177549FD5402421719FA2B8FFED73EE60EBACAE4D5CCB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:__all__ = ['op', 'kernel']....import sys..import cv2 as cv....# NB: Register function in specific module..def register(mname):.. def parameterized(func):.. sys.modules[mname].__dict__[func.__name__] = func.. return func.. return parameterized......@register('cv2.gapi')..def networks(*args):.. return cv.gapi_GNetPackage(list(map(cv.detail.strip, args)))......@register('cv2.gapi')..def compile_args(*args):.. return list(map(cv.GCompileArg, args))......@register('cv2')..def GIn(*args):.. return [*args]......@register('cv2')..def GOut(*args):.. return [*args]......@register('cv2')..def gin(*args):.. return [*args]......@register('cv2.gapi')..def descr_of(*args):.. return [*args]......@register('cv2')..class GOpaque():.. # NB: Inheritance from c++ class cause segfault... # So just aggregate cv.GOpaqueT instead of inheritance.. def __new__(cls, argtype):.. return cv.GOpaqueT(argtype).... class Bool():.. def __new__(self):..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):271
                                                                                                                                                                                                                                  Entropy (8bit):4.627093215673309
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SoSvYFyMXS/qdadew7mZ6ALNCpvdYZ4un:kUFuT7mZlCpFw4u
                                                                                                                                                                                                                                  MD5:EED4002FFE913424133D8F19FDF1C2A8
                                                                                                                                                                                                                                  SHA1:F232D4C5ACF73885D8E0D70418FB2E1481D9271B
                                                                                                                                                                                                                                  SHA-256:FF583A5874BE8F848E73C2F61B3A71680995926479C9BC436E6565C5CCE7CA07
                                                                                                                                                                                                                                  SHA-512:115F32B21E99DEC9B50C766CC685F9387A0D0C1611A41540CA23B71579E2963E04A1E940C6C8F3447A26006DBC45F17013A7FFE97BE620B74F1CF20A21505B8E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# flake8: noqa..import os..import sys....if sys.version_info[:2] >= (3, 0):.. def exec_file_wrapper(fpath, g_vars, l_vars):.. with open(fpath) as f:.. code = compile(f.read(), os.path.basename(fpath), 'exec').. exec(code, g_vars, l_vars)..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1138
                                                                                                                                                                                                                                  Entropy (8bit):4.943391541348593
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:7TYCO6HEqbPo5d1i0N0QhKNAhno3oBoIVbOXono6RnZB:gKkLdzN0QhKNuniM5iC/r
                                                                                                                                                                                                                                  MD5:12A5274D62FDACE8465D52F6216676EC
                                                                                                                                                                                                                                  SHA1:EA9F4F5C2BE9527B825D6B38C0DC4BF8DB5965DF
                                                                                                                                                                                                                                  SHA-256:FB87662AFF127BA738E73C04AE3DF9CEE5B02F3C64BCC3EAAABEEC68FF16EF8A
                                                                                                                                                                                                                                  SHA-512:502744A0C9B22437F9D0C0D9CD4019C08DD913ED2A50B6C60A6776B8F4720DF5CF1EBAC6AFFB9553FE89FB5C8CDD635576D301F76AA34C09EF4D6A35026F394C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:__all__ = []....import numpy as np..import cv2 as cv..from typing import TYPE_CHECKING, Any....# Same as cv2.typing.NumPyArrayGeneric, but avoids circular dependencies..if TYPE_CHECKING:.. _NumPyArrayGeneric = np.ndarray[Any, np.dtype[np.generic]]..else:.. _NumPyArrayGeneric = np.ndarray....# NumPy documentation: https://numpy.org/doc/stable/user/basics.subclassing.html....class Mat(_NumPyArrayGeneric):.. '''.. cv.Mat wrapper for numpy array..... Stores extra metadata information how to interpret and process of numpy array for underlying C++ code... '''.... def __new__(cls, arr, **kwargs):.. obj = arr.view(Mat).. return obj.... def __init__(self, arr, **kwargs):.. self.wrap_channels = kwargs.pop('wrap_channels', getattr(arr, 'wrap_channels', False)).. if len(kwargs) > 0:.. raise TypeError('Unknown parameters: {}'.format(repr(kwargs))).... def __array_finalize__(self, obj):.. if obj is None:.. return..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):38
                                                                                                                                                                                                                                  Entropy (8bit):3.968211974414884
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:1LT2QbQNQ4yL9v:1LT2Q8NQ4yJ
                                                                                                                                                                                                                                  MD5:C6B0244719659C5EDEC0592AF112032A
                                                                                                                                                                                                                                  SHA1:6BD926FE0C853A9938BDB5D9537BD88FD1EF5401
                                                                                                                                                                                                                                  SHA-256:495BD79594CCE174673E372C85C4DD8F4FFDF2B3A73FD4623955B0D55DE0D462
                                                                                                                                                                                                                                  SHA-512:28D80015309AC1AE19F048E9461D4D04B85CE16B9E68C58D7608351A39B8D3EC0235FCCFD928B0349082C702D890B6C6ABD36B8030A176BF05888AE8C493B545
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:from .version import get_ocv_version..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):95
                                                                                                                                                                                                                                  Entropy (8bit):4.525707419533802
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:JS4iydoKE4yLYfg+4zxNG364yLA9E5HJwv:mIXE4y0YpE6405pwv
                                                                                                                                                                                                                                  MD5:2D3125F1843A670B9F3229A7BC362816
                                                                                                                                                                                                                                  SHA1:E884BC3D05E5E732D1308DE67AA5F96BBF4FC69F
                                                                                                                                                                                                                                  SHA-256:C93A418793FCB15B9B4316C0741B8336740E490E94F3B7D1EBE8CD5F6F23815C
                                                                                                                                                                                                                                  SHA-512:BFDCF6BFC1D82E3ACAF625B5940CA169784427712F14895FD6CA92CC9C864F1A894FECF97BF2AFA6FC5CF4ABA9738A302D30024BC192F85025989C0D93A8B540
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:import cv2......def get_ocv_version():.. return getattr(cv2, "__version__", "unavailable")..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):26314752
                                                                                                                                                                                                                                  Entropy (8bit):6.591317626319441
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:196608:4WuFNpujlgPA/ujrrZSmB/vb3ty2vKqNn93NN6Yy2fR5yWoVx:4LvujlNujrrZ3vrLnp76Yy2psWWx
                                                                                                                                                                                                                                  MD5:CB4DB51EE9A423E6168B9D08BEE61EFC
                                                                                                                                                                                                                                  SHA1:C4D4CEEF485F76EF33780AE9CB7D636BC8C09539
                                                                                                                                                                                                                                  SHA-256:969A3219854B6B654A7E5A89CCDB87F3CC143AF5E43858EEA0AD9275237EA406
                                                                                                                                                                                                                                  SHA-512:37D239A7A1171EDA91351FFF0A076B3A38249F2D40849EBF4B5F9302CA44F4B34144F318A422F419F3F89B2EE81BEE3757AA1D979C90FD1F90001FC9B082D4D6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."..."..A......n..P..........p.....................................&........ .................................................p*...P..8.......D............`..................................(...................L................................text.....A.......A.................`.P`.data........0A.......A.............@.`..rdata..p.>...F...>...E.............@..@.rodata............................@.P@.pdata..D..........................@.0@.xdata...............x..............@.0@.bss.....l............................`..edata...............<..............@.0@.idata..p*.......,...>..............@.0..CRT....`....0.......j..............@.@..tls.........@.......l..............@.@..rsrc...8....P.......n..............@.0..reloc.......`.......r..............@.0B........................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5312
                                                                                                                                                                                                                                  Entropy (8bit):5.151212669340542
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:c9ACTXc/yidAKdpJktF8O7wDpHGN5RME0Kdc:c3zji+KI+RcRME0N
                                                                                                                                                                                                                                  MD5:463A64D02EC0FCDE83ACD069B3A1CE99
                                                                                                                                                                                                                                  SHA1:76AA3B96BB58848C2E1262CE4C08809F931635D0
                                                                                                                                                                                                                                  SHA-256:22388B3F92EE622782C38FD278296520742955B9D09BF51F128904D7B5519898
                                                                                                                                                                                                                                  SHA-512:E621A22CF65D93920DE97FCD6C43F8FA46986081C7B303A6F75EF97B3C60AE134B75FDDAE4B3FA18736AE5949F743CD284E811ED98C62119D7DC81DD3F41B1CD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:__all__ = [.. "IntPointer",.. "MatLike",.. "MatShape",.. "Size",.. "Size2f",.. "Scalar",.. "Point",.. "Point2i",.. "Point2f",.. "Point2d",.. "Point3i",.. "Point3f",.. "Point3d",.. "Range",.. "Rect",.. "Rect2i",.. "Rect2d",.. "Moments",.. "RotatedRect",.. "TermCriteria",.. "Vec2i",.. "Vec2f",.. "Vec2d",.. "Vec3i",.. "Vec3f",.. "Vec3d",.. "Vec4i",.. "Vec4f",.. "Vec4d",.. "Vec6f",.. "FeatureDetector",.. "DescriptorExtractor",.. "FeatureExtractor",.. "GProtoArg",.. "GProtoInputArgs",.. "GProtoOutputArgs",.. "GRunArg",.. "GOptRunArg",.. "GMetaArg",.. "Prim",.. "Matx33f",.. "Matx33d",.. "Matx44f",.. "Matx44d",.. "GTypeInfo",.. "ExtractArgsCallback",.. "ExtractMetaCallback",.. "LayerId",.. "IndexParams",.. "SearchParams",.. "map_string_and_string",.. "map_string_and_int",.. "map_string_and_vector_size_t",.. "map_string_and_vector_flo
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Python script, ASCII text executable, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):344
                                                                                                                                                                                                                                  Entropy (8bit):4.438685267245838
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:1zBhJDyTH2XE2OTH2XRxEMGMBrMhWcROEoiZAIfH2Xc10F9vSumHcROEoiZWf:1zBHyLkOLejrMYccRIfh0FNSfcct
                                                                                                                                                                                                                                  MD5:952D77A31C0171AE90C0086AA8E3FCC7
                                                                                                                                                                                                                                  SHA1:000D22FD5A2545CEFBBF294D63415E82E232820A
                                                                                                                                                                                                                                  SHA-256:2B16990B35B569AF1CA7239DC10F7B24EC62F27A46626B1E2F1271D2E1AA3554
                                                                                                                                                                                                                                  SHA-512:36E5BEA12CDF8AE29D737F7062923AE4A1DBDB2C98904F9A35559222119FAFA836C4A7553F5CD9F5639043183155F5E93DFE731EBCF385349A8E4CA72D2E92B6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:from collections import namedtuple....import cv2......NativeMethodPatchedResult = namedtuple("NativeMethodPatchedResult",.. ("py", "native"))......def testOverwriteNativeMethod(arg):.. return NativeMethodPatchedResult(.. arg + 1,.. cv2.utils._native.testOverwriteNativeMethod(arg).. )..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):96
                                                                                                                                                                                                                                  Entropy (8bit):4.586374127148575
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:K2T2Q5Lh4eEi+gI/aIysi+gIgZPGXV:K2TbVh4eIgMaDR1CV
                                                                                                                                                                                                                                  MD5:FC16A0FD28A5C2C13D29AE4858551AB5
                                                                                                                                                                                                                                  SHA1:012E90A5403FA22C9D5D62C558871758313E9186
                                                                                                                                                                                                                                  SHA-256:526DE7A7E12808572EC8EE66473282958DEB5ACF419CC9B17220330DFB4D62B8
                                                                                                                                                                                                                                  SHA-512:708384970CD9A388D8A6C50B84DA9EF13BC1BCAF7DB24995D459044BFCCC2B3FAE251C32E0F0CC125F18D26CBCFB0E8CC3F94DCDE754BE6B3C6B642946400C96
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:opencv_version = "4.9.0.80"..contrib = False..headless = False..rolling = False..ci_build = True
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3399200
                                                                                                                                                                                                                                  Entropy (8bit):6.094152840203032
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:98304:R3+YyRoAK2rXHsoz5O8M1CPwDv3uFh+r:t9yWAK2zsozZM1CPwDv3uFh+r
                                                                                                                                                                                                                                  MD5:CC4CBF715966CDCAD95A1E6C95592B3D
                                                                                                                                                                                                                                  SHA1:D5873FEA9C084BCC753D1C93B2D0716257BEA7C3
                                                                                                                                                                                                                                  SHA-256:594303E2CE6A4A02439054C84592791BF4AB0B7C12E9BBDB4B040E27251521F1
                                                                                                                                                                                                                                  SHA-512:3B5AF9FBBC915D172648C2B0B513B5D2151F940CCF54C23148CD303E6660395F180981B148202BEF76F5209ACC53B8953B1CB067546F90389A6AA300C1FBE477
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............K..K..K..;K..K...J..K...J..K...J..K...J..K...J..K..Kb.Kd..J..Kd..J..Kd..J..Kd.WK..Kd..J..KRich..K........................PE..d......^.........." .....R$..........r.......................................`4......~4...`.........................................`...hg...3.@.....3.|.....1.......3. .....3..O...m,.8............................m,...............3..............................text...GQ$......R$................. ..`.rdata.......p$......V$.............@..@.data....z...P1..,...41.............@....pdata..P.....1......`1.............@..@.idata...#....3..$....3.............@..@.00cfg........3......@3.............@..@.rsrc...|.....3......B3.............@..@.reloc..fx....3..z...J3.............@..B................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):32792
                                                                                                                                                                                                                                  Entropy (8bit):6.3566777719925565
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:2nypDwZH1XYEMXvdQOsNFYzsQDELCvURDa7qscTHstU0NsICwHLZxXYIoBneEAR8:2l0Vn5Q28J8qsqMttktDxOpWDG4yKRF
                                                                                                                                                                                                                                  MD5:EEF7981412BE8EA459064D3090F4B3AA
                                                                                                                                                                                                                                  SHA1:C60DA4830CE27AFC234B3C3014C583F7F0A5A925
                                                                                                                                                                                                                                  SHA-256:F60DD9F2FCBD495674DFC1555EFFB710EB081FC7D4CAE5FA58C438AB50405081
                                                                                                                                                                                                                                  SHA-512:DC9FF4202F74A13CA9949A123DFF4C0223DA969F49E9348FEAF93DA4470F7BE82CFA1D392566EAAA836D77DDE7193FED15A8395509F72A0E9F97C66C0A096016
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......6.3.r}]Ar}]Ar}]A{..Ap}]A .\@p}]A..\@q}]Ar}\AU}]A .X@~}]A .Y@z}]A .^@q}]A..Y@t}]A..^@s}]A..]@s}]A.._@s}]ARichr}]A........................PE..d......].........." .....F...$.......I....................................................`..........................................j.......m..P....................f...............b...............................b...............`.. ............................text....D.......F.................. ..`.rdata..H....`.......J..............@..@.data................^..............@....pdata...............`..............@..@.reloc...............d..............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):689184
                                                                                                                                                                                                                                  Entropy (8bit):5.526574117413294
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12288:1SurcFFRd4l6NCNH98PikxqceDotbA/nJspatQM5eJpAJfeMw4o8s6U2lvz:1KWZH98PiRLsAtf8AmMHogU2lvz
                                                                                                                                                                                                                                  MD5:BC778F33480148EFA5D62B2EC85AAA7D
                                                                                                                                                                                                                                  SHA1:B1EC87CBD8BC4398C6EBB26549961C8AAB53D855
                                                                                                                                                                                                                                  SHA-256:9D4CF1C03629F92662FC8D7E3F1094A7FC93CB41634994464B853DF8036AF843
                                                                                                                                                                                                                                  SHA-512:80C1DD9D0179E6CC5F33EB62D05576A350AF78B5170BFDF2ECDA16F1D8C3C2D0E991A5534A113361AE62079FB165FFF2344EFD1B43031F1A7BFDA696552EE173
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......E......T...T...T...T...TS.U...TZ.U...TS.U...TS.U...TS.U...T..U...T...T.T..U-..T..U...T..uT...T..U...TRich...T........PE..d......^.........." .....(...H.......%..............................................H.....`..............................................N..85..........s........K...j.. .......L.......8............................................ ..8............................text....&.......(.................. ..`.rdata...%...@...&...,..............@..@.data...!M...p...D...R..............@....pdata..TT.......V..................@..@.idata...V... ...X..................@..@.00cfg...............D..............@..@.rsrc...s............F..............@..@.reloc..5............N..............@..B................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):38168576
                                                                                                                                                                                                                                  Entropy (8bit):6.305082264196138
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:196608:O99XmuJ2l6d6iET5BH6ZCy1iMq5NV2OzPWJAt+bOzPWVa+llOzPWIqzfr2V9EwS6:0OzPW5OzPW5OzPWIDMD9K6LSn1ZP
                                                                                                                                                                                                                                  MD5:5E46C3D334C90C3029EB6AE2A3FE58F2
                                                                                                                                                                                                                                  SHA1:AD3D806F720289CCB90CE8BFD0DA49FA99E7777B
                                                                                                                                                                                                                                  SHA-256:57B87772BF676B5C2D718C79DDDC9F039D79EC3319FEE1398CC305ADFF7B69E5
                                                                                                                                                                                                                                  SHA-512:4BD29D19B619076A64A928F3871EDCCE8416BCF100C1AA1250932479D6536D9497F2F9A2668C90B3479D0D4AB4234FFA06F81BC6B107FAD1BE5097FA2B60AB28
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......e.D........& ...$.....x......P.........{..............................`........F...`... ......................................P..Xe...................p...$...............V.............................(...................|...P............................text...............................`..`.data....,..........................@.`..rdata...L... ...N..................@.p@.pdata...$...p...&...X..............@.0@.xdata..p#.......$...~..............@.0@.bss.....~............................`..edata..Xe...P...f..................@.0@.idata..............................@.0..CRT....`............"..............@.@..tls.................$..............@.@..reloc...V.......X...&..............@.0B/4...... ....`.......~..............@.PB/19.....Y....p......................@..B/31......_...P...`...`..............@..B/45.................................@..B/57.....
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):65024
                                                                                                                                                                                                                                  Entropy (8bit):5.994058285005393
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:NVKE5GHks9RpvRcvSDGbVPEH5YyCOawtvneP2FGsKuKgPEhmCyxF72a:NVteLpaVsH97tveP2FC5gbCGFv
                                                                                                                                                                                                                                  MD5:46A229F9C54C0F0211325DCC3826ACA9
                                                                                                                                                                                                                                  SHA1:E746610BA4DAD9CC9E731655104FA5B017CED543
                                                                                                                                                                                                                                  SHA-256:7DFF04E2A5BF5EA15535B897DB792BF3B7AD1591FEA919C15B4E9DBD4C5F67C6
                                                                                                                                                                                                                                  SHA-512:21DCB83213802082FD266E7634DFE5933DEF4BDF964B32C8769B75063AF763D9DB0000B7ED34327D9D3B46572BDE70492D6000E2380849436878F37646BC2BCC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........T..............................................@.......6....`.........................................0........................ ...............0......P...............................p...8............... ............................text.............................. .P`.rdata..29.......:..................@.P@.data...............................@.P..pdata....... ......................@.0@.reloc.......0......................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2834432
                                                                                                                                                                                                                                  Entropy (8bit):6.6311576070873945
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:49152:YZrpn16VCAjPsYazDMjycgtQBAUZzo4qCY4zl+vKdB+K:YZBAjO/Uup2+vKdp
                                                                                                                                                                                                                                  MD5:F5604FE675F54E081A2E522461371670
                                                                                                                                                                                                                                  SHA1:5430BD0FE7AB9ABAB2BA657A603485A105C325D4
                                                                                                                                                                                                                                  SHA-256:174FA7B850775F0224764BB754D4C0CA5515885480AAC14A08A2EA8C305AAC16
                                                                                                                                                                                                                                  SHA-512:584C7F8510384E8095AFC3008A84DA38FC3ADA4DE4E8CBF14F1A6EB83B2180EDBAE1353A8BCC249DC89F6C5516C84B1EA8DD5F8FC8AC91BBF95628F4077837B7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.................."...... .........t. .......................................-......>,...`.........................................`@'.p....@'.,.............+.h............P-..$...d%............................. e%.8............. ..............................text..... ....... ................. .P`.rdata....... ....... .............@.P@.data....!....'......^'.............@.P..pdata..h.....+......|).............@.0@.reloc...$...P-..&....+.............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):110080
                                                                                                                                                                                                                                  Entropy (8bit):6.155785393782448
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:8YD9m9yyTZOXZtTZS6royKDaGW2A8wWYpdC4J9u2+:8YD4rVOXnVSLyKe/21wW2z7
                                                                                                                                                                                                                                  MD5:715BE8257D3D4717F0FCCD54B04E8563
                                                                                                                                                                                                                                  SHA1:988F23AD08647713A1C7D08EB55D00BF35D9E647
                                                                                                                                                                                                                                  SHA-256:2F2049F9EE05AECDFC59BE6EF059C5F97B2B6BDEBE5E27FDD431AD67F788D8D7
                                                                                                                                                                                                                                  SHA-512:5973A365C5C8ED35F1AA5CCD06FB2A346092C8D97544FD31CA80C7F9F1B2C0C057F5661C676E69D50A2609B1DC5B98344D16FA2F6A24FB1CA8FC76C553B5FB4C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....|..........`................................................d....`.............................................t.......................................<.....................................8............................................text....{.......|.................. .P`.rdata..h........ ..................@.P@.data...............................@.P..pdata..............................@.0@.reloc..<...........................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):106496
                                                                                                                                                                                                                                  Entropy (8bit):6.29508015660015
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:fl/0h7pqMLGrm19IlDiBLlJb+GBKlT51addBCQUo5+QzJocQ7JQWAPiP:ql4vkBLlJb+AKlT4rso5+QmchWAPi
                                                                                                                                                                                                                                  MD5:DB7697C1626D30E98EABF9822FB8A088
                                                                                                                                                                                                                                  SHA1:35AAE7BB6F45546006D9EEB6B482FC115B8CBC2F
                                                                                                                                                                                                                                  SHA-256:3327E82005D1259BBECE28122C75A4E83BB508EE0CD62114ADC285F21AE89365
                                                                                                                                                                                                                                  SHA-512:BC4B9A0114BAC52F19CA3BA1261B1A95553FE21899AAF51F0D63D4383EEF8FD8979F8AB697D384117D170A2EEC4D75AA8BA6AA313D82A3875C32F2B00A0F820D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....N...T.......R..............................................).....`.............................................h...(........................................u.............................. u..8............`..(............................text....M.......N.................. .P`.rdata...5...`...6...R..............@.P@.data...............................@.P..pdata..............................@.0@.reloc..............................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):257024
                                                                                                                                                                                                                                  Entropy (8bit):6.379029212539396
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6144:wewkgh4gwSIdtALZrZ6LK5zyfn5jwT9X8zcKzDWV:0G6LT6R5jwOcl
                                                                                                                                                                                                                                  MD5:BDD5DB8721C48DF94B9D7211F8ACC5F8
                                                                                                                                                                                                                                  SHA1:314DA2C2978F43840F641FD6274177E4B0AF9047
                                                                                                                                                                                                                                  SHA-256:1D5C98F95ABC2C87533237B1200E14539B7C5D8F1BF90870C15CFC00D51097FF
                                                                                                                                                                                                                                  SHA-512:29874CDA6595BD908C54A67C43BB8AD7B0D17BA1895650605D42B580A573395BFD4BF49453396AE131F192D2AB92627CF67667BE19573FA6D79A39401C173033
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....2...........6.......................................@.......'....`............................................. ...0...x............................0..P......................................8............P...............................text....1.......2.................. .P`.rdata..l....P.......6..............@.P@.data...............................@.P..pdata..............................@.0@.reloc..P....0......................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174080
                                                                                                                                                                                                                                  Entropy (8bit):6.105176064620869
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:hAyDLu/gTyqWqDOUi9a0h70q7jEZMDt7knNr1z4OSf2xIVUKTZap:hAy/uoTyRaA9jxDhG1z7LKNa
                                                                                                                                                                                                                                  MD5:075B073473A9529D0DBC2CBAC637CE09
                                                                                                                                                                                                                                  SHA1:903E1768A7A943A4FCFC122DC903F21ECD86C0E3
                                                                                                                                                                                                                                  SHA-256:48BF0E11F32DC18D4AE4BBA02F952A21A167573326AE6DA1A87DDDD9349EC86C
                                                                                                                                                                                                                                  SHA-512:A8C2FB6E976EC26A11D5E2E1D23F1DF59FFB71B7F5AE3983382CCEE9BF256622C5FF27938FB5DB4780E5BE26F4EE2C749FFB8DA594C84990581A54D4B68D961D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....8...l.......<....................................................`......................................... ...\...|...x...................................P...............................p...8............P...............................text....7.......8.................. .P`.rdata..dW...P...X...<..............@.P@.data...............................@.P..pdata..............................@.0@.reloc..............................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):694272
                                                                                                                                                                                                                                  Entropy (8bit):6.313719191343553
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12288:q2/4/rpBYL6PYFaK76nBisdLRxfxUOmxm+K+jwjT:R/4zpBYjFqlRxx+Kek
                                                                                                                                                                                                                                  MD5:F193FDAFA9DB9A528B12EDAD61CC6E00
                                                                                                                                                                                                                                  SHA1:8A9C7E78035F864102A3D84886D107539B3BAEFC
                                                                                                                                                                                                                                  SHA-256:99F57F0EC077F5CF3AEF47AA2EF5291964F74BE5D73851F63C7FD15B87C31CBE
                                                                                                                                                                                                                                  SHA-512:A8E317A120481D84D123283D68ED25B181E3BAF5708A90C1980B53444419DA30A305122B817A3A05EC5305676010884C54DCA4103B82B4CA91D0EB83F38D724D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....6...^.......:...............................................M....`..........................................P.......X..................................h....%...............................%..8............P...............................text....5.......6.................. .P`.rdata...#...P...$...:..............@.P@.data...h9...........^..............@.P..pdata...............v..............@.0@.reloc..h...........................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):77312
                                                                                                                                                                                                                                  Entropy (8bit):6.190129520453749
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:tX2z8GmDtvm2B1/FuHWIx68XTWbDdCmdVBEZhrAOT:tGz8GKjJG68XQmXrAO
                                                                                                                                                                                                                                  MD5:B15E49985A36102A282F4655D2115DE2
                                                                                                                                                                                                                                  SHA1:5CC2BF51E40738DABDFFF5384C44398101777DCA
                                                                                                                                                                                                                                  SHA-256:B7B81EF1DF9952651C3473FD7D640D79B0524192050AE9BB8E2AB71E8EED3212
                                                                                                                                                                                                                                  SHA-512:30A1BC3D4FA27A5FDA2FC4DDE71F9A545A690BAD1FD66C417C13E48918597F0E0DACA88CA4A301B11457CA47746851FB70D2635C67722777BAAC0505DDCEC864
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........f......P........................................p............`..........................................%..`....&..x............P...............`..|... ...............................@...8............................................text............................... .P`.rdata...W.......X..................@.P@.data...H....@....... ..............@.P..pdata.......P.......$..............@.0@.reloc..|....`.......,..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):84480
                                                                                                                                                                                                                                  Entropy (8bit):6.065331568083205
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:sxDenRFCSmTV6rIuKX1hJ6K7fkVxi0IE5nnmF/h:sZaFCSmTNRX1hQKTW5nnmF
                                                                                                                                                                                                                                  MD5:C2A8002BF0AA62E0BFE0F1E938A12EF6
                                                                                                                                                                                                                                  SHA1:AD15A572D51F628757F227F881E004052A93A193
                                                                                                                                                                                                                                  SHA-256:C67705D6D3843A3656A8CD6EEDAC62C2B4209D3F801A92F3B2B5000A75600B8A
                                                                                                                                                                                                                                  SHA-512:B3FBD58CAE741C00A14AD630FFACDA5FA9F74BF6E558A7E8ECDD7418A131F7F615220DB042BB55939E7CF754FA9CB6AD4CA19F8B7DA39FD64F507B22E90D5907
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........t............................................................`.........................................`?..\....?..x...............8................... 3..............................@3..8............................................text...8........................... .P`.rdata..fa.......b..................@.P@.data........`.......8..............@.P..pdata..8............@..............@.0@.reloc...............H..............@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):70656
                                                                                                                                                                                                                                  Entropy (8bit):6.054105449649638
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:konm5wl9AXmpixdR9GrC2DZFEmW+4QqX2G7b5td2ETmSS:kvw3AsrC21zWDHNb5tdZTmSS
                                                                                                                                                                                                                                  MD5:18E0B9676B9724A3931491828966BEB2
                                                                                                                                                                                                                                  SHA1:0C8846DFDB2900268009042DD53DFF90570096D0
                                                                                                                                                                                                                                  SHA-256:73E35656E4E26137F771FDDADB1B7A806FA8399BFA8ABB66B63E1A9EDE809D18
                                                                                                                                                                                                                                  SHA-512:5E4DCBA88657BC099AC6BD43C46FBD88AEF42E8F7EC3698CFB8334FFC46E5F12D0B74B2E8B00297A8F2FB943ACCF123DEBBEA384CB4DA8CEDAA3C764DE86B49E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........`......P........................................P.......K....`.............................................\...\...x............0...............@..|.......................................8............................................text............................... .P`.rdata..\S.......T..................@.P@.data...(.... ......................@.P..pdata.......0......................@.0@.reloc..|....@......................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):51712
                                                                                                                                                                                                                                  Entropy (8bit):5.886300247740077
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:4W5V7Yiy8/X0y86nnABveaLxl+Ek9Swj73Uw8w8SHyuUAa8oPHGcFSgxEdkBBc:4AVFF0an8VlXvwMtfDXGOxEdWc
                                                                                                                                                                                                                                  MD5:EEECD86BE89A4944A7FC0569F31A48EC
                                                                                                                                                                                                                                  SHA1:572F70ECA1FB29D9B12CC4BB3278309D0DD3AABC
                                                                                                                                                                                                                                  SHA-256:5F778438D9BFC32B4AD3CB0EF7182AF098504A081AA5E17DB077CF424DAE8D42
                                                                                                                                                                                                                                  SHA-512:3F3566734D6BD057231253B026B41DC3AE8F6EA579EE54A58C18D1AD66F8CDDBC3785C3A234FFA5F5CB9D3E1CA4EFAD1CB8B9728C4E3473DACE0F00B68033D09
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".....|...J......P....................................................`............................................\...,...x...............................p......................................8............................................text....{.......|.................. .P`.rdata...=.......>..................@.P@.data...............................@.P..pdata..............................@.0@.reloc..p...........................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):164352
                                                                                                                                                                                                                                  Entropy (8bit):6.170419189874856
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:Lj6KO4lIE5h0/VrHEjQEUF6uR+UR2FRl+I9U2+Warahg2+WarahjLMSl5c9DNHaq:Lj6KO46SWdrHdF6G2vl+uU2+Warahg2m
                                                                                                                                                                                                                                  MD5:B2879AF0EC91B94458E85C03C441CD14
                                                                                                                                                                                                                                  SHA1:D8431B9E52277DD768666A7A20E4C5217362A980
                                                                                                                                                                                                                                  SHA-256:8B7B29F63F051F93AB7BE369E7FD22CAB1385E3AAA83D7BEB3267DF4F39154AB
                                                                                                                                                                                                                                  SHA-512:3DBCE2B102E2A7AD62881FF24D2446AB25DC760BD5C1AF8EE8780D08A94270D55B5754D99FCEA1E5FBF885D3789A7983177E91BA132EDFFB38274B6F45298247
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".................................................................h....`..........................................V..h...XW..x...................................PE..............................pE..8............................................text...x........................... .P`.rdata..............................@.P@.data...X$...p.......`..............@.P..pdata...............t..............@.0@.reloc..............................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):596992
                                                                                                                                                                                                                                  Entropy (8bit):6.215300924489346
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12288:lDie19QbZGfL0DlT0U5Xc0X2bfRFAg3jwG:lNDQbZ9jjXBgT5
                                                                                                                                                                                                                                  MD5:12C6AAB00309D50D5FF5E7B6877F83D6
                                                                                                                                                                                                                                  SHA1:D53B321B496FF637643570A948A7238A3098BE9C
                                                                                                                                                                                                                                  SHA-256:F2206738B19668BC5718D0E684890AB9A6D420AAC35D5C784D4CC35A6D520493
                                                                                                                                                                                                                                  SHA-512:564E75B86AF8ED3FCCEC51F85AD5442B5B68EE70393126A61F0FF174D1D0165E427E413F8B02724DCF748A4BDFA3F1B58A5D1FBF2ADBD066BE690471DAA10673
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d..................".........*...............................................p...........`..................................................................@..\............`......P...............................p...8...............x............................text............................... .P`.rdata..............................@.P@.data...X,..........................@.P..pdata..\....@......................@.0@.reloc.......`......................@.0B........................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4
                                                                                                                                                                                                                                  Entropy (8bit):1.5
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:Mn:M
                                                                                                                                                                                                                                  MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                                  SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                                  SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                                  SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:pip.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1090
                                                                                                                                                                                                                                  Entropy (8bit):5.1315093013694835
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:RsMiJHxRHuyPP3GtIHw1Gg9QH+sUW8Ok4F+d1o36qjFD:KMiJzfPvGt7ICQH+sfIte36AFD
                                                                                                                                                                                                                                  MD5:8BA06D529C955048E5DDD7C45459EB2E
                                                                                                                                                                                                                                  SHA1:33263B236DBFF36FC92163EC61D62B9370384FEC
                                                                                                                                                                                                                                  SHA-256:5BA21FBB0964F936AD7D15362D1ED6D4931CC8C8F9FF2D4D91190E109BE74431
                                                                                                                                                                                                                                  SHA-512:B556395FE3FD5E11CCE48B082C4E9799D37514D5AC0CFAEC6FEDD7C00D72EA3B9D001F8791E948253B516CC6BDA0E8663B055D6B8587D7CFA11773153834B8DE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Copyright (c) 2008-2019 The pip developers (see AUTHORS.txt file)..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND.NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE.LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION.OF CONTRACT, TORT OR OTHERWISE, ARISING FROM
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3708
                                                                                                                                                                                                                                  Entropy (8bit):4.978925380870447
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:DygN5jaaxmPkxsxM5wBlhLMxSbMY0Ltb63Rg6jWMy:1sMw3Rg0g
                                                                                                                                                                                                                                  MD5:107AA0D8738CFFB2A4BDEF3045E30990
                                                                                                                                                                                                                                  SHA1:2D9B8FE93EDBDF63B261F6CF30B94CBBE43321F0
                                                                                                                                                                                                                                  SHA-256:F669873F705ECDE43088F8F5D8D74B16CA6A731AAB7FBC6A5BA397F4FC194ABE
                                                                                                                                                                                                                                  SHA-512:64E12E3E8AEAAE98DD4E62104D0046B5EA6259E438C5340AAD21DDFA3273A0595FF92C7A3E2BD2894767B1D266F721E6D5A95F75A77E849855F3FC6C96929092
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Metadata-Version: 2.1.Name: pip.Version: 20.2.3.Summary: The PyPA recommended tool for installing Python packages..Home-page: https://pip.pypa.io/.Author: The pip developers.Author-email: distutils-sig@python.org.License: MIT.Project-URL: Documentation, https://pip.pypa.io.Project-URL: Source, https://github.com/pypa/pip.Project-URL: Changelog, https://pip.pypa.io/en/stable/news/.Keywords: distutils easy_install egg setuptools wheel virtualenv.Platform: UNKNOWN.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Topic :: Software Development :: Build Tools.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 2.Classifier: Programming Language :: Python :: 2.7.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3.5.Classifier: Programming Language :: Python :: 3.6.Classifier: Programming Language :: P
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:CSV text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):58156
                                                                                                                                                                                                                                  Entropy (8bit):5.568921432203395
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:YHcayOazPVb+5pEJ88vVe4bTd1bsccWv01uCjhVy:YHcrHVb+5pY84Ve4bTd1bscdvErtY
                                                                                                                                                                                                                                  MD5:96926E5190FAA264E6C2A06FE92C4E1C
                                                                                                                                                                                                                                  SHA1:BF9F2C41155DE36C51948279C07774F9A2E5AEB0
                                                                                                                                                                                                                                  SHA-256:BD8C847639F746B6F8EB4CFF003B7FBEF43E82DDD1F98A0A199D46A541F6C349
                                                                                                                                                                                                                                  SHA-512:E974A89C7B9965CA215C6758936EEECBF8A16640938560F7D56A519F970EF284D9AEAA08F1C44C35BFB605EFA706E4169EBC67A926813777A22F9894E460A205
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:../../Scripts/pip.exe,sha256=Esrq-uIHboffERhf5Z7Y8Phsqn9OSYVvGDPvXBG_Xwo,106376..../../Scripts/pip3.9.exe,sha256=Esrq-uIHboffERhf5Z7Y8Phsqn9OSYVvGDPvXBG_Xwo,106376..../../Scripts/pip3.exe,sha256=Esrq-uIHboffERhf5Z7Y8Phsqn9OSYVvGDPvXBG_Xwo,106376..pip-20.2.3.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..pip-20.2.3.dist-info/LICENSE.txt,sha256=W6Ifuwlk-TatfRU2LR7W1JMcyMj5_y1NkRkOEJvnRDE,1090..pip-20.2.3.dist-info/METADATA,sha256=9mmHP3BezeQwiPj12NdLFspqcxqrf7xqW6OX9PwZSr4,3708..pip-20.2.3.dist-info/RECORD,,..pip-20.2.3.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..pip-20.2.3.dist-info/WHEEL,sha256=ADKeyaGyKF5DwBNE0sRE5pvW-bSkFMJfBuhzZ3rceP4,110..pip-20.2.3.dist-info/entry_points.txt,sha256=HtfDOwpUlr9s73jqLQ6wF9V0_0qvUXJwCBz7Vwx0Ue0,125..pip-20.2.3.dist-info/top_level.txt,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..pip/__init__.py,sha256=NkPibWV383InU5x7DgeQLdL2zhlXTKjJRBMQTSKNYjI,455..pip/__main__.py,sha256=bqCAM1cj1HwHCD
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):110
                                                                                                                                                                                                                                  Entropy (8bit):4.816968543485036
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:RtEeX7MWcSlVii6KRRP+tPCCf7irO5S:RtBMwlViGjWBBwt
                                                                                                                                                                                                                                  MD5:D25A99ECD1ECB535EE4E31874B0C7B95
                                                                                                                                                                                                                                  SHA1:B80780FBBF97A5FBF433C4F692E340632EA675F1
                                                                                                                                                                                                                                  SHA-256:00329EC9A1B2285E43C01344D2C444E69BD6F9B4A414C25F06E873677ADC78FE
                                                                                                                                                                                                                                  SHA-512:539E072414E6E8AD3BFAEDB0587507443B39826814FB330B57D605FB5FBE61134D3548359F41A14CC63B44E23EF0AA1E62EA1C4A2F3B344BE548F4C2C8143976
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.35.1).Root-Is-Purelib: true.Tag: py2-none-any.Tag: py3-none-any..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):125
                                                                                                                                                                                                                                  Entropy (8bit):4.063179170203111
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:1VriL6MtGC8eeBK6MtGC8eeWivMh6MtGC8e3n:1VriLtofKtotKtoa
                                                                                                                                                                                                                                  MD5:1717F250956AACBB7973AF030DDCC506
                                                                                                                                                                                                                                  SHA1:1A6C243A1581ADA312B7C5B68790803CEB1169A2
                                                                                                                                                                                                                                  SHA-256:1ED7C33B0A5496BF6CEF78EA2D0EB017D574FF4AAF517270081CFB570C7451ED
                                                                                                                                                                                                                                  SHA-512:0B823A5646350663C146D64F0EED98E3A99ABF068C45ED4FF5FDD389EA58AD79BD79DA0B60A945F090B8EE87252139B33712C6B8285E5591440A3312A107E2A3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:[console_scripts].pip = pip._internal.cli.main:main.pip3 = pip._internal.cli.main:main.pip3.8 = pip._internal.cli.main:main..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4
                                                                                                                                                                                                                                  Entropy (8bit):1.5
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:Mn:M
                                                                                                                                                                                                                                  MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                                  SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                                  SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                                  SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:pip.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):67072
                                                                                                                                                                                                                                  Entropy (8bit):5.90551713971002
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:ZhseNxkc7Xva0Y420G1UD+dS4gBeLmRy:Z1kcbi0Y42bUD+dS4oeiRy
                                                                                                                                                                                                                                  MD5:01F9D30DD889A3519E3CA93FE6EFEE70
                                                                                                                                                                                                                                  SHA1:EBF55ADBD8CD938C4C11D076203A3E54D995AEFF
                                                                                                                                                                                                                                  SHA-256:A66444A08A8B9CEAFA05DAEFEB32AA1E65C8009A3C480599F648FA52A20AFB7D
                                                                                                                                                                                                                                  SHA-512:76FED302D62BB38A39E0BF6C9038730E83B6AFFFA2F36E7A62B85770D4847EA6C688098061945509A1FDB799FB7F5C88699F94E7DA1934F88A9C3B6A433EE9EF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......`T..$5..$5..$5..-M3..5..v@..&5..v@..(5..v@..,5..v@.. 5...k..&5..oM..55..$5...5...@..45...@..%5...@_.%5...@..%5..Rich$5..........................PE..d.....~e.........." .........h..............................................@............`.........................................P...`.......@.... .......................0..(.......................................8............................................text............................... ..`.rdata..|I.......J..................@..@.data...x...........................@....pdata..............................@..@.rsrc........ ......................@..@.reloc..(....0......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):301568
                                                                                                                                                                                                                                  Entropy (8bit):6.3420350412756274
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6144:UWxKWIAdASHubXQV2ehNu5JBsPvotjnOG:FxKWz1hKa8nX
                                                                                                                                                                                                                                  MD5:2AADB9C4E19F30CF9787B01256E36D6C
                                                                                                                                                                                                                                  SHA1:EA928D1EFA8B979F826C3984A9C87CEAD525167C
                                                                                                                                                                                                                                  SHA-256:5F121FE659843864E0606329D268DB7158FCEEF4C8F1FACA9C558D787BF39404
                                                                                                                                                                                                                                  SHA-512:94617F55A791E545DF4ED2FC80E344017EEAF48AAA8FED17E6B41943A66AD08D0FA7205FC9CE98F5E1B3857E04D11B347891F94A8A268A715660F7A2352E7E2E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......P<M%.]#v.]#v.]#v.6 w.]#v.6&w.]#v.6'w.]#vv%&w.]#vv%'w.]#vv% w.]#v.("w.]#v.6"w.]#v.]"v.]#vu''w.]#vu'+w.]#vu'#w.]#vu'.v.]#vu'!w.]#vRich.]#v........PE..d.....Ge.........." ... ..................................................................`..........................................I..d....J..................d)..................`............................... ...@............0...............................text............................... ..`.rdata..`/...0...0..................@..@.data...p2...`.......F..............@....pdata..d).......*...b..............@..@_RDATA..\...........................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):188944
                                                                                                                                                                                                                                  Entropy (8bit):6.316734516354951
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:PPByGzRK2iMxLo706iAJFyPMf+ImzdJclGJmRlhLblXQOlf/ITTpb26ROfuQL5UL:PUp2iMxM70afLmzdJcbtbnf/ypKLqt
                                                                                                                                                                                                                                  MD5:0DC9848A5FCE6EC03799AC65602DC053
                                                                                                                                                                                                                                  SHA1:DDFD97A45C0DB5117E047BF45D66873B53160978
                                                                                                                                                                                                                                  SHA-256:ADC9C63F92629ED4B860FC1855400B59A1AE73DD489FD49DB326DCFCAD48550E
                                                                                                                                                                                                                                  SHA-512:D1B2F71000CAB1115971D44C690FDB8966B9B402216B87EC1F1E8E8A1CCA3CE1E1145B8D650C8AD737E6E24C59503AAF9310DE3E96A0AC6596187C800013AC71
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......zJXf>+65>+65>+657S.54+65.[74<+65.[345+65.[246+65.[54=+65.Z74<+65eC74=+65>+75L+65.Z;4:+65.Z64?+65.Z.5?+65.Z44?+65Rich>+65................PE..d....={_.........." .................................................................*....`.............................................P...`........................................5..T............................6..0............ ...............................text...s........................... ..`.rdata....... ......................@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):58384
                                                                                                                                                                                                                                  Entropy (8bit):5.879471644001699
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:oSspSGOfpzVHBlAUcfc0la6WS6kH/ZFJ1Yu+wNBECaOMyCgUhkb0E/G88AIhV0cj:whf+kD8AIhV05yJ
                                                                                                                                                                                                                                  MD5:3C88DE1EBD52E9FCB46DC44D8A123579
                                                                                                                                                                                                                                  SHA1:7D48519D2A19CAC871277D9B63A3EA094FBBB3D9
                                                                                                                                                                                                                                  SHA-256:2B22B6D576118C5AE98F13B75B4ACE47AB0C1F4CD3FF098C6AEE23A8A99B9A8C
                                                                                                                                                                                                                                  SHA-512:1E55C9F7AC5ACF3F7262FA2F3C509EE0875520BB05D65CD68B90671AC70E8C99BCE99433B02055C07825285004D4C5915744F17ECCFAC9B25E0F7CD1BEE9E6D3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............d...d...d.n.l...d.n.d...d.n.....d.n.f...d.Rich..d.................PE..d....={_.........." .................................................................@....`.........................................` ............................................... ..T............................................................................text............................... ..`.rdata....... ......................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4457488
                                                                                                                                                                                                                                  Entropy (8bit):6.4375658606576405
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:49152:1kYH+B/E8d7YHDCxJvUIIHd4hP8wuqNdOMFit/gxSwzaBuv4lz1ZRVgwWFJfzMpg:zo7Yq0a2YaCIIzcHxJ7HtMU5weHWeMt
                                                                                                                                                                                                                                  MD5:11C051F93C922D6B6B4829772F27A5BE
                                                                                                                                                                                                                                  SHA1:42FBDF3403A4BC3D46D348CA37A9F835E073D440
                                                                                                                                                                                                                                  SHA-256:0EABF135BB9492E561BBBC5602A933623C9E461ACEAF6EB1CECED635E363CD5C
                                                                                                                                                                                                                                  SHA-512:1CDEC23486CFFCB91098A8B2C3F1262D6703946ACF52AA2FE701964FB228D1411D9B6683BD54527860E10AFFC0E3D3DE92A6ECF2C6C8465E9C8B9A7304E2A4A6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................7.......QH&.....7.......7.......7........r.....................x.......x.......x.......x.......Rich....................PE..d....={_.........." ....."#..b#......O........................................F.......D...`.........................................pZ<.......=.|....0F.......D.\/....C......@F..u..4.$.T.............................$.0............@#.`............................text.... #......"#................. ..`.rdata.......@#......&#.............@..@.data........P=......*=.............@....pdata..\/....D..0...:A.............@..@.rsrc........0F......jC.............@..@.reloc...u...@F..v...tC.............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):669696
                                                                                                                                                                                                                                  Entropy (8bit):6.041318185220244
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12288:0JAdJvxYYlSBSEglosP1ZhDuGWpdH+czk:EAfvx1gcE6omZpuec
                                                                                                                                                                                                                                  MD5:8D4CD39CF6B1E5D3743AC1BCDCAB4F12
                                                                                                                                                                                                                                  SHA1:2ECFD93164920A60C273B1D000DF14351816DBD7
                                                                                                                                                                                                                                  SHA-256:0789F9321ABFA3A6403A483CB3BA684DA5CFC39D26195FCE8669A77C6367C413
                                                                                                                                                                                                                                  SHA-512:7734D61B7B2C5F829D05488B26D958B85D0CF87776B91E8A63B58DEBF5D32DB42BC2D203CC5A27AB426672C282BF95B41B8429EE3EA1F0E0D9CA55F9F68E77BD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........x...+...+...+.P+...+...*...+...*...+...*...+...*...+!..*...+...*...+x..*...+...*...+...+...+!..*...+!..*...+!..*...+Rich...+........PE..d...k..d.........." ......................................................................`.........................................pU...c..............\....@..0{............... ......T...........................0...8............................................text............................... ..`.rdata..|$.......&..................@..@.data....I..........................@....pdata..0{...@...|..................@..@.rsrc...\...........................@..@.reloc... ......."..................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):134656
                                                                                                                                                                                                                                  Entropy (8bit):6.0017332542566715
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072://ZCM+lst/TPZa4TjDY/r06trJhQAjkYe1K6SXxKpjAjfMG://ZCplst/TPnY/rxt6A4Ye1KbXYpEjf
                                                                                                                                                                                                                                  MD5:F20FD2E2AC9058A9FD227172F8FF2C12
                                                                                                                                                                                                                                  SHA1:89EBA891352BE46581B94A17DB7C2EDE9A39AB01
                                                                                                                                                                                                                                  SHA-256:20BDE8E50E42F7AABF59106EEA238FCC0DECE0C6E362C0A7FEEB004AB981DB8A
                                                                                                                                                                                                                                  SHA-512:42A86FA192AEA7ADB4283DC48A323A4F687DAD40060EA3FFDDCD8FD7670BB535D31A7764706E5C5473DA28399FEC048AE714A111EE238BB25E1AAD03E12078D4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........9.$.X.w.X.w.X.w. Kw.X.w.-.v.X.w.7%w.X.w.-.v.X.w.-.v.X.w.-.v.X.w.3.v.X.wY1.v.X.w.3.v.X.w.X.w&X.w.-.v.X.w.-.v.X.w.-.v.X.wRich.X.w........PE..d......d.........." .........................................................P............`..........................................u..`B..p...,....0..d.......L............@..0...`Q..T............................Q..8............................................text............................... ..`.rdata..\...........................@..@.data....-.......(..................@....pdata..L...........................@..@.rsrc...d....0......................@..@.reloc..0....@......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):27152
                                                                                                                                                                                                                                  Entropy (8bit):6.196341800261924
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:1AEYe1nJzV3mynQwhS/hHq++4XvPAr70cElZ8AIhqGLnYPLxDG4y8eKAtO:FBBDnQwhihHq2v8uZ8AIhqGLWDG4y0iO
                                                                                                                                                                                                                                  MD5:7A442BBCC4B7AA02C762321F39487BA9
                                                                                                                                                                                                                                  SHA1:0FCB5BBDD0C3D3C5943E557CC2A5B43E20655B83
                                                                                                                                                                                                                                  SHA-256:1DD7BBA480E65802657C31E6D20B1346D11BCA2192575B45EB9760A4FEB468AD
                                                                                                                                                                                                                                  SHA-512:3433C46C7603AE0A73AA9A863B2AECD810F8C0CC6C2CD96C71EF6BDE64C275E0FCEB4EA138E46A5C9BF72F66DCDEA3E9551CF2103188A1E98A92D8140879B34C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........K...%...%...%.......%.Z.$...%.Z. ...%.Z.!...%.Z.&...%...$...%...$...%...$...%...(...%...%...%.......%...'...%.Rich..%.........................PE..d....={_.........." ..... ...2......................................................:.....`..........................................@..L....@..x....p.......`..<....P..........@....2..T...........................03..0............0..(............................text...=........ .................. ..`.rdata..*....0.......$..............@..@.data........P.......>..............@....pdata..<....`.......@..............@..@.rsrc........p.......D..............@..@.reloc..@............N..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4
                                                                                                                                                                                                                                  Entropy (8bit):1.5
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:Mn:M
                                                                                                                                                                                                                                  MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                                                  SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                                                  SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                                                  SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:pip.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1078
                                                                                                                                                                                                                                  Entropy (8bit):5.127816565309219
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:p7rOJH7H0yxgtUHw1hC09QHOsUv4eOk4/+/m3oqLFh:RSJrlxEvdQHOs5exm3ogFh
                                                                                                                                                                                                                                  MD5:9A33897F1BCA1160D7AAD3835152E158
                                                                                                                                                                                                                                  SHA1:A5234543D56E03C950C0080826B53A0CB97671AF
                                                                                                                                                                                                                                  SHA-256:C32A3AC395AF6321EFD28BE73D06A00F0DB6AB887D1C21D4FEC46128D2056D5A
                                                                                                                                                                                                                                  SHA-512:0CC71D2F794775FE676B729532C1B5B68777CABC7FB15E0D5F38542A3D4631B211074FF86D69127E2F088CD357161CF0C353F658F640711CDCC821D4D45CB318
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Copyright (C) 2016 Jason R Coombs <jaraco@jaraco.com>..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies.of the Software, and to permit persons to whom the Software is furnished to do.so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4819
                                                                                                                                                                                                                                  Entropy (8bit):5.0865265175094425
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:DpGYyJAmhQI/aMxmPd132n71ACA8IjqyU8BeqGpDiHVP6o7PFPMUwTeXv:DF9Gn7mZ8IjqyU8BeqG4wTY
                                                                                                                                                                                                                                  MD5:0FBFE2D1A8DE08A2DD673D160AF5A360
                                                                                                                                                                                                                                  SHA1:7178E12234DE06A05C99949DB5873D6B47B7B835
                                                                                                                                                                                                                                  SHA-256:0695712D72E0EE815F934E51B91B8079AE093D37D8AD5097D277D6E00F52F70F
                                                                                                                                                                                                                                  SHA-512:6B8D660E5C378A960385EC29CA58E9F60FCDC073C3433FD9ADE8C3C5B465B4906028E7155B7FAFDA3BEDEEBF37609D018904D49C56712C1043531EC6AA5D716C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Metadata-Version: 2.1.Name: setuptools.Version: 49.2.1.Summary: Easily download, build, install, upgrade, and uninstall Python packages.Home-page: https://github.com/pypa/setuptools.Author: Python Packaging Authority.Author-email: distutils-sig@python.org.License: UNKNOWN.Project-URL: Documentation, https://setuptools.readthedocs.io/.Keywords: CPAN PyPI distutils eggs package management.Platform: UNKNOWN.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Operating System :: OS Independent.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.5.Classifier: Programming Language :: Python :: 3.6.Classifier: Programming Language :: Python :: 3.7.Classifier: Programming Language :: Python :: 3.8.Classifier: Topic :: Software Development :: Libraries :: Python Modules.Classifier: Topic
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:CSV text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):22793
                                                                                                                                                                                                                                  Entropy (8bit):5.590242412302483
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:sPUdzrUuHSo+ahtaPEkcFEU2HWvao4I6pLXB+ZIXvRNwyUvBU3yYFh9QU5HGf9oB:2eLvctfRZUv2iYFrQU5i9qV
                                                                                                                                                                                                                                  MD5:C67F968859FD8DEDDF867B444ECD4398
                                                                                                                                                                                                                                  SHA1:E2FE467DA10D1338C5658E1E8DA55BF40AF3CDDD
                                                                                                                                                                                                                                  SHA-256:F74DC2386FDE51D0E5E4F7C01D622790EBC143B29B278190CAF4C4AE6C3C4241
                                                                                                                                                                                                                                  SHA-512:BD3466855AD0FF536D4B1769EF544753FE03C0F01E53BF2CD2893F0AC9CB1E6B61C89415D5C00A3E3B548EAB181A33322915A8855889E8A13FB0F1E0E08F0EF2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:../../Scripts/easy_install-3.9.exe,sha256=VEvVrEhbE_qAeziwi8dhT61IKWcXV3VQTcte3mGYBoI,106385..../../Scripts/easy_install.exe,sha256=VEvVrEhbE_qAeziwi8dhT61IKWcXV3VQTcte3mGYBoI,106385..__pycache__/easy_install.cpython-39.pyc,,..easy_install.py,sha256=MDC9vt5AxDsXX5qcKlBz2TnW6Tpuv_AobnfhCJ9X3PM,126..pkg_resources/__init__.py,sha256=44G2LkL_lXbDzjTukLmR5baLQtE3S4IaFciSZPDcOM8,108481..pkg_resources/__pycache__/__init__.cpython-39.pyc,,..pkg_resources/_vendor/__init__.py,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..pkg_resources/_vendor/__pycache__/__init__.cpython-39.pyc,,..pkg_resources/_vendor/__pycache__/appdirs.cpython-39.pyc,,..pkg_resources/_vendor/__pycache__/pyparsing.cpython-39.pyc,,..pkg_resources/_vendor/__pycache__/six.cpython-39.pyc,,..pkg_resources/_vendor/appdirs.py,sha256=MievUEuv3l_mQISH5SF0shDk_BNhHHzYiAPrT3ITN4I,24701..pkg_resources/_vendor/packaging/__about__.py,sha256=CpuMSyh1V7adw8QMjWKkY3LtdqRUkRX4MgJ6nF4stM0,744..pkg_resources/_vendor/packaging/__init__.py,
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):92
                                                                                                                                                                                                                                  Entropy (8bit):4.842566724466667
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:RtEeX7MWcSlVitcv6KjP+tPCCfA5S:RtBMwlViWZWBBf
                                                                                                                                                                                                                                  MD5:2295CBFB2556C76D0EB0F184F7F5E416
                                                                                                                                                                                                                                  SHA1:AC049E2836CED0D89815B6A59D6FA063094EEA71
                                                                                                                                                                                                                                  SHA-256:8389CCB3B77E5E5F7EC42F57A2F52BB031C65EDF854F4135ED8AA8F760C47EF6
                                                                                                                                                                                                                                  SHA-512:9579F4AA5FB4131B79F1162100756459B0175521C919ACD75C74219531404191962FE56488CD0881D05FF8918720069D51CD014FFA19B96B75E1100EC7DECB49
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.34.2).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):239
                                                                                                                                                                                                                                  Entropy (8bit):4.9593491706048285
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:2MqdSOGVKfetEX8sEuGLRxtqdSOGR74pN6Dzqv:2qbcmEdEuudXUpN6DzU
                                                                                                                                                                                                                                  MD5:6E8EDE13DB59FBC370572CA72D66E36C
                                                                                                                                                                                                                                  SHA1:A0BE976BB2269ECB935661972C427CDD70BDCA1E
                                                                                                                                                                                                                                  SHA-256:1E5902164A0AE536D9E4430B6CB29884B718FC4DF5901583F13A96D848266AD4
                                                                                                                                                                                                                                  SHA-512:153439FE69A27A5FCEA82162B42FEA5BD88A469B1A853E5FC9DFBF8B6F64CD90B3900DC5683593F1DC97553DAEF4D42857E9437CC4BF05E95C3117619B4BCEB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:https://files.pythonhosted.org/packages/source/c/certifi/certifi-2016.9.26.tar.gz#md5=baa81e951a29958563689d868ef1064d.https://files.pythonhosted.org/packages/source/w/wincertstore/wincertstore-0.2.zip#md5=ae728f2f007185648d0c7a8679b361e2.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3143
                                                                                                                                                                                                                                  Entropy (8bit):4.536591833837899
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:R/YG8BZvy3g6yj+DsmnA540rZh2Phv4hhpTSeTonTj:qG8jPAorZoP94hTTSecTj
                                                                                                                                                                                                                                  MD5:B7EFFC5DA69B35D6794BA145EC0FE238
                                                                                                                                                                                                                                  SHA1:BCB0BA6F1E37C84D8616760EA8B555F6DE37CB5B
                                                                                                                                                                                                                                  SHA-256:D4AE45AF4FB93E1DD945916EC0D6B0F0444688D2D5A87BDD28336DDE85C64BAC
                                                                                                                                                                                                                                  SHA-512:8DF58FF4BD178241EBFFF00A6135FF1701D85D0FACC18B747E763B9BBE0CCCD2E6D19F067866B2D802693B53DCF9BE9935481E179886D264750FA6693A7C7C66
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:[console_scripts].easy_install = setuptools.command.easy_install:main.easy_install-3.8 = setuptools.command.easy_install:main..[distutils.commands].alias = setuptools.command.alias:alias.bdist_egg = setuptools.command.bdist_egg:bdist_egg.bdist_rpm = setuptools.command.bdist_rpm:bdist_rpm.bdist_wininst = setuptools.command.bdist_wininst:bdist_wininst.build_clib = setuptools.command.build_clib:build_clib.build_ext = setuptools.command.build_ext:build_ext.build_py = setuptools.command.build_py:build_py.develop = setuptools.command.develop:develop.dist_info = setuptools.command.dist_info:dist_info.easy_install = setuptools.command.easy_install:easy_install.egg_info = setuptools.command.egg_info:egg_info.install = setuptools.command.install:install.install_egg_info = setuptools.command.install_egg_info:install_egg_info.install_lib = setuptools.command.install_lib:install_lib.install_scripts = setuptools.command.install_scripts:install_scripts.rotate = setuptools.command.rotate:rotate.saveop
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):86619
                                                                                                                                                                                                                                  Entropy (8bit):2.2972446758995697
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:XSeUMIZQkyMiS4Y3fPOYo55XVi684z6WwQrrNoTRoyzDciB126afGG9whRJGAy/I:XhcQjSr3XeXVbmWdWd/zl5auG2hU/I
                                                                                                                                                                                                                                  MD5:12DBEEF45546A01E041332427FEC7A51
                                                                                                                                                                                                                                  SHA1:5C8E691AE3C13308820F4CF69206D765CFD5094B
                                                                                                                                                                                                                                  SHA-256:0C0DF17BFECE897A1DA7765C822453B09866573028CECCED13E2EFEE02BCCCC4
                                                                                                                                                                                                                                  SHA-512:FC8A250EE17D5E94A765AFCD9464ECAE74A4E2FF594A8632CEAEC5C84A3C4D26599642DA42E507B7873C37849D3E784CFB0792DE5B4B4262428619D7473FF611
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: gb12345, double-byte.D.233F 0 83.21.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.000030003001300230FB02C902C700A8300330052015FF5E2225202620182019.201C201D3014301530083009300A300B300C300D300E300F3016301730103011.00B100D700F72236222722282211220F222A222922082237221A22A522252220.23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235.22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605.25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1091
                                                                                                                                                                                                                                  Entropy (8bit):3.1978221748141253
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:qrmTUmJvRju36hVbsZiAMiZyb7PN8pUPnfk5JM0RHFj:qSgmO8VIwAMiw/PNPQPFj
                                                                                                                                                                                                                                  MD5:06645FE6C135D2EDE313629D24782F98
                                                                                                                                                                                                                                  SHA1:49C663AC26C1FE4F0FD1428C9EF27058AEE6CA95
                                                                                                                                                                                                                                  SHA-256:A2717AE09E0CF2D566C245DC5C5889D326661B40DB0D5D9A6D95B8E6B0F0E753
                                                                                                                                                                                                                                  SHA-512:DB544CFE58753B2CF8A5D65321A2B41155FE2430DB6783DD2F20E1244657482072633D16C8AC99765C113B60E99C8718263C483763A34C5E4BB04B4FFBA41976
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: gb1988, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.002000210022002300A500250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D203E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F.FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F.FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F.FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F.000000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):84532
                                                                                                                                                                                                                                  Entropy (8bit):2.3130049332819502
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:KSevutIzbwixZ1J9vS+MReR8cMvwKVDAcmaj8HEtG0waFtFsKQ2RzIjTfYahm6n3:Kat+wmTJYReltKVMeYkXOjYo5tG3VN+
                                                                                                                                                                                                                                  MD5:BF74C90D28E52DD99A01377A96F462E3
                                                                                                                                                                                                                                  SHA1:DBA09C670F24D47B95D12D4BB9704391B81DDA9A
                                                                                                                                                                                                                                  SHA-256:EC11BFD49C715CD89FB9D387A07CF54261E0F4A1CCEC1A810E02C7B38AD2F285
                                                                                                                                                                                                                                  SHA-512:8F5A86BB57256ED2412F6454AF06C52FB44C83EB7B820C642CA9216E9DB31D6EC22965BF5CB9E8AE4492C77C1F48EB2387B1CBDC80F6CDA33FA57C57EC9FF9CD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: gb2312, double-byte.D.233F 0 81.21.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.000030003001300230FB02C902C700A8300330052015FF5E2225202620182019.201C201D3014301530083009300A300B300C300D300E300F3016301730103011.00B100D700F72236222722282211220F222A222922082237221A22A522252220.23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235.22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605.25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.00000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):85574
                                                                                                                                                                                                                                  Entropy (8bit):2.3109636068522357
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:SgOycCs6mBixg1k6y8NMSwR8JMvz6VaVZmASVHBtGtRfS7FXtQ/RSJj9fNLSmXn/:SdC4BmCkjSwAO6VIrahNrVNTSYG3Oln
                                                                                                                                                                                                                                  MD5:9A60E5D1AB841DB3324D584F1B84F619
                                                                                                                                                                                                                                  SHA1:BCCC899015B688D5C426BC791C2FCDE3A03A3EB5
                                                                                                                                                                                                                                  SHA-256:546392237F47D71CEE1DAA1AAE287D94D93216A1FABD648B50F59DDCE7E8AE35
                                                                                                                                                                                                                                  SHA-512:E9F42B65A8DFB157D1D3336A94A83D372227BAA10A82EB0C6B6FB5601AA352A576FA3CDFD71EDF74A2285ABCA3B1D3172BB4B393C05B3B4AB141AAF04B10F426
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: euc-cn, multi-byte.M.003F 0 82.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.000000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):192
                                                                                                                                                                                                                                  Entropy (8bit):4.915818681498601
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SOd5MNXVSVLqRIBXSl1AEXMV/RRDfANDemSjs5dqcRcRZMvs5BCUNZ:SVNFS01K+MtkvSjwqd9NZ
                                                                                                                                                                                                                                  MD5:224219C864280FA5FB313ADBC654E37D
                                                                                                                                                                                                                                  SHA1:39E20B41CFA8B269377AFA06F9C4D66EDD946ACB
                                                                                                                                                                                                                                  SHA-256:E12928E8B5754D49D0D3E799135DE2B480BA84B5DBAA0E350D9846FA67F943EC
                                                                                                                                                                                                                                  SHA-512:6E390D83B67E2FD5BCAC1BA603A9C6F8BE071FA64021612CE5F8EE33FD8E3840A8C31A7B00134A0039E46BDC66BEF7EB6EA1F8663BA72816B86AF792EF7BDC56
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso2022-jp, escape-driven.E.name..iso2022-jp.init..{}.final..{}.ascii..\x1b(B.jis0201..\x1b(J.jis0208..\x1b$B.jis0208..\x1b$@.jis0212..\x1b$(D.gb2312..\x1b$A.ksc5601..\x1b$(C.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):115
                                                                                                                                                                                                                                  Entropy (8bit):4.945508829557185
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SOd5MNXVTEXIBXSl1AEXNELmUHhqQc6XfUNOvn:SVNFS1K+9Qc6sNA
                                                                                                                                                                                                                                  MD5:F6464F7C5E3F642BC3564D59B888C986
                                                                                                                                                                                                                                  SHA1:94C5F39256366ABB68CD67E3025F177F54ECD39D
                                                                                                                                                                                                                                  SHA-256:6AC0F1845A56A1A537B9A6D9BCB724DDDF3D3A5E61879AE925931B1C0534FBB7
                                                                                                                                                                                                                                  SHA-512:B9A7E0A9344D8E883D44D1A975A7C3B966499D34BA6206B15C90250F88A8FA422029CEF190023C4E4BE806791AC3BEA87FD8872B47185B0CE0F9ED9C38C41A84
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso2022-kr, escape-driven.E.name..iso2022-kr.init..\x1b$)C.final..{}.iso8859-1.\x0f.ksc5601..\x0e.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):226
                                                                                                                                                                                                                                  Entropy (8bit):4.925633473589168
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SOd5MNXVUW+IBXSl1AEXM56DfqQc6WHmSjs5dReQSXcRcRZMvs5BCUNxXeR5IHRv:SVNFUX1K+M55Qc6WGSjwRDSXd9NGIHRv
                                                                                                                                                                                                                                  MD5:745464FF8692E3C3D8EBBA38D23538C8
                                                                                                                                                                                                                                  SHA1:9D6F077598A5A86E6EB6A4EEC14810BF525FBD89
                                                                                                                                                                                                                                  SHA-256:753DDA518A7E9F6DC0309721B1FAAE58C9661F545801DA9F04728391F70BE2D0
                                                                                                                                                                                                                                  SHA-512:E919677CC96DEF4C75126A173AF6C229428731AB091CDDBB2A6CE4EB82BCD8191CE64A33B418057A15E094A48E846BEE7820619E414E7D90EDA6E2B66923DDA5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso2022, escape-driven.E.name..iso2022.init..{}.final..{}.iso8859-1.\x1b(B.jis0201..\x1b(J.gb1988..\x1b(T.jis0208..\x1b$B.jis0208..\x1b$@.jis0212..\x1b$(D.gb2312..\x1b$A.ksc5601..\x1b$(C.jis0208..\x1b&@\x1b$B.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):3.163043970763833
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:iyTUmJvRju3ShVbsZiAMiZyb7P4UPvvPNNAkbnMH+tjg:iygmOEVIwAMiw/PTvok7zE
                                                                                                                                                                                                                                  MD5:E3BAE26F5D3D9A4ADCF5AE7D30F4EC38
                                                                                                                                                                                                                                  SHA1:A71B6380EA3D23DC0DE11D3B8CEA86A4C8063D47
                                                                                                                                                                                                                                  SHA-256:754EF6BF3A564228AB0B56DDE391521DCC1A6C83CFB95D4B761141E71D2E8E87
                                                                                                                                                                                                                                  SHA-512:AFED8F5FE02A9A30987736F08B47F1C19339B5410D6020CC7EA37EA0D717A70AF6CDDC775F53CE261FCF215B579206E56458D61AB4CEB44E060BD6B3AC2F4C41
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-1, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF.00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF.00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF.00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF.00E000E100E200E300E400E500E600E700E8
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.2483197762497458
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:jTUmJvRju3ShVbsZiAMiZyb7P4UP6L2yhBKyta:jgmOEVIwAMiw/PT6L2Ryta
                                                                                                                                                                                                                                  MD5:162E76BD187CB54A5C9F0B72A082C668
                                                                                                                                                                                                                                  SHA1:CEC787C4DE78F9DBB97B9C44070CF2C12A2468F7
                                                                                                                                                                                                                                  SHA-256:79F6470D9BEBD30832B3A9CA59CD1FDCA28C5BE6373BD01D949EEE1BA51AA7A8
                                                                                                                                                                                                                                  SHA-512:ADDBCA6E296286220FFF449D3E34E5267528627AFFF1FCBD2B9AC050A068D116452D70308049D88208FB7CB2C2F7582FCF1703CF22CFC125F2E6FA89B8A653FE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-10, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A0010401120122012A0128013600A7013B011001600166017D00AD016A014A.00B0010501130123012B0129013700B7013C011101610167017E2015016B014B.010000C100C200C300C400C500C6012E010C00C9011800CB011600CD00CE00CF.00D00145014C00D300D400D500D6016800D8017200DA00DB00DC00DD00DE00DF.010100E100E200E300E400E500E6012F010
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.267798724121087
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:olTUmJvRju3ShVbsZiAMiZyb7P4UP1w4LaxUVG4dT:olgmOEVIwAMiw/PT+4VfT
                                                                                                                                                                                                                                  MD5:BF3993877A45AC7091CFC81CFD4A4D43
                                                                                                                                                                                                                                  SHA1:D462934A074EE13F2C810463FD061084953F77BC
                                                                                                                                                                                                                                  SHA-256:33C6072A006BA4E9513D7B7FD3D08B1C745CA1079B6D796C36B2A5AE8E4AE02B
                                                                                                                                                                                                                                  SHA-512:17489E6AD6A898628239EA1B43B4BE81ECC33608F0FD3F7F0E19CF74F7FC4752813C3C21F1DC73E9CC8765E23C63ED932799905381431DAF4E10A88EC29EBF6E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-13, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A0201D00A200A300A4201E00A600A700D800A9015600AB00AC00AD00AE00C6.00B000B100B200B3201C00B500B600B700F800B9015700BB00BC00BD00BE00E6.0104012E0100010600C400C501180112010C00C90179011601220136012A013B.01600143014500D3014C00D500D600D701720141015A016A00DC017B017D00DF.0105012F0101010700E400E501190113010
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.296489289648924
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:vTUmJvRju3ShVbsZiAMiZyb7P4UPt6C5AkE7MH+tZS4Y:vgmOEVIwAMiw/PTAQAkCzsP
                                                                                                                                                                                                                                  MD5:3BE4986264587BEC738CC46EBB43D698
                                                                                                                                                                                                                                  SHA1:62C253AA7A868CE32589868FAB37336542457A96
                                                                                                                                                                                                                                  SHA-256:8D737283289BAF8C08EF1DD7E47A6C775DACE480419C5E2A92D6C0E85BB5B381
                                                                                                                                                                                                                                  SHA-512:CB9079265E47EF9672EAACFCE474E4D6771C6F61394F29CC59C9BBE7C99AE89A0EACD73F2BCDD8374C4E03BE9B1685F463F029E35C4070DF9D1B143B02CAD573
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-14, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A01E021E0300A3010A010B1E0A00A71E8000A91E821E0B1EF200AD00AE0178.1E1E1E1F012001211E401E4100B61E561E811E571E831E601EF31E841E851E61.00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF.017400D100D200D300D400D500D61E6A00D800D900DA00DB00DC00DD017600DF.00E000E100E200E300E400E500E600E700E
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.1878838020538374
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:mTUmJvRju3ShVbsZiAMiZyb7P4UPvRarkbnMH+tjg:mgmOEVIwAMiw/PTvqk7zE
                                                                                                                                                                                                                                  MD5:6AE49F4E916B02EB7EDB160F88B5A27F
                                                                                                                                                                                                                                  SHA1:49F7A42889FB8A0D78C80067BDE18094DBE956EE
                                                                                                                                                                                                                                  SHA-256:C7B0377F30E42048492E4710FE5A0A54FA9865395B8A6748F7DAC53B901284F9
                                                                                                                                                                                                                                  SHA-512:397E636F4B95522FD3909B4546A1B7E31E92388DAE4F9F6B638875449E3498B49320F4C4A47168C7ADD43C78EF5680CAAEE40661DDC8205687532D994133EA3B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-15, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A000A100A200A320AC00A5016000A7016100A900AA00AB00AC00AD00AE00AF.00B000B100B200B3017D00B500B600B7017E00B900BA00BB01520153017800BF.00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF.00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF.00E000E100E200E300E400E500E600E700E
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.2349228762697972
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:dTUmJvRju3ShVbsZiAMiZyb7P4UP/SlTPkyTtZVc:dgmOEVIwAMiw/PTqFPkypXc
                                                                                                                                                                                                                                  MD5:D30094CAEFA5C4A332159829C6CB7FEC
                                                                                                                                                                                                                                  SHA1:50FDA6C70A133CB64CF38AA4B2F313B54D2FD955
                                                                                                                                                                                                                                  SHA-256:C40CA014B88F97AE62AE1A816C5963B1ED432A77D84D89C3A764BA15C8A23708
                                                                                                                                                                                                                                  SHA-512:6EDD6912053D810D1E2B0698494D26E119EF1BF3FABC2FBFBA44551792800FA0CF163773E4F37F908C2DE41F05D6F17153656623A6D4681BE74EB253D9163422
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-16, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A001040105014120AC201E016000A7016100A9021800AB017900AD017A017B.00B000B1010C0142017D201D00B600B7017E010D021900BB015201530178017C.00C000C100C2010200C4010600C600C700C800C900CA00CB00CC00CD00CE00CF.0110014300D200D300D4015000D6015A017000D900DA00DB00DC0118021A00DF.00E000E100E2010300E4010700E600E700E
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):3.269412550127009
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:UTUmJvRju3ShVbsZiAMiZyb7P4UPPssm0O4yT2H:UgmOEVIwAMiw/PTPss5tyT2H
                                                                                                                                                                                                                                  MD5:69FCA2E8F0FD9B39CDD908348BD2985E
                                                                                                                                                                                                                                  SHA1:FF62EB5710FDE11074A87DAEE9229BCF7F66D7A0
                                                                                                                                                                                                                                  SHA-256:0E0732480338A229CC3AD4CDDE09021A0A81902DC6EDFB5F12203E2AFF44668F
                                                                                                                                                                                                                                  SHA-512:46A7899D17810D2E0FF812078D91F29BF2BB8770F09A02367CF8361229F424FC9B06EAC8E3756491612972917463B6F27DB3D897AFAE8DB5F159D45975D9CBD8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-2, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A0010402D8014100A4013D015A00A700A80160015E0164017900AD017D017B.00B0010502DB014200B4013E015B02C700B80161015F0165017A02DD017E017C.015400C100C2010200C40139010600C7010C00C9011800CB011A00CD00CE010E.01100143014700D300D4015000D600D70158016E00DA017000DC00DD016200DF.015500E100E2010300E4013A010700E7010D
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):3.178020305301999
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:tTUmJvRju3ShVbsZiAMiZyb7P4UPp2g4kBTvSMkFtP0:tgmOEVIwAMiw/PTj4kBTvSDP0
                                                                                                                                                                                                                                  MD5:5685992A24D85E93BD8EA62755E327BA
                                                                                                                                                                                                                                  SHA1:B0BEBEDEC53FFB894D9FB0D57F25AB2A459B6DD5
                                                                                                                                                                                                                                  SHA-256:73342C27CF55F625D3DB90C5FC8E7340FFDF85A51872DBFB1D0A8CB1E43EC5DA
                                                                                                                                                                                                                                  SHA-512:E88ED02435026CA9B8A23073F61031F3A75C4B2CD8D2FC2B598F924ADF34B268AB16909120F1D96B794BDBC484C764FDE83B63C9FB122279AC5242D57030AF3A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-3, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A0012602D800A300A40000012400A700A80130015E011E013400AD0000017B.00B0012700B200B300B400B5012500B700B80131015F011F013500BD0000017C.00C000C100C2000000C4010A010800C700C800C900CA00CB00CC00CD00CE00CF.000000D100D200D300D4012000D600D7011C00D900DA00DB00DC016C015C00DF.00E000E100E2000000E4010B010900E700E8
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):3.2703067063488724
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:KTUmJvRju3ShVbsZiAMiZyb7P4UP04xsD/njwKyjhJ:KgmOEVIwAMiw/PT06s3fylJ
                                                                                                                                                                                                                                  MD5:07576E85AFDB2816BBCFFF80E2A12747
                                                                                                                                                                                                                                  SHA1:CC1C2E6C35B005C17EB7B1A3D744983A86A75736
                                                                                                                                                                                                                                  SHA-256:17745BDD299779E91D41DB0CEE26CDC7132DA3666907A94210B591CED5A55ADB
                                                                                                                                                                                                                                  SHA-512:309EEF25EE991E3321A57D2CEE139C9C3E7C8B3D9408664AAFE9BA34E28EF5FB8167481F3C5CAD0557AE55249E47016CA3A6AC19857D76EFB58D0CDAC428F600
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-4, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A001040138015600A40128013B00A700A8016001120122016600AD017D00AF.00B0010502DB015700B40129013C02C700B80161011301230167014A017E014B.010000C100C200C300C400C500C6012E010C00C9011800CB011600CD00CE012A.01100145014C013600D400D500D600D700D8017200DA00DB00DC0168016A00DF.010100E100E200E300E400E500E6012F010D
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):3.2716690950473573
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:zTUmJvRju3ShVbsZiAMiZyb7P4UPNXe+SAJlM9aHe3cmy+:zgmOEVIwAMiw/PTNp5+smy+
                                                                                                                                                                                                                                  MD5:67577E6720013EEF73923D3F050FBFA1
                                                                                                                                                                                                                                  SHA1:F9F64BB6014068E2C0737186C694B8101DD9575E
                                                                                                                                                                                                                                  SHA-256:BC5ED164D15321404BBDCAD0D647C322FFAB1659462182DBD3945439D9ECBAE7
                                                                                                                                                                                                                                  SHA-512:B584DB1BD5BE97CCFCA2F71E765DEC66CF2ABE18356C911894C988B2238E14074748C71074E0633C7CA50733E189D937160A35438C720DB2243CBC3566F52629
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-5, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A0040104020403040404050406040704080409040A040B040C00AD040E040F.0410041104120413041404150416041704180419041A041B041C041D041E041F.0420042104220423042404250426042704280429042A042B042C042D042E042F.0430043104320433043404350436043704380439043A043B043C043D043E043F.044004410442044304440445044604470448
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):2.9147595181616284
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:YTUmJvRju3ShVbsZiAMiZyb7P4UPSIZjyco/rs:YgmOEVIwAMiw/PTBsBrs
                                                                                                                                                                                                                                  MD5:49DEC951C7A7041314DF23FE26C9B300
                                                                                                                                                                                                                                  SHA1:B810426354D857718CC841D424DA070EFB9F144F
                                                                                                                                                                                                                                  SHA-256:F502E07AE3F19CCDC31E434049CFC733DD5DF85487C0160B0331E40241AD0274
                                                                                                                                                                                                                                  SHA-512:CB5D8C5E807A72F35AD4E7DA80882F348D70052169A7ED5BB585152C2BF628177A2138BD0A982A398A8DF373E1D3E145AD1F6C52485DE57ECBE5A7ED33E13776
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-6, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A000000000000000A40000000000000000000000000000060C00AD00000000.00000000000000000000000000000000000000000000061B000000000000061F.0000062106220623062406250626062706280629062A062B062C062D062E062F.0630063106320633063406350636063706380639063A00000000000000000000.064006410642064306440645064606470648
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):3.2933089629252037
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:TMyTUmJvRju3ShVbsZiAMiZyb7P4UP1mKUQQSqJWeIDmq:TlgmOEVIwAMiw/PTkKJQSqJWeI1
                                                                                                                                                                                                                                  MD5:0AF65F8F07F623FA38E2D732400D95CF
                                                                                                                                                                                                                                  SHA1:D2903B32FEA225F3FB9239E622390A078C8A8FA6
                                                                                                                                                                                                                                  SHA-256:8FEC7631A69FCF018569EBADB05771D892678790A08E63C05E0007C9910D58A8
                                                                                                                                                                                                                                  SHA-512:EF03237A030C54E0E20DBA7ED724580C513490B9B3B043C1E885638E7BCE21415CE56C3902EA39689365B12E44194C6BF868C4D9BCBCA8FDC334BE77DA46E24D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-7, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A02018201900A30000000000A600A700A800A9000000AB00AC00AD00002015.00B000B100B200B303840385038600B703880389038A00BB038C00BD038E038F.0390039103920393039403950396039703980399039A039B039C039D039E039F.03A003A1000003A303A403A503A603A703A803A903AA03AB03AC03AD03AE03AF.03B003B103B203B303B403B503B603B703B8
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):2.9730608214144323
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:uTUmJvRju3ShVbsZiAMiZyb7P4UPtePly0b:ugmOEVIwAMiw/PTtw
                                                                                                                                                                                                                                  MD5:45E35EFF7ED2B2DF0B5694A2B639FE1E
                                                                                                                                                                                                                                  SHA1:4EA5EC5331541EDE65A9CF601F5418FD4B6CFCBC
                                                                                                                                                                                                                                  SHA-256:E1D207917AA3483D9110E24A0CC0CD1E0E5843C8BFC901CFEE7A6D872DD945A9
                                                                                                                                                                                                                                  SHA-512:527283C9EFF2C1B21FAE716F5DFB938D8294B22938C76A73D88135312FA01B5C3DF288461CCE8B692928B334A28A7D29319F9F48733174C898F41BD1BEB8E862
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-8, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A0000000A200A300A400A500A600A700A800A900D700AB00AC00AD00AE00AF.00B000B100B200B300B400B500B600B700B800B900F700BB00BC00BD00BE0000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000002017.05D005D105D205D305D405D505D605D705D8
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1094
                                                                                                                                                                                                                                  Entropy (8bit):3.1865263857127375
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:XTUmJvRju3ShVbsZiAMiZyb7P4UPvvPNNAkKMH+tZL/M:XgmOEVIwAMiw/PTvokKzR0
                                                                                                                                                                                                                                  MD5:675C89ECD212C8524B1875095D78A5AF
                                                                                                                                                                                                                                  SHA1:F585C70A5589DE39558DAC016743FF85E0C5F032
                                                                                                                                                                                                                                  SHA-256:1CDCF510C38464E5284EDCFAEC334E3FC516236C1CA3B9AB91CA878C23866914
                                                                                                                                                                                                                                  SHA-512:E620657C5F521A101B6FF7B5FD9A7F0DDD560166BA109D20E91F2E828F81697F897DFA136533C0D6F24A9861E92F34C0CC0FA590F344713C089157F8AC3ECFE2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: iso8859-9, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF.00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF.00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF.011E00D100D200D300D400D500D600D700D800D900DA00DB00DC0130015E00DF.00E000E100E200E300E400E500E600E700E8
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1092
                                                                                                                                                                                                                                  Entropy (8bit):3.1984111069807395
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:zBTUmJvRju3ShVbsZiAMiZyb7PN8pUPnfk5JM0RHFj:zBgmOEVIwAMiw/PNPQPFj
                                                                                                                                                                                                                                  MD5:0DCB64ACBB4B518CC20F4E196E04692C
                                                                                                                                                                                                                                  SHA1:7AEB708C89C178FB4D5611C245EA1A7CF66ADF3A
                                                                                                                                                                                                                                  SHA-256:480F61D0E1A75DEE59BF9A66DE0BB78FAAE4E87FD6317F93480412123277D442
                                                                                                                                                                                                                                  SHA-512:4AFA210763DE9742626886D7D281AC15169CDC7A31D185F48D105190CA247AA014FB8F281AFCB4A0C31D2D55EE7D907B6A8E51FC4BEEDB9DB8C484E88CAA78A9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: jis0201, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D203E007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F.FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F.FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F.FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F.00000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):80453
                                                                                                                                                                                                                                  Entropy (8bit):2.274731552146978
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:R7Cyeug/RAEo7umlshyGYknyRXglMVw9bq7bYI45zh2cvA3FXwhZ1BrUc2C5oS5u:RgZJo7uNhbyO1ZiEXPcXwhZbrUPkBso2
                                                                                                                                                                                                                                  MD5:F35938AC582E460A14646D2C93F1A725
                                                                                                                                                                                                                                  SHA1:A922ACACE0C1A4A7DDC92FE5DD7A116D30A3686B
                                                                                                                                                                                                                                  SHA-256:118EA160EF29E11B46DEC57AF2C44405934DD8A7C49D2BC8B90C94E8BAA6138B
                                                                                                                                                                                                                                  SHA-512:D27CD9C9D67370C288036AACA5999314231F7070152FF7EEF1F3379E748EF9047001430D391B61C281FF69AB4F709D47F8FF5390873B5DEFD105371AB8FB8872
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: jis0208, double-byte.D.2129 0 77.21.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000300030013002FF0CFF0E30FBFF1AFF1BFF1FFF01309B309C00B4FF4000A8.FF3EFFE3FF3F30FD30FE309D309E30034EDD30053006300730FC20152010FF0F.FF3C301C2016FF5C2026202520182019201C201DFF08FF0930143015FF3BFF3D.FF5BFF5D30083009300A300B300C300D300E300F30103011FF0B221200B100D7.00F7FF1D2260FF1CFF1E22662267221E22342642264000B0203220332103FFE5.FF0400A200A3FF05FF03FF06FF0AFF2000A72606260525CB25CF25CE25C70000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):70974
                                                                                                                                                                                                                                  Entropy (8bit):2.2631380488363284
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:WmU4+qNPpEzjKgGWJACVeCssX2Qt5E2+G7PBIv:LU4+qNaCgGW7VGK2o+0qv
                                                                                                                                                                                                                                  MD5:F518436AC485F5DC723518D7872038E0
                                                                                                                                                                                                                                  SHA1:15013478760463A0BCE3577B4D646ECDB07632B5
                                                                                                                                                                                                                                  SHA-256:24A9D379FDA39F2BCC0580CA3E0BD2E99AE279AF5E2841C9E7DBE7F931D19CC0
                                                                                                                                                                                                                                  SHA-512:2325705D4772A10CD81082A035BEAC85E6C64C7CCFA5981955F0B85CAF9A95D8A0820092957822A05C2E8E773F2089035ED5E76BF3FAF19B0E7E6AED7B4214D8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: jis0212, double-byte.D.2244 0 68.22.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.00000000000000000000000000000000000000000000000000000000000002D8.02C700B802D902DD00AF02DB02DA007E03840385000000000000000000000000.0000000000A100A600BF00000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000BA00AA00A900AE2122.00A4211600000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1091
                                                                                                                                                                                                                                  Entropy (8bit):3.463428231669408
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:KcJ5mTUmJvRju3ShVbsZiAMiZyb7PcSzm1XvRS3YcmchJQ3MAxSy:KmmgmOEVIwAMiw/Ptz8gBmRcAx5
                                                                                                                                                                                                                                  MD5:E66D42CB71669CA0FFBCDC75F6292832
                                                                                                                                                                                                                                  SHA1:366C137C02E069B1A93FBB5D64B9120EA6E9AD1F
                                                                                                                                                                                                                                  SHA-256:7142B1120B993D6091197574090FE04BE3EA64FFC3AD5A167A4B5E0B42C9F062
                                                                                                                                                                                                                                  SHA-512:6FBF7AF0302B4AA7EF925EFED7235E946EDA8B628AA204A8BBB0A3D1CB8C79DD37D9DD92A276AD14B55776FEBB3B55CF5881AC4013F95ED4E618E3B49771E8A5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: koi8-r, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.25002502250C251025142518251C2524252C2534253C258025842588258C2590.259125922593232025A02219221A22482264226500A0232100B000B200B700F7.25502551255204512553255425552556255725582559255A255B255C255D255E.255F25602561040125622563256425652566256725682569256A256B256C00A9.044E0430043104460434043504440433044504380439043A043B043C043D043E.043F044F044004410442044304360432044C044B04370448044D04490447044A.042E04100411042604140415042404130425041
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1091
                                                                                                                                                                                                                                  Entropy (8bit):3.439504497428066
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:K+TUmJvRju3ShVbsZiAMiZyb7PcSzmn3gXDRS3YcmchJQ3MAxSy:K+gmOEVIwAMiw/Ptz0KgBmRcAx5
                                                                                                                                                                                                                                  MD5:D722EFEA128BE671A8FDA45ED7ADC586
                                                                                                                                                                                                                                  SHA1:DA9E67F64EC4F6A74C60CB650D5A12C4430DCFF7
                                                                                                                                                                                                                                  SHA-256:BBB729B906F5FC3B7EE6694B208B206D19A9D4DC571E235B9C94DCDD4A323A2A
                                                                                                                                                                                                                                  SHA-512:FDF183C1A0D9109E21F7EEBC5996318AEDED3F87319A980C4E96BFE1D43593BDB693D181744C5C7E391A849783E3594234060A9F76116DE56F9592EF95979E63
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: koi8-u, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.25002502250C251025142518251C2524252C2534253C258025842588258C2590.259125922593232025A02219221A22482264226500A0232100B000B200B700F7.25502551255204510454255404560457255725582559255A255B0491255D255E.255F25602561040104032563040604072566256725682569256A0490256C00A9.044E0430043104460434043504440433044504380439043A043B043C043D043E.043F044F044004410442044304360432044C044B04370448044D04490447044A.042E04100411042604140415042404130425041
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):92877
                                                                                                                                                                                                                                  Entropy (8bit):2.32911747373862
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:XtWS2ymX62EztZ1Oyxk1uGtQPUNg0q+6XVfEFh:XtWnzEn1HxRQQPV0Eeh
                                                                                                                                                                                                                                  MD5:599CEA614F5C5D01CDFA433B184AA904
                                                                                                                                                                                                                                  SHA1:C2FFA427457B4931E5A92326F251CD3D671059B0
                                                                                                                                                                                                                                  SHA-256:0F8B530AD0DECBF8DD81DA8291B8B0F976C643B5A292DB84680B31ECFBE5D00A
                                                                                                                                                                                                                                  SHA-512:43D24B719843A21E3E1EDDFC3607B1B198542306C2EC8D621188CD39BA913D23678D39D12D8370CC1CE12828661AF0A5F14AD2B2BF99F62387C5E3E365BA1E75
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: ksc5601, double-byte.D.233F 0 89.21.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.000030003001300200B72025202600A8300300AD20152225FF3C223C20182019.201C201D3014301530083009300A300B300C300D300E300F3010301100B100D7.00F7226022642265221E223400B0203220332103212BFFE0FFE1FFE526422640.222022A52312220222072261225200A7203B2606260525CB25CF25CE25C725C6.25A125A025B325B225BD25BC219221902191219321943013226A226B221A223D.221D2235222B222C2208220B2286228722822283222A222922272228FFE20000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1096
                                                                                                                                                                                                                                  Entropy (8bit):3.3601842107710365
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8jTUmJvRju3ShVbsZiAMiZyb7P4ZVPJS82WcVDX1MPEd4RPMppJ8K:8jgmOEVIwAMiw/PsVoy24VMppiK
                                                                                                                                                                                                                                  MD5:CADFBF5A4C7CAD984294284D643E9CA3
                                                                                                                                                                                                                                  SHA1:16B51D017001688A32CB7B15DE6E7A49F28B76FD
                                                                                                                                                                                                                                  SHA-256:8F3089F4B2CA47B7AC4CB78375B2BFAC01268113A7C67D020F8B5B7F2C25BBDA
                                                                                                                                                                                                                                  SHA-512:3941ACA62CF59BF6857BA9C300B4236F18690DE1213BB7FCFA0EC87DCD71152849F1DEAFB470CA4BC2ACC2C0C13D7FD57661BFC053960ADD7570DE365AE7E63C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macCentEuro, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00C40100010100C9010400D600DC00E10105010C00E4010D0106010700E90179.017A010E00ED010F01120113011600F3011700F400F600F500FA011A011B00FC.202000B0011800A300A7202200B600DF00AE00A92122011900A822600123012E.012F012A22642265012B0136220222110142013B013C013D013E0139013A0145.0146014300AC221A01440147220600AB00BB202600A00148015000D50151014C.20132014201C201D2018201900F725CA014D0154015501582039203A01590156.01570160201A201E0161015A015B00C101
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1096
                                                                                                                                                                                                                                  Entropy (8bit):3.3293096097500965
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8ULyTUmJvRju3ShVbsZiAMiZyb7P4SNMdNxOZwl+KR8DklJyseQWkv:8ULygmOEVIwAMiw/P34+KR8DklEswm
                                                                                                                                                                                                                                  MD5:F13D479550D4967A0BC76A60C89F1461
                                                                                                                                                                                                                                  SHA1:63F44E818284384DE07AB0D8B0CD6F7EBFE09AB9
                                                                                                                                                                                                                                  SHA-256:8D0B6A882B742C5CCE938241328606C111DDA0CB83334EBEDCDA17605F3641AE
                                                                                                                                                                                                                                  SHA-512:80AB9DCAAC1A496FD2CA6BE9959FE2DE201F504D8A58D114F2FF5D1F6AAD507F052B87D29D3EBA69093C3D965CC4C113C9EA6DB8EEBB67BD620ADF860CA2CC35
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macCroatian, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8.00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC.202000B000A200A300A7202200B600DF00AE0160212200B400A82260017D00D8.221E00B122642265220600B522022211220F0161222B00AA00BA03A9017E00F8.00BF00A100AC221A01922248010600AB010C202600A000C000C300D501520153.01102014201C201D2018201900F725CAF8FF00A9204420AC2039203A00C600BB.201300B7201A201E203000C2010700C101
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1096
                                                                                                                                                                                                                                  Entropy (8bit):3.3482225358368565
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8dTUmJvRju3ShVbsZiAMiZyb7P4GE+SAJlM9aDpiR/Pk956e3cmh:8dgmOEVIwAMiw/Pr5NY3k9nsmh
                                                                                                                                                                                                                                  MD5:60FFC8E390A31157D8646AEAC54E58AE
                                                                                                                                                                                                                                  SHA1:3DE17B2A5866272602FB8E9C54930A4CD1F3B06C
                                                                                                                                                                                                                                  SHA-256:EB135A89519F2E004282DED21B11C3AF7CCB2320C9772F2DF7D1A4A1B674E491
                                                                                                                                                                                                                                  SHA-512:3644429A9BD42ADC356E1BD6FCFABEE120E851348B538A4FE4903B72A533174D7448A6C2DA71219E4CD5D0443C0475417D54C8E113005DF2CA20C608DE5E3306
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macCyrillic, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0410041104120413041404150416041704180419041A041B041C041D041E041F.0420042104220423042404250426042704280429042A042B042C042D042E042F.202000B0049000A300A7202200B6040600AE00A9212204020452226004030453.221E00B122642265045600B504910408040404540407045704090459040A045A.0458040500AC221A01922248220600AB00BB202600A0040B045B040C045C0455.20132014201C201D2018201900F7201E040E045E040F045F211604010451044F.0430043104320433043404350436043704
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1096
                                                                                                                                                                                                                                  Entropy (8bit):3.8086748658227827
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:87JM0UmJvRjuyfqYCsUBOdXBCbtwHviANskNWkiXFtoE4OSFgHrBPkq:87KfmOEqYCs6CXRPiANHWkiXFt9XSMdf
                                                                                                                                                                                                                                  MD5:EBD121A4E93488A48FC0A06ADE9FD158
                                                                                                                                                                                                                                  SHA1:A40E6DB97D6DB2893A072B2275DC22E2A4D60737
                                                                                                                                                                                                                                  SHA-256:8FBCC63CB289AFAAE15B438752C1746F413F3B79BA5845C2EF52BA1104F8BDA6
                                                                                                                                                                                                                                  SHA-512:26879ABE4854908296F32B2BB97AEC1F693C56EC29A7DB9B63B2DA62282F2D2EDAE9D50738595D1530731DF5B1812719A74F50ADF521F80DD5067F3DF6A3517C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macDingbats, single-byte.S.003F 1 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.00202701270227032704260E2706270727082709261B261E270C270D270E270F.2710271127122713271427152716271727182719271A271B271C271D271E271F.2720272127222723272427252726272726052729272A272B272C272D272E272F.2730273127322733273427352736273727382739273A273B273C273D273E273F.2740274127422743274427452746274727482749274A274B25CF274D25A0274F.27502751275225B225BC25C6275625D727582759275A275B275C275D275E007F.F8D7F8D8F8D9F8DAF8DBF8DCF8DDF8DEF8DFF8E0F8E1F8E2F8E3F8E4008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.0000276127622763276427652766276726632666266526602460246124622463.2464246524662467246824692776277727782779277A277B277C277D277E277F.2780278127822783278427852786278727882789278A278B278C278D278E278F.2790279127922793279421922194219527982799279A279B279C279D279E279F.27A027A127A227A327A427A527A627A727
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1093
                                                                                                                                                                                                                                  Entropy (8bit):3.4271472017271556
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8dOTUmJvRju3ShVbsZiAMiZyb7P4Hlb7BMM2aSYjsSkUEkp1FsOSUTime:8kgmOEVIwAMiw/Pg7K23s0x1FsOJTime
                                                                                                                                                                                                                                  MD5:14AD68855168E3E741FE179888EA7482
                                                                                                                                                                                                                                  SHA1:9C2AD53D69F5077853A05F0933330B5D6F88A51C
                                                                                                                                                                                                                                  SHA-256:F7BFF98228DED981EC9A4D1D0DA62247A8D23F158926E3ACBEC3CCE379C998C2
                                                                                                                                                                                                                                  SHA-512:FB13F32197D3582BC20EEA604A0B0FD7923AE541CCEB3AF1CDE36B0404B8DB6312FB5270B40CBC8BA4C91B9505B57FB357EB875E8AFB3DB76DFB498CE17851ED
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macGreek, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00C400B900B200C900B300D600DC038500E000E200E4038400A800E700E900E8.00EA00EB00A3212200EE00EF202200BD203000F400F600A600AD00F900FB00FC.2020039303940398039B039E03A000DF00AE00A903A303AA00A7226000B000B7.039100B12264226500A503920395039603970399039A039C03A603AB03A803A9.03AC039D00AC039F03A1224803A400AB00BB202600A003A503A7038603880153.20132015201C201D2018201900F70389038A038C038E03AD03AE03AF03CC038F.03CD03B103B203C803B403B503C603B303B70
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.3292041026777457
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8KTUmJvRju3ShVbsZiAMiZyb7P4SNMVtOZm5YRMdjY4g4JysAWD:8KgmOEVIwAMiw/Pf2YRMFBEszD
                                                                                                                                                                                                                                  MD5:6D52A84C06970CD3B2B7D8D1B4185CE6
                                                                                                                                                                                                                                  SHA1:C434257D76A9FDF81CCCD8CC14242C8E3940FD89
                                                                                                                                                                                                                                  SHA-256:633F5E3E75BF1590C94AB9CBF3538D0F0A7A319DB9016993908452D903D9C4FD
                                                                                                                                                                                                                                  SHA-512:711F4DC86DD609823BF1BC5505DEE9FA3875A8AA7BCA31DC1B5277720C5ABE65B62E8A592FC55D99D1C7CA181FDDC2606551C43A9D12489B9FECFF152E9A3DCF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macIceland, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8.00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC.00DD00B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8.221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8.00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153.20132014201C201D2018201900F725CA00FF0178204420AC00D000F000DE00FE.00FD00B7201A201E203000C200CA00C100C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):48028
                                                                                                                                                                                                                                  Entropy (8bit):3.3111639331656635
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:ehuW1PJnT9TO7RaQiPCLUKr7KBi9FrOLdtHJ:eZPV9KuqTxFGXp
                                                                                                                                                                                                                                  MD5:105B49F855C77AE0D3DED6C7130F93C2
                                                                                                                                                                                                                                  SHA1:BA187C52FAE9792DA5BFFBEAA781FD4E0716E0F6
                                                                                                                                                                                                                                  SHA-256:2A6856298EC629A16BDD924711DFE3F3B1E3A882DDF04B7310785D83EC0D566C
                                                                                                                                                                                                                                  SHA-512:5B5FBE69D3B67AF863759D92D4A68481EC2211FF84ED9F0B3BD6129857966DE32B42A42432C44B9246C9D0D9C4C546CD3C6D13FF49BD338192C24AD053C0602E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macJapan, multi-byte.M.003F 0 46.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.00A0FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F.FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F.FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F.FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F.0000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1093
                                                                                                                                                                                                                                  Entropy (8bit):3.3361385497578406
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8TTUmJvRju3ShVbsZiAMiZyb7P4SNMVtOZm5YRMdjBtRg4JysAWD:8TgmOEVIwAMiw/P32YRMTtRBEszD
                                                                                                                                                                                                                                  MD5:30BECAE9EFD678B6FD1E08FB952A7DBE
                                                                                                                                                                                                                                  SHA1:E4D8EA6A0E70BB793304CA21EB1337A7A2C26A31
                                                                                                                                                                                                                                  SHA-256:68F22BAD30DAA81B215925416C1CC83360B3BB87EFC342058929731AC678FF37
                                                                                                                                                                                                                                  SHA-512:E87105F7A5A983ACEAC55E93FA802C985B2B19F51CB3C222B4C13DDCF17C32D08DF323C829FB4CA33770B668485B7D14B7F6B0CF2287B0D76091DE2A675E88BD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macRoman, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8.00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC.202000B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8.221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8.00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153.20132014201C201D2018201900F725CA00FF0178204420AC2039203AFB01FB02.202100B7201A201E203000C200CA00C100CB0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.342586490827578
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8tTUmJvRju3ShVbsZiAMiZyb7P4SNMVZSxOZFYRMdj/TAg4JysAWD:8tgmOEVIwAMiw/P3AtYRMFTABEszD
                                                                                                                                                                                                                                  MD5:C9AD5E42DA1D2C872223A14CC76F1D2B
                                                                                                                                                                                                                                  SHA1:E257BD16EF34FDC29D5B6C985A1B45801937354C
                                                                                                                                                                                                                                  SHA-256:71AE80ADFB437B7BC88F3C76FD37074449B3526E7AA5776D2B9FD5A43C066FA8
                                                                                                                                                                                                                                  SHA-512:74588523D35A562AD4B1AF2B570596194D8C5018D5B44C8BA2B1F6BAD422D06E90172B0E65BB975663F3A3C246BCF2F598E9778BA86D1C5A51F5C0A38A2670EC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macRomania, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8.00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC.202000B000A200A300A7202200B600DF00AE00A9212200B400A822600102015E.221E00B12264226500A500B522022211220F03C0222B00AA00BA21260103015F.00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153.20132014201C201D2018201900F725CA00FF0178204400A42039203A01620163.202100B7201A201E203000C200CA00C100C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1092
                                                                                                                                                                                                                                  Entropy (8bit):3.539905812302991
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:88TUmJvRju3ShVbsZiAMiZyb7P4oJi8XPHmED43U/Tmh:88gmOEVIwAMiw/PNJpP43U0
                                                                                                                                                                                                                                  MD5:163729C7C2B1F5A5DE1FB7866C93B102
                                                                                                                                                                                                                                  SHA1:633D190B5E281CFC0178F6C11DD721C6A266F643
                                                                                                                                                                                                                                  SHA-256:CEAD5EB2B0B44EF4003FBCB2E49CA0503992BA1D6540D11ACBBB84FDBBD6E79A
                                                                                                                                                                                                                                  SHA-512:2093E3B59622E61F29276886911FAA50BA3AA9D903CAF8CB778A1D3FDB3D1F7DA43071AFC3672C27BE175E7EEBBC542B655A85533F41EA39F32E80663CAF3B44
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macThai, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00AB00BB2026F88CF88FF892F895F898F88BF88EF891F894F897201C201DF899.FFFD2022F884F889F885F886F887F888F88AF88DF890F893F89620182019FFFD.00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F.0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F.0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F.0E300E310E320E330E340E350E360E370E380E390E3AFEFF200B201320140E3F.0E400E410E420E430E440E450E460E470E480E
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.353168947106635
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8QjTUmJvRju3ShVbsZiAMiZyb7P4SNMVtOZm5YRMdD/g4JysD:88gmOEVIwAMiw/P32YRM9BEsD
                                                                                                                                                                                                                                  MD5:F20CBBE1FF9289AC4CBAFA136A9D3FF1
                                                                                                                                                                                                                                  SHA1:382E34824AD8B79EF0C98FD516750649FD94B20A
                                                                                                                                                                                                                                  SHA-256:F703B7F74CC6F5FAA959F51C757C94623677E27013BCAE23BEFBA01A392646D9
                                                                                                                                                                                                                                  SHA-512:23733B711614EA99D954E92C6035DAC1237866107FE11CDD5B0CD2A780F22B9B7B879570DB38C6B9195F54DAD9DFB0D60641AB37DFF3C51CF1A11D1D36471B2D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macTurkish, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.00C400C500C700C900D100D600DC00E100E000E200E400E300E500E700E900E8.00EA00EB00ED00EC00EE00EF00F100F300F200F400F600F500FA00F900FB00FC.202000B000A200A300A7202200B600DF00AE00A9212200B400A8226000C600D8.221E00B12264226500A500B522022211220F03C0222B00AA00BA03A900E600F8.00BF00A100AC221A01922248220600AB00BB202600A000C000C300D501520153.20132014201C201D2018201900F725CA00FF0178011E011F01300131015E015F.202100B7201A201E203000C200CA00C100C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1095
                                                                                                                                                                                                                                  Entropy (8bit):3.3460856516901947
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8TzTUmJvRju3ShVbsZiAMiZyb7P4GE+SAJlM9aDpiR/Pk956e3cmq:8PgmOEVIwAMiw/Pr5NY3k9nsmq
                                                                                                                                                                                                                                  MD5:92716A59D631BA3A352DE0872A5CF351
                                                                                                                                                                                                                                  SHA1:A487946CB2EFD75FD748503D75E495720B53E5BC
                                                                                                                                                                                                                                  SHA-256:4C94E7FBE183379805056D960AB624D78879E43278262E4D6B98AB78E5FEFEA8
                                                                                                                                                                                                                                  SHA-512:863A667B6404ED02FE994089320EB0ECC34DC431D591D661277FB54A2055334DBEBCAAE1CA06FB8D190727EBA23A47B47991323BE35E74C182F83E5DEAA0D83B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: macUkraine, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0410041104120413041404150416041704180419041A041B041C041D041E041F.0420042104220423042404250426042704280429042A042B042C042D042E042F.202000B0049000A300A7202200B6040600AE00A9212204020452226004030453.221E00B122642265045600B504910408040404540407045704090459040A045A.0458040500AC221A01922248220600AB00BB202600A0040B045B040C045C0455.20132014201C201D2018201900F7201E040E045E040F045F211604010451044F.04300431043204330434043504360437043
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):41862
                                                                                                                                                                                                                                  Entropy (8bit):3.4936148161949747
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:/huW1PJnT9TOZRaQiPCLUKr7KBi9FrOLdtY:/ZPV9KoqTxFGXY
                                                                                                                                                                                                                                  MD5:8FBCB1BBC4B59D6854A8FCBF25853E0D
                                                                                                                                                                                                                                  SHA1:2D56965B24125D999D1020C7C347B813A972647C
                                                                                                                                                                                                                                  SHA-256:7502587D52E7810228F2ECB45AC4319EA0F5C008B7AC91053B920010DC6DDF94
                                                                                                                                                                                                                                  SHA-512:128E66F384F9EA8F3E7FBEAD0D3AA1D45570EB3669172269A89AE3B522ED44E4572C6A5C9281B7E219579041D14FF0E76777A36E3902BFA1B58DC3DA729FA075
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: shiftjis, multi-byte.M.003F 0 40.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E007F.0080000000000000000000850086008700000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F.FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F.FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F.FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F.0000000000000000000000000000000000000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1091
                                                                                                                                                                                                                                  Entropy (8bit):3.675943323650254
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:Sd0UmJvRjuLoVoMQVoRmSdsTAsSnP9Us+yw4VivXObCXv:afmOEVoMQVoRmosTHSP9U/ydmXwCXv
                                                                                                                                                                                                                                  MD5:1B612907F31C11858983AF8C009976D6
                                                                                                                                                                                                                                  SHA1:F0C014B6D67FC0DC1D1BBC5F052F0C8B1C63D8BF
                                                                                                                                                                                                                                  SHA-256:73FD2B5E14309D8C036D334F137B9EDF1F7B32DBD45491CF93184818582D0671
                                                                                                                                                                                                                                  SHA-512:82D4A8F9C63F50E5D77DAD979D3A59729CD2A504E7159AE3A908B7D66DC02090DABD79B6A6DC7B998C32C383F804AACABC564A5617085E02204ADF0B13B13E5B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: symbol, single-byte.S.003F 1 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002122000023220300250026220D002800292217002B002C2212002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.22450391039203A70394039503A603930397039903D1039A039B039C039D039F.03A0039803A103A303A403A503C203A9039E03A80396005B2234005D22A5005F.F8E503B103B203C703B403B503C603B303B703B903D503BA03BB03BC03BD03BF.03C003B803C103C303C403C503D603C903BE03C803B6007B007C007D223C007F.0080008100820083008400850086008700880089008A008B008C008D008E008F.0090009100920093009400950096009700980099009A009B009C009D009E009F.000003D2203222642044221E0192266326662665266021942190219121922193.00B000B12033226500D7221D2202202200F72260226122482026F8E6F8E721B5.21352111211C21182297229522052229222A2283228722842282228622082209.2220220700AE00A92122220F221A22C500AC2227222821D421D021D121D221D3.22C42329F8E8F8E9F8EA2211F8EBF8ECF8EDF8E
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1091
                                                                                                                                                                                                                                  Entropy (8bit):2.9763240350841884
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:ZlTUmJvRju3ShVbsZiAMiZyb7PNHmED43U/TW5dF:PgmOEVIwAMiw/PJ43UKF
                                                                                                                                                                                                                                  MD5:7273E998972C9EFB2CEB2D5CD553DE49
                                                                                                                                                                                                                                  SHA1:4AA47E6DF964366FA3C29A0313C0DAE0FA63A78F
                                                                                                                                                                                                                                  SHA-256:330517F72738834ECBF4B6FA579F725B4B33AD9F4669975E727B40DF185751FF
                                                                                                                                                                                                                                  SHA-512:56BF15C123083D3F04FE0C506EE8ECE4C08C17754F0CAAD3566F1469728CFD2F0A487023DCB26432240EB09F064944D3EF08175979F5D1D2BF734E7C7C609055
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Encoding file: tis-620, single-byte.S.003F 0 1.00.0000000100020003000400050006000700080009000A000B000C000D000E000F.0010001100120013001400150016001700180019001A001B001C001D001E001F.0020002100220023002400250026002700280029002A002B002C002D002E002F.0030003100320033003400350036003700380039003A003B003C003D003E003F.0040004100420043004400450046004700480049004A004B004C004D004E004F.0050005100520053005400550056005700580059005A005B005C005D005E005F.0060006100620063006400650066006700680069006A006B006C006D006E006F.0070007100720073007400750076007700780079007A007B007C007D007E0000.0000000000000000000000000000000000000000000000000000000000000000.0000000000000000000000000000000000000000000000000000000000000000.00000E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F.0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F.0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F.0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F.0E400E410E420E430E440E450E460E470E480E
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7900
                                                                                                                                                                                                                                  Entropy (8bit):4.806010360595623
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:DXzSaH9ox7j4LaQMpsyGb0XEACrHpff6Jy8qNy6QRIt5QYTLa3QAQYplavQqQIL0:DpH9m7DPnQdg+Q
                                                                                                                                                                                                                                  MD5:E8FD468CCD2EE620544FE204BDE2A59D
                                                                                                                                                                                                                                  SHA1:2E26B7977D900EAA7D4908D5113803DF6F34FC59
                                                                                                                                                                                                                                  SHA-256:9B6E400EB85440EC64AB66B4AC111546585740C9CA61FD156400D7153CBAD9F4
                                                                                                                                                                                                                                  SHA-512:13A40A4BDE32F163CB789C69BD260ABF41C6771E7AC50FB122C727B9F39BE5D73E4D8BAE040DDDD94C5F2B901AB7C32D9C6BB62310121CA8DB4ADE25CB9AA4B0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# history.tcl --.#.# Implementation of the history command..#.# Copyright (c) 1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution of.# this file, and for a DISCLAIMER OF ALL WARRANTIES..#...# The tcl::history array holds the history list and some additional.# bookkeeping variables..#.# nextid.the index used for the next history list item..# keep..the max size of the history list.# oldest.the index of the oldest item in the history...namespace eval ::tcl {. variable history. if {![info exists history]} {..array set history {.. nextid.0.. keep.20.. oldest.-20..}. }.. namespace ensemble create -command ::tcl::history -map {..add.::tcl::HistAdd..change.::tcl::HistChange..clear.::tcl::HistClear..event.::tcl::HistEvent..info.::tcl::HistInfo..keep.::tcl::HistKeep..nextid.::tcl::HistNextID..redo.::tcl::HistRedo. }.}...# history --.#.#.This is the main history command. See the man page for its interface..#.This does s
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9689
                                                                                                                                                                                                                                  Entropy (8bit):4.754346192989986
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:kQkH8VqqNg5PPx7GRpoMJesrCL2coOG0vARQVSDR6VrKj7vWQYQN81QvLbDdv:pVqeglpu6toO3ACUnvv
                                                                                                                                                                                                                                  MD5:1DA12C32E7E4C040BD9AB2BCBAC5445B
                                                                                                                                                                                                                                  SHA1:8E8659BEF065AF9430509BBDD5FB4CFE0EF14153
                                                                                                                                                                                                                                  SHA-256:ACBFF9B5EF75790920B95023156FAD80B18AFF8CAFC4A6DC03893F9388E053A2
                                                                                                                                                                                                                                  SHA-512:A269C76C1684EC1A2E2AA611ABB459AA3BE2973FD456737BC8C8D2E5C8BC53A26BBC1488062281CA87E38D548281166C4D775C50C695AEC9741FE911BB431EAD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# http.tcl.# Client-side HTTP for GET, POST, and HEAD commands..# These routines can be used in untrusted code that uses the Safesock.# security policy..# These procedures use a callback interface to avoid using vwait,.# which is not defined in the safe base..#.# See the http.n man page for documentation..package provide http 1.0..array set http {. -accept */*. -proxyhost {}. -proxyport {}. -useragent {Tcl http client package 1.0}. -proxyfilter httpProxyRequired.}.proc http_config {args} {. global http. set options [lsort [array names http -*]]. set usage [join $options ", "]. if {[llength $args] == 0} {..set result {}..foreach name $options {.. lappend result $name $http($name)..}..return $result. }. regsub -all -- - $options {} options. set pat ^-([join $options |])$. if {[llength $args] == 1} {..set flag [lindex $args 0]..if {[regexp -- $pat $flag]} {.. return $http($flag)..} else {.. return -code error "Unknown option $flag, must be:
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):735
                                                                                                                                                                                                                                  Entropy (8bit):4.669068874824871
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:jHxxYRs+opS42wyGlTajUA43KXks4L57+HkuRz20JSv6C3l5kl:bbYRshS42wyGlTah9XkbL5i1z2jxXkl
                                                                                                                                                                                                                                  MD5:10EC7CD64CA949099C818646B6FAE31C
                                                                                                                                                                                                                                  SHA1:6001A58A0701DFF225E2510A4AAEE6489A537657
                                                                                                                                                                                                                                  SHA-256:420C4B3088C9DACD21BC348011CAC61D7CB283B9BEE78AE72EED764AB094651C
                                                                                                                                                                                                                                  SHA-512:34A0ACB689E430ED2903D8A903D531A3D734CB37733EF13C5D243CB9F59C020A3856AAD98726E10AD7F4D67619A3AF1018F6C3E53A6E073E39BD31D088EFD4AF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Tcl package index file, version 1.0.# This file is generated by the "pkg_mkIndex" command.# and sourced either when an application starts up or.# by a "package unknown" script. It invokes the.# "package ifneeded" command to set up package-related.# information so that packages will be loaded automatically.# in response to "package require" commands. When this.# script is sourced, the variable $dir must contain the.# full path name of this file's directory...package ifneeded http 1.0 [list tclPkgSetup $dir http 1.0 {{http.tcl source {httpCopyDone httpCopyStart httpEof httpEvent httpFinish httpMapReply httpProxyRequired http_code http_config http_data http_formatQuery http_get http_reset http_size http_status http_wait}}}].
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Tcl script, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):24432
                                                                                                                                                                                                                                  Entropy (8bit):4.824619671192163
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:U8Oh2gWD8Ud4zaJqacMQsRNLKx32LgWMOFaBBf6/9IrO1zWq8oXbjdEfdQxAp12Q:2OD8Ud4WJqJfcMOFt/9IrOBWq8oXwQxM
                                                                                                                                                                                                                                  MD5:B900811A252BE90C693E5E7AE365869D
                                                                                                                                                                                                                                  SHA1:345752C46F7E8E67DADEF7F6FD514BED4B708FC5
                                                                                                                                                                                                                                  SHA-256:BC492B19308BC011CFCD321F1E6E65E6239D4EEB620CC02F7E9BF89002511D4A
                                                                                                                                                                                                                                  SHA-512:36B8CDBA61B9222F65B055C0C513801F3278A3851912215658BCF0CE10F80197C1F12A5CA3054D8604DA005CE08DA8DCD303B8544706B642140A49C4377DD6CE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# init.tcl --.#.# Default system startup file for Tcl-based applications. Defines.# "unknown" procedure and auto-load facilities..#.# Copyright (c) 1991-1993 The Regents of the University of California..# Copyright (c) 1994-1996 Sun Microsystems, Inc..# Copyright (c) 1998-1999 Scriptics Corporation..# Copyright (c) 2004 by Kevin B. Kenny. All rights reserved..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# This test intentionally written in pre-7.5 Tcl.if {[info commands package] == ""} {. error "version mismatch: library\nscripts expect Tcl version 7.5b1 or later but the loaded version is\nonly [info patchlevel]".}.package require -exact Tcl 8.6.9..# Compute the auto path to use in this interpreter..# The values on the path come from several locations:.#.# The environment variable TCLLIBPATH.#.# tcl_library, which is the directory containing this init.tcl script..# [tclInit] (Tcl_Init()) sea
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):989
                                                                                                                                                                                                                                  Entropy (8bit):4.015702624322247
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu8wcm2NkKcmtH3WhvdfjESBToOqepFHvFgdF69dixmem1OMVjeza6O6c:4azu8DtkN3bbJ75pF9gG3U2e+gc
                                                                                                                                                                                                                                  MD5:3A3B4D3B137E7270105DC7B359A2E5C2
                                                                                                                                                                                                                                  SHA1:2089B3948F11EF8CE4BD3D57167715ADE65875E9
                                                                                                                                                                                                                                  SHA-256:2981965BD23A93A09EB5B4A334ACB15D00645D645C596A5ECADB88BFA0B6A908
                                                                                                                                                                                                                                  SHA-512:044602E7228D2CB3D0A260ADFD0D3A1F7CAB7EFE5DD00C7519EAF00A395A48A46EEFDB3DE81902D420D009B137030BC98FF32AD97E9C3713F0990FE6C09887A2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset af DAYS_OF_WEEK_ABBREV [list \. "So"\. "Ma"\. "Di"\. "Wo"\. "Do"\. "Vr"\. "Sa"]. ::msgcat::mcset af DAYS_OF_WEEK_FULL [list \. "Sondag"\. "Maandag"\. "Dinsdag"\. "Woensdag"\. "Donderdag"\. "Vrydag"\. "Saterdag"]. ::msgcat::mcset af MONTHS_ABBREV [list \. "Jan"\. "Feb"\. "Mar"\. "Apr"\. "Mei"\. "Jun"\. "Jul"\. "Aug"\. "Sep"\. "Okt"\. "Nov"\. "Des"\. ""]. ::msgcat::mcset af MONTHS_FULL [list \. "Januarie"\. "Februarie"\. "Maart"\. "April"\. "Mei"\. "Junie"\. "Julie"\. "Augustus"\. "September"\. "Oktober"\. "November"\. "Desember"\. ""]. ::msgcat::mcset af AM "VM". ::msgcat::mcset af PM "NM".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.879621059534584
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmouFygvNLouFqF3v6aZouFy9+3vR6HK:4EnLzu8YAgvNTYF3v6axAI3voq
                                                                                                                                                                                                                                  MD5:27C356DF1BED4B22DFA55835115BE082
                                                                                                                                                                                                                                  SHA1:677394DF81CDBAF3D3E735F4977153BB5C81B1A6
                                                                                                                                                                                                                                  SHA-256:3C2F5F631ED3603EF0D5BCB31C51B2353C5C27839C806A036F3B7007AF7F3DE8
                                                                                                                                                                                                                                  SHA-512:EE88348C103382F91F684A09F594177119960F87E58C5E4FC718C698AD436E332B74B8ED18DF8563F736515A3A6442C608EBCBE6D1BD13B3E3664E1AA3851076
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset af_ZA DATE_FORMAT "%d %B %Y". ::msgcat::mcset af_ZA TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset af_ZA DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1964
                                                                                                                                                                                                                                  Entropy (8bit):4.417722751563065
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8fnkFewadQxvbkMPm/FiUoAwonC9UFsvSnvMq:46dw/L+C9cKSvF
                                                                                                                                                                                                                                  MD5:0A88A6BFF15A6DABAAE48A78D01CFAF1
                                                                                                                                                                                                                                  SHA1:90834BCBDA9B9317B92786EC89E20DCF1F2DBD22
                                                                                                                                                                                                                                  SHA-256:BF984EC7CF619E700FE7E00381FF58ABE9BD2F4B3DD622EB2EDACCC5E6681050
                                                                                                                                                                                                                                  SHA-512:85CB96321BB6FB3119D69540B9E76916F0C5F534BA01382E73F8F9A0EE67A7F1BFC39947335688F2C8F3DB9B51D969D8EA7C7104A035C0E949E8E009D4656288
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ar DAYS_OF_WEEK_ABBREV [list \. "\u062d"\. "\u0646"\. "\u062b"\. "\u0631"\. "\u062e"\. "\u062c"\. "\u0633"]. ::msgcat::mcset ar DAYS_OF_WEEK_FULL [list \. "\u0627\u0644\u0623\u062d\u062f"\. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\. "\u0627\u0644\u062e\u0645\u064a\u0633"\. "\u0627\u0644\u062c\u0645\u0639\u0629"\. "\u0627\u0644\u0633\u0628\u062a"]. ::msgcat::mcset ar MONTHS_ABBREV [list \. "\u064a\u0646\u0627"\. "\u0641\u0628\u0631"\. "\u0645\u0627\u0631"\. "\u0623\u0628\u0631"\. "\u0645\u0627\u064a"\. "\u064a\u0648\u0646"\. "\u064a\u0648\u0644"\. "\u0623\u063a\u0633"\. "\u0633\u0628\u062a"\. "\u0623\u0643\u062a"\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):259
                                                                                                                                                                                                                                  Entropy (8bit):4.825452591398057
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoKNvf/NLoKU3v6xH5oKNo+3vfXM6PYv:4EnLzu8yvf/Nq3v6vF3vfc6q
                                                                                                                                                                                                                                  MD5:EEB42BA91CC7EF4F89A8C1831ABE7B03
                                                                                                                                                                                                                                  SHA1:74D12B4CBCDF63FDF00E589D8A604A5C52C393EF
                                                                                                                                                                                                                                  SHA-256:29A70EAC43B1F3AA189D8AE4D92658E07783965BAE417FB66EE5F69CFCB564F3
                                                                                                                                                                                                                                  SHA-512:6CCB2F62986CE1CF3CE78538041A0E4AAF717496F965D73014A13E9B05093EB43185C3C14212DC052562F3F369AB6985485C8C93D1DFC60CF9B8DABEA7CDF434
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ar_IN DATE_FORMAT "%A %d %B %Y". ::msgcat::mcset ar_IN TIME_FORMAT_12 "%I:%M:%S %z". ::msgcat::mcset ar_IN DATE_TIME_FORMAT "%A %d %B %Y %I:%M:%S %z %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1812
                                                                                                                                                                                                                                  Entropy (8bit):4.023830561129656
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8J5Fe6k+wR+9Gb+Oa+UcP+wR+9Gb+Oa+UD:46I6CNbtdNbQ
                                                                                                                                                                                                                                  MD5:4338BD4F064A6CDC5BFED2D90B55D4E8
                                                                                                                                                                                                                                  SHA1:709717BB1F62A71E94D61056A70660C6A03B48AE
                                                                                                                                                                                                                                  SHA-256:78116E7E706C7D1E3E7446094709819FB39A50C2A2302F92D6A498E06ED4A31B
                                                                                                                                                                                                                                  SHA-512:C63A535AD19CBEF5EFC33AC5A453B1C503A59C6CE71A4CABF8083BC516DF0F3F14D3D4F309D33EDF2EC5E79DB00ED1F7D56FD21068F09F178BB2B191603BAC25
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ar_JO DAYS_OF_WEEK_ABBREV [list \. "\u0627\u0644\u0623\u062d\u062f"\. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\. "\u0627\u0644\u062e\u0645\u064a\u0633"\. "\u0627\u0644\u062c\u0645\u0639\u0629"\. "\u0627\u0644\u0633\u0628\u062a"]. ::msgcat::mcset ar_JO MONTHS_ABBREV [list \. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\. "\u0634\u0628\u0627\u0637"\. "\u0622\u0630\u0627\u0631"\. "\u0646\u064a\u0633\u0627\u0646"\. "\u0646\u0648\u0627\u0631"\. "\u062d\u0632\u064a\u0631\u0627\u0646"\. "\u062a\u0645\u0648\u0632"\. "\u0622\u0628"\. "\u0623\u064a\u0644\u0648\u0644"\. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u0644"\. "\u062a\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1812
                                                                                                                                                                                                                                  Entropy (8bit):4.020656526954981
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu865Fehk+wR+9Gb+Oa+UXP+wR+9Gb+Oa+UD:46nhCNbadNbQ
                                                                                                                                                                                                                                  MD5:3789E03CF926D4F12AFD30FC7229B78D
                                                                                                                                                                                                                                  SHA1:AEF38AAB736E5434295C72C14F38033AAFE6EF15
                                                                                                                                                                                                                                  SHA-256:7C970EFEB55C53758143DF42CC452A3632F805487CA69DB57E37C1F478A7571B
                                                                                                                                                                                                                                  SHA-512:C9172600703337EDB2E36D7470A3AED96CCC763D7163067CB19E7B097BB7877522758C3109E31D5D72F486DD50BF510DDBA50EDD248B899FA0A2EEF09FCBF903
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ar_LB DAYS_OF_WEEK_ABBREV [list \. "\u0627\u0644\u0623\u062d\u062f"\. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\. "\u0627\u0644\u062e\u0645\u064a\u0633"\. "\u0627\u0644\u062c\u0645\u0639\u0629"\. "\u0627\u0644\u0633\u0628\u062a"]. ::msgcat::mcset ar_LB MONTHS_ABBREV [list \. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\. "\u0634\u0628\u0627\u0637"\. "\u0622\u0630\u0627\u0631"\. "\u0646\u064a\u0633\u0627\u0646"\. "\u0646\u0648\u0627\u0631"\. "\u062d\u0632\u064a\u0631\u0627\u0646"\. "\u062a\u0645\u0648\u0632"\. "\u0622\u0628"\. "\u0623\u064a\u0644\u0648\u0644"\. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u0644"\. "\u062a\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1812
                                                                                                                                                                                                                                  Entropy (8bit):4.02203966019266
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8k5Fezk+wR+9Gb+Oa+U5P+wRa9Gb+Oa+UD:46ZzCNb0d5bQ
                                                                                                                                                                                                                                  MD5:EC736BFD4355D842E5BE217A7183D950
                                                                                                                                                                                                                                  SHA1:C6B83C02F5D4B14064D937AFD8C6A92BA9AE9EFB
                                                                                                                                                                                                                                  SHA-256:AEF17B94A0DB878E2F0FB49D982057C5B663289E3A8E0E2B195DCEC37E8555B1
                                                                                                                                                                                                                                  SHA-512:68BB7851469C24003A9D74FC7FE3599A2E95EE3803014016DDEBF4C5785F49EDBADA69CD4103F2D3B6CE91E9A32CC432DBDFEC2AED0557E5B6B13AED489A1EDA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ar_SY DAYS_OF_WEEK_ABBREV [list \. "\u0627\u0644\u0623\u062d\u062f"\. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\. "\u0627\u0644\u062e\u0645\u064a\u0633"\. "\u0627\u0644\u062c\u0645\u0639\u0629"\. "\u0627\u0644\u0633\u0628\u062a"]. ::msgcat::mcset ar_SY MONTHS_ABBREV [list \. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\. "\u0634\u0628\u0627\u0637"\. "\u0622\u0630\u0627\u0631"\. "\u0646\u064a\u0633\u0627\u0646"\. "\u0646\u0648\u0627\u0631"\. "\u062d\u0632\u064a\u0631\u0627\u0646"\. "\u062a\u0645\u0648\u0632"\. "\u0622\u0628"\. "\u0623\u064a\u0644\u0648\u0644"\. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u0644"\. "\u062a\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2105
                                                                                                                                                                                                                                  Entropy (8bit):4.215818273236158
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46dJRQPQ86AK0xQuEQS3oQsDptuCrQICZmQ8ZVDtN1QFqQLtCSjZMpktvp:hdP6HIZoFnl1Rgx
                                                                                                                                                                                                                                  MD5:1A3ABFBC61EF757B45FF841C197BB6C3
                                                                                                                                                                                                                                  SHA1:74D623DAB6238D05C18DDE57FC956D84974FC2D4
                                                                                                                                                                                                                                  SHA-256:D790E54217A4BF9A7E1DCB4F3399B5861728918E93CD3F00B63F1349BDB71C57
                                                                                                                                                                                                                                  SHA-512:154D053410AA0F7817197B7EE1E8AE839BA525C7660620581F228477B1F5B972FE95A4E493BB50365D0B63B0115036DDE54A98450CA4E8048AF5D0AF092BADE5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset be DAYS_OF_WEEK_ABBREV [list \. "\u043d\u0434"\. "\u043f\u043d"\. "\u0430\u0442"\. "\u0441\u0440"\. "\u0447\u0446"\. "\u043f\u0442"\. "\u0441\u0431"]. ::msgcat::mcset be DAYS_OF_WEEK_FULL [list \. "\u043d\u044f\u0434\u0437\u0435\u043b\u044f"\. "\u043f\u0430\u043d\u044f\u0434\u0437\u0435\u043b\u0430\u043a"\. "\u0430\u045e\u0442\u043e\u0440\u0430\u043a"\. "\u0441\u0435\u0440\u0430\u0434\u0430"\. "\u0447\u0430\u0446\u0432\u0435\u0440"\. "\u043f\u044f\u0442\u043d\u0456\u0446\u0430"\. "\u0441\u0443\u0431\u043e\u0442\u0430"]. ::msgcat::mcset be MONTHS_ABBREV [list \. "\u0441\u0442\u0434"\. "\u043b\u044e\u0442"\. "\u0441\u043a\u0432"\. "\u043a\u0440\u0441"\. "\u043c\u0430\u0439"\. "\u0447\u0440\u0432"\. "\u043b\u043f\u043d"\. "\u0436\u043d\u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1819
                                                                                                                                                                                                                                  Entropy (8bit):4.363233187157474
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46scAXuQfuQVoQAWN5EPIKfD8WQjQ3QgQaQLSqQsQGtQWCQMmt1f:hD/zQaPIKfTSiF3KVfVCqp
                                                                                                                                                                                                                                  MD5:11FA3BA30A0EE6A7B2B9D67B439C240D
                                                                                                                                                                                                                                  SHA1:EC5557A16A0293ABF4AA8E5FD50940B60A8A36A6
                                                                                                                                                                                                                                  SHA-256:E737D8DC724AA3B9EC07165C13E8628C6A8AC1E80345E10DC77E1FC62A6D86F1
                                                                                                                                                                                                                                  SHA-512:B776E7C98FB819436C61665206EE0A2644AA4952D739FF7CC58EAFBD549BD1D26028DE8E11B8533814102B31FC3884F95890971F547804BCAA4530E35BDD5CFD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset bg DAYS_OF_WEEK_ABBREV [list \. "\u041d\u0434"\. "\u041f\u043d"\. "\u0412\u0442"\. "\u0421\u0440"\. "\u0427\u0442"\. "\u041f\u0442"\. "\u0421\u0431"]. ::msgcat::mcset bg DAYS_OF_WEEK_FULL [list \. "\u041d\u0435\u0434\u0435\u043b\u044f"\. "\u041f\u043e\u043d\u0435\u0434\u0435\u043b\u043d\u0438\u043a"\. "\u0412\u0442\u043e\u0440\u043d\u0438\u043a"\. "\u0421\u0440\u044f\u0434\u0430"\. "\u0427\u0435\u0442\u0432\u044a\u0440\u0442\u044a\u043a"\. "\u041f\u0435\u0442\u044a\u043a"\. "\u0421\u044a\u0431\u043e\u0442\u0430"]. ::msgcat::mcset bg MONTHS_ABBREV [list \. "I"\. "II"\. "III"\. "IV"\. "V"\. "VI"\. "VII"\. "VIII"\. "IX"\. "X"\. "XI"\. "XII"\. ""]. ::msgcat::mcset bg MONTHS_FULL [list \. "\u042
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2286
                                                                                                                                                                                                                                  Entropy (8bit):4.04505151160981
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8adWa9tUEVcqVc5VcaUTVcHVEVc+7VclEVcNGVcn0VcMG/0VcMjVcMK7YXs+:46C07LetHigetH1YES
                                                                                                                                                                                                                                  MD5:B387D4A2AB661112F2ABF57CEDAA24A5
                                                                                                                                                                                                                                  SHA1:80DB233687A9314600317AD39C01466C642F3C4C
                                                                                                                                                                                                                                  SHA-256:297D4D7CAE6E99DB3CA6EE793519512BFF65013CF261CF90DED4D28D3D4F826F
                                                                                                                                                                                                                                  SHA-512:450BB56198AAAB2EEFCD4E24C29DD79D71D2EF7E8D066F3B58F9C5D831F960AFB78C46ECE2DB32EF81454BCCC80C730E36A610DC9BAF06757E0757B421BACB19
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset bn DAYS_OF_WEEK_ABBREV [list \. "\u09b0\u09ac\u09bf"\. "\u09b8\u09cb\u09ae"\. "\u09ae\u0999\u0997\u09b2"\. "\u09ac\u09c1\u09a7"\. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf"\. "\u09b6\u09c1\u0995\u09cd\u09b0"\. "\u09b6\u09a8\u09bf"]. ::msgcat::mcset bn DAYS_OF_WEEK_FULL [list \. "\u09b0\u09ac\u09bf\u09ac\u09be\u09b0"\. "\u09b8\u09cb\u09ae\u09ac\u09be\u09b0"\. "\u09ae\u0999\u0997\u09b2\u09ac\u09be\u09b0"\. "\u09ac\u09c1\u09a7\u09ac\u09be\u09b0"\. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf\u09ac\u09be\u09b0"\. "\u09b6\u09c1\u0995\u09cd\u09b0\u09ac\u09be\u09b0"\. "\u09b6\u09a8\u09bf\u09ac\u09be\u09b0"]. ::msgcat::mcset bn MONTHS_ABBREV [list \. "\u099c\u09be\u09a8\u09c1\u09df\u09be\u09b0\u09c0"\. "\u09ab\u09c7\u09ac\u09cd\u09b0\u09c1\u09df\u09be\u09b0\u09c0"\.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):259
                                                                                                                                                                                                                                  Entropy (8bit):4.821338044395148
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmovtvflD/Lo/E3v6xH5ovto+3vflm6PYv:4EnLzu81tvflD/SE3v6etF3vflm6q
                                                                                                                                                                                                                                  MD5:764E70363A437ECA938DEC17E615608B
                                                                                                                                                                                                                                  SHA1:2296073AE8CC421780E8A3BCD58312D6FB2F5BFC
                                                                                                                                                                                                                                  SHA-256:7D3A956663C529D07C8A9610414356DE717F3A2A2CE9B331B052367270ACEA94
                                                                                                                                                                                                                                  SHA-512:4C7B9082DA9DDF07C2BE16C359A1A42834B8E730AD4DD5B987866C2CC735402DDE513588A89C8DFA25A1AC6F66AF9FDDBEA8FD500F8526C4641BBA7011CD0D28
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset bn_IN DATE_FORMAT "%A %d %b %Y". ::msgcat::mcset bn_IN TIME_FORMAT_12 "%I:%M:%S %z". ::msgcat::mcset bn_IN DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1102
                                                                                                                                                                                                                                  Entropy (8bit):4.213250101046006
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8WBVUUQ48wsF0nuLsCtJeUFqwv1v3:46BwoL5ScfR3
                                                                                                                                                                                                                                  MD5:9378A5AD135137759D46A7CC4E4270E0
                                                                                                                                                                                                                                  SHA1:8D2D53DA208BB670A335C752DFC4B4FF4509A799
                                                                                                                                                                                                                                  SHA-256:14FF564FAB584571E954BE20D61C2FACB096FE2B3EF369CC5ECB7C25C2D92D5A
                                                                                                                                                                                                                                  SHA-512:EF784D0D982BA0B0CB37F1DA15F8AF3BE5321F59E586DBED1EDD0B3A38213D3CEA1CDFC983A025418403400CCE6039B786EE35694A5DFCE1F22CB2D315F5FCF8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ca DAYS_OF_WEEK_ABBREV [list \. "dg."\. "dl."\. "dt."\. "dc."\. "dj."\. "dv."\. "ds."]. ::msgcat::mcset ca DAYS_OF_WEEK_FULL [list \. "diumenge"\. "dilluns"\. "dimarts"\. "dimecres"\. "dijous"\. "divendres"\. "dissabte"]. ::msgcat::mcset ca MONTHS_ABBREV [list \. "gen."\. "feb."\. "mar\u00e7"\. "abr."\. "maig"\. "juny"\. "jul."\. "ag."\. "set."\. "oct."\. "nov."\. "des."\. ""]. ::msgcat::mcset ca MONTHS_FULL [list \. "gener"\. "febrer"\. "mar\u00e7"\. "abril"\. "maig"\. "juny"\. "juliol"\. "agost"\. "setembre"\. "octubre"\. "novembre"\. "desembre"\. ""]. ::msgcat::mcset ca DATE_FORMAT "%d/%m/%Y". ::msg
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1300
                                                                                                                                                                                                                                  Entropy (8bit):4.400184537938628
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8f4sO4fETEtd3N5EPIK+kJQz3R3VJ2PYYITCF3eYGCvt2/v3eG:46/ETKN5EPIKfsxV+pBtMJ
                                                                                                                                                                                                                                  MD5:4C5679B0880394397022A70932F02442
                                                                                                                                                                                                                                  SHA1:CA5C47A76CD4506D8E11AECE1EA0B4A657176019
                                                                                                                                                                                                                                  SHA-256:49CF452EEF0B8970BC56A7B8E040BA088215508228A77032CBA0035522412F86
                                                                                                                                                                                                                                  SHA-512:39FA0D3235FFD3CE2BCCFFFA6A4A8EFE2668768757DAFDE901917731E20AD15FCAC4E48CF4ACF0ADFAA38CC72768FD8F1B826464B0F71A1C784E334AE72F857C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset cs DAYS_OF_WEEK_ABBREV [list \. "Ne"\. "Po"\. "\u00dat"\. "St"\. "\u010ct"\. "P\u00e1"\. "So"]. ::msgcat::mcset cs DAYS_OF_WEEK_FULL [list \. "Ned\u011ble"\. "Pond\u011bl\u00ed"\. "\u00dater\u00fd"\. "St\u0159eda"\. "\u010ctvrtek"\. "P\u00e1tek"\. "Sobota"]. ::msgcat::mcset cs MONTHS_ABBREV [list \. "I"\. "II"\. "III"\. "IV"\. "V"\. "VI"\. "VII"\. "VIII"\. "IX"\. "X"\. "XI"\. "XII"\. ""]. ::msgcat::mcset cs MONTHS_FULL [list \. "leden"\. "\u00fanor"\. "b\u0159ezen"\. "duben"\. "kv\u011bten"\. "\u010derven"\. "\u010dervenec"\. "srpen"\. "z\u00e1\u0159\u00ed"\. "\u0159\u00edjen"\. "listopad"\. "prosinec"\. ""]
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1156
                                                                                                                                                                                                                                  Entropy (8bit):4.242018456508518
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8xVKE6V4/xPsS9CfXTBfijQT1GqAPwvsvT:461H6y/RsJXTNGqAuKT
                                                                                                                                                                                                                                  MD5:F012F45523AA0F8CFEACC44187FF1243
                                                                                                                                                                                                                                  SHA1:B171D1554244D2A6ED8DE17AC8000AA09D2FADE9
                                                                                                                                                                                                                                  SHA-256:CA58FF5BAA9681D9162E094E833470077B7555BB09EEE8E8DD41881B108008A0
                                                                                                                                                                                                                                  SHA-512:5BBC44471AB1B1622FABC7A12A8B8727087BE64BEAF72D2C3C9AAC1246A41D9B7CAFC5C451F24A3ACC681C310BF47BBC3384CF80EB0B4375E12646CB7BB8FFD5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset da DAYS_OF_WEEK_ABBREV [list \. "s\u00f8"\. "ma"\. "ti"\. "on"\. "to"\. "fr"\. "l\u00f8"]. ::msgcat::mcset da DAYS_OF_WEEK_FULL [list \. "s\u00f8ndag"\. "mandag"\. "tirsdag"\. "onsdag"\. "torsdag"\. "fredag"\. "l\u00f8rdag"]. ::msgcat::mcset da MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "maj"\. "jun"\. "jul"\. "aug"\. "sep"\. "okt"\. "nov"\. "dec"\. ""]. ::msgcat::mcset da MONTHS_FULL [list \. "januar"\. "februar"\. "marts"\. "april"\. "maj"\. "juni"\. "juli"\. "august"\. "september"\. "oktober"\. "november"\. "december"\. ""]. ::msgcat::mcset da BCE "f.Kr.". ::msgcat::mcset da CE "e.Kr.".
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1222
                                                                                                                                                                                                                                  Entropy (8bit):4.277486792653572
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8byFouxpZzWsu0biMe5pF9g1tT9egQTqrS8QWmWFUvIvWI3:46CFB/ZzWsu0vpHlrS8QLWFSeWI3
                                                                                                                                                                                                                                  MD5:68882CCA0886535A613ECFE528BB81FC
                                                                                                                                                                                                                                  SHA1:6ABF519F6E4845E6F13F272D628DE97F2D2CD481
                                                                                                                                                                                                                                  SHA-256:CC3672969C1DD223EADD9A226E00CAC731D8245532408B75AB9A70E9EDD28673
                                                                                                                                                                                                                                  SHA-512:ACD5F811A0494E04A18035D2B9171FAF3AB8C856AAB0C09AEBE755590261066ADCD2750565F1CB840B2D0111D95C98970294550A4FBD00E4346D2EDBA3A5C957
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset de DAYS_OF_WEEK_ABBREV [list \. "So"\. "Mo"\. "Di"\. "Mi"\. "Do"\. "Fr"\. "Sa"]. ::msgcat::mcset de DAYS_OF_WEEK_FULL [list \. "Sonntag"\. "Montag"\. "Dienstag"\. "Mittwoch"\. "Donnerstag"\. "Freitag"\. "Samstag"]. ::msgcat::mcset de MONTHS_ABBREV [list \. "Jan"\. "Feb"\. "Mrz"\. "Apr"\. "Mai"\. "Jun"\. "Jul"\. "Aug"\. "Sep"\. "Okt"\. "Nov"\. "Dez"\. ""]. ::msgcat::mcset de MONTHS_FULL [list \. "Januar"\. "Februar"\. "M\u00e4rz"\. "April"\. "Mai"\. "Juni"\. "Juli"\. "August"\. "September"\. "Oktober"\. "November"\. "Dezember"\. ""]. ::msgcat::mcset de BCE "v. Chr.". ::msgcat::mcset de CE "n. Chr.".
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):812
                                                                                                                                                                                                                                  Entropy (8bit):4.344116560816791
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu8U3S5dkTo7eqepFHvFgt1BAI+5zS17eM5Qz3q6owjI9I3vd3v6B3v9dy:4azu8UlMe5pF9gXDT9egQTqr+rv1vivi
                                                                                                                                                                                                                                  MD5:63B8EBBA990D1DE3D83D09375E19F6AC
                                                                                                                                                                                                                                  SHA1:B7714AF372B4662A0C15DDBC0F80D1249CB1EEBD
                                                                                                                                                                                                                                  SHA-256:80513A9969A12A8FB01802D6FC3015712A4EFDDA64552911A1BB3EA7A098D02C
                                                                                                                                                                                                                                  SHA-512:638307C9B97C74BAF38905AC88E73B57F24282E40929DA43ADB74978040B818EFCC2EE2A377DFEB3AC9050800536F2BE1C7C2A7AB9E7B8BCF8D15E5F293F24D9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset de_AT MONTHS_ABBREV [list \. "J\u00e4n"\. "Feb"\. "M\u00e4r"\. "Apr"\. "Mai"\. "Jun"\. "Jul"\. "Aug"\. "Sep"\. "Okt"\. "Nov"\. "Dez"\. ""]. ::msgcat::mcset de_AT MONTHS_FULL [list \. "J\u00e4nner"\. "Februar"\. "M\u00e4rz"\. "April"\. "Mai"\. "Juni"\. "Juli"\. "August"\. "September"\. "Oktober"\. "November"\. "Dezember"\. ""]. ::msgcat::mcset de_AT DATE_FORMAT "%Y-%m-%d". ::msgcat::mcset de_AT TIME_FORMAT "%T". ::msgcat::mcset de_AT TIME_FORMAT_12 "%T". ::msgcat::mcset de_AT DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1223
                                                                                                                                                                                                                                  Entropy (8bit):4.319193323810203
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8I8VWRFFAVa8VpZzWsuEbkMe5pF9grtT9egQTqr9u5sevOevmDvi:46kR6VaIZzWsuEJnHlrg5soOomzi
                                                                                                                                                                                                                                  MD5:A741CF1A27C77CFF2913076AC9EE9DDC
                                                                                                                                                                                                                                  SHA1:DE519D3A86DCF1E8F469490967AFE350BAEAFE01
                                                                                                                                                                                                                                  SHA-256:7573581DEC27E90B0C7D34057D9F4EF89727317D55F2C4E0428A47740FB1EB7A
                                                                                                                                                                                                                                  SHA-512:C9272793BAA1D33C32576B48756063F4A9BB97E8FFA276809CF4C3956CC457E48C577BDF359C1ECF5CF665A68135CAED17E972DC053A6AFBAAC3BA0ECBAFEB05
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset de_BE DAYS_OF_WEEK_ABBREV [list \. "Son"\. "Mon"\. "Die"\. "Mit"\. "Don"\. "Fre"\. "Sam"]. ::msgcat::mcset de_BE DAYS_OF_WEEK_FULL [list \. "Sonntag"\. "Montag"\. "Dienstag"\. "Mittwoch"\. "Donnerstag"\. "Freitag"\. "Samstag"]. ::msgcat::mcset de_BE MONTHS_ABBREV [list \. "Jan"\. "Feb"\. "M\u00e4r"\. "Apr"\. "Mai"\. "Jun"\. "Jul"\. "Aug"\. "Sep"\. "Okt"\. "Nov"\. "Dez"\. ""]. ::msgcat::mcset de_BE MONTHS_FULL [list \. "Januar"\. "Februar"\. "M\u00e4rz"\. "April"\. "Mai"\. "Juni"\. "Juli"\. "August"\. "September"\. "Oktober"\. "November"\. "Dezember"\. ""]. ::msgcat::mcset de_BE AM "vorm". ::msgcat::mcs
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2252
                                                                                                                                                                                                                                  Entropy (8bit):4.313031807335687
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8+v+39bYW4v+0Wn4Obg+EKkJQg9UWWY+YcYGV97Wu9TJGJABRF6RrJFdsvjt:468XxCSpAWL8jdL
                                                                                                                                                                                                                                  MD5:E152787B40C5E30699AD5E9B0C60DC07
                                                                                                                                                                                                                                  SHA1:4FB9DB6E784E1D28E632B55ED31FBBB4997BF575
                                                                                                                                                                                                                                  SHA-256:9B2F91BE34024FBCF645F6EF92460E5F944CA6A16268B79478AB904B2934D357
                                                                                                                                                                                                                                  SHA-512:DE59E17CAB924A35C4CC74FE8FCA4776BD49E30C224E476741A273A74BBE40CDAAEDBF6BBB5E30011CD0FEED6B2840F607FD0F1BD3E136E7FE39BAE81C7ED4DB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset el DAYS_OF_WEEK_ABBREV [list \. "\u039a\u03c5\u03c1"\. "\u0394\u03b5\u03c5"\. "\u03a4\u03c1\u03b9"\. "\u03a4\u03b5\u03c4"\. "\u03a0\u03b5\u03bc"\. "\u03a0\u03b1\u03c1"\. "\u03a3\u03b1\u03b2"]. ::msgcat::mcset el DAYS_OF_WEEK_FULL [list \. "\u039a\u03c5\u03c1\u03b9\u03b1\u03ba\u03ae"\. "\u0394\u03b5\u03c5\u03c4\u03ad\u03c1\u03b1"\. "\u03a4\u03c1\u03af\u03c4\u03b7"\. "\u03a4\u03b5\u03c4\u03ac\u03c1\u03c4\u03b7"\. "\u03a0\u03ad\u03bc\u03c0\u03c4\u03b7"\. "\u03a0\u03b1\u03c1\u03b1\u03c3\u03ba\u03b5\u03c5\u03ae"\. "\u03a3\u03ac\u03b2\u03b2\u03b1\u03c4\u03bf"]. ::msgcat::mcset el MONTHS_ABBREV [list \. "\u0399\u03b1\u03bd"\. "\u03a6\u03b5\u03b2"\. "\u039c\u03b1\u03c1"\. "\u0391\u03c0\u03c1"\. "\u039c\u03b1\u03ca"\. "\u0399\u03bf\u03c5\u03bd"\. "\u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):300
                                                                                                                                                                                                                                  Entropy (8bit):4.849761581276844
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoCwmGjbJFLoCws6W3vULoCws6W3v6p6HH5oCwmT+3vjb0y6:4EnLzu8brJFqs6W3v3s6W3v6QQJ3vK
                                                                                                                                                                                                                                  MD5:F8AE50E60590CC1FF7CCC43F55B5B8A8
                                                                                                                                                                                                                                  SHA1:52892EDDFA74DD4C8040F9CDD19A9536BFF72B6E
                                                                                                                                                                                                                                  SHA-256:B85C9A373FF0F036151432652DD55C182B0704BD0625EA84BED1727EC0DE3DD8
                                                                                                                                                                                                                                  SHA-512:8E15C9CA9A7D2862FDBA330F59BB177B06E5E3154CF3EA948B8E4C0282D66E75E18C225F28F6A203B4643E8BCAA0B5BDB59578A4C20D094F8B923650796E2E72
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_AU DATE_FORMAT "%e/%m/%Y". ::msgcat::mcset en_AU TIME_FORMAT "%H:%M:%S". ::msgcat::mcset en_AU TIME_FORMAT_12 "%I:%M:%S %P %z". ::msgcat::mcset en_AU DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):305
                                                                                                                                                                                                                                  Entropy (8bit):4.823881517188826
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoCr3FD/LoCsX3vtfNrFLoCsX3v6YNn5oCs+3v3FnN9:4EnLzu863FD/U3vtNm3v6yt3v3FnN9
                                                                                                                                                                                                                                  MD5:A0BB5A5CC6C37C12CB24523198B82F1C
                                                                                                                                                                                                                                  SHA1:B7A6B4BFB6533CC33A0A0F5037E55A55958C4DFC
                                                                                                                                                                                                                                  SHA-256:596AC02204C845AA74451FC527645549F2A3318CB63051FCACB2BF948FD77351
                                                                                                                                                                                                                                  SHA-512:9859D8680E326C2EB39390F3B96AC0383372433000A4E828CF803323AB2AB681B2BAE87766CB6FB23F6D46DBA38D3344BC4A941AFB0027C737784063194F9AE4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_BE DATE_FORMAT "%d %b %Y". ::msgcat::mcset en_BE TIME_FORMAT "%k:%M:%S". ::msgcat::mcset en_BE TIME_FORMAT_12 "%k h %M min %S s %z". ::msgcat::mcset en_BE DATE_TIME_FORMAT "%d %b %Y %k:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.869619023232552
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmosmGvNLoss6W3v6aZosmT+3vR6HK:4EnLzu8WrvNbs6W3v6aBJ3voq
                                                                                                                                                                                                                                  MD5:ECC735522806B18738512DC678D01A09
                                                                                                                                                                                                                                  SHA1:EEEC3A5A3780DBA7170149C779180748EB861B86
                                                                                                                                                                                                                                  SHA-256:340804F73B620686AB698B2202191D69227E736B1652271C99F2CFEF03D72296
                                                                                                                                                                                                                                  SHA-512:F46915BD68249B5B1988503E50EBC48C13D9C0DDBDCBA9F520386E41A0BAAE640FD97A5085698AB1DF65640CE70AC63ED21FAD49AF54511A5543D1F36247C22D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_BW DATE_FORMAT "%d %B %Y". ::msgcat::mcset en_BW TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset en_BW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):288
                                                                                                                                                                                                                                  Entropy (8bit):4.828989678102087
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoAhgqH5oAZF3vGoAZF3v6loAh9+3vnFDLq:4EnLzu8mhgqHFZF3vGZF3v65hI3v9G
                                                                                                                                                                                                                                  MD5:F9A9EE00A4A2A899EDCCA6D82B3FA02A
                                                                                                                                                                                                                                  SHA1:BFDBAD5C0A323A37D5F91C37EC899B923DA5B0F5
                                                                                                                                                                                                                                  SHA-256:C9FE2223C4949AC0A193F321FC0FD7C344A9E49A54B00F8A4C30404798658631
                                                                                                                                                                                                                                  SHA-512:4E5471ADE75E0B91A02A30D8A042791D63565487CBCA1825EA68DD54A3AE6F1E386D9F3B016D233406D4B0B499B05DF6295BC0FFE85E8AA9DA4B4B7CC0128AD9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_CA DATE_FORMAT "%d/%m/%y". ::msgcat::mcset en_CA TIME_FORMAT "%r". ::msgcat::mcset en_CA TIME_FORMAT_12 "%I:%M:%S %p". ::msgcat::mcset en_CA DATE_TIME_FORMAT "%a %d %b %Y %r %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.84511182583436
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoEbtvqH5oELE3vG5oELE3v6X5oEbto+3vnFDoAov:4EnLzu8ibtvqHBLE3v4LE3v6RbtF3v98
                                                                                                                                                                                                                                  MD5:07C16C81F1B59444508D0F475C2DB175
                                                                                                                                                                                                                                  SHA1:DEDBDB2C9ACA932C373C315FB6C5691DBEDEB346
                                                                                                                                                                                                                                  SHA-256:AE38AD5452314B0946C5CB9D3C89CDFC2AD214E146EB683B8D0CE3FE84070FE1
                                                                                                                                                                                                                                  SHA-512:F13333C975E6A0AD06E57C5C1908ED23C4A96008A895848D1E2FE7985001B2E5B9B05C4824C74EDA94E0CC70EC7CABCB103B97E54E957F986D8F277EEC3325B7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_GB DATE_FORMAT "%d/%m/%y". ::msgcat::mcset en_GB TIME_FORMAT "%T". ::msgcat::mcset en_GB TIME_FORMAT_12 "%T". ::msgcat::mcset en_GB DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):321
                                                                                                                                                                                                                                  Entropy (8bit):4.803235346516854
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoa/5oaQ9woaAx/G4FLoaYYW3v6aZoaAx/T+3v4x6HK:4EnLzu8cpZF4F7xW3v6ah/3v4Iq
                                                                                                                                                                                                                                  MD5:27B4185EB5B4CAAD8F38AE554231B49A
                                                                                                                                                                                                                                  SHA1:67122CAA8ECA829EC0759A0147C6851A6E91E867
                                                                                                                                                                                                                                  SHA-256:C9BE2C9AD31D516B508D01E85BCCA375AAF807D6D8CD7C658085D5007069FFFD
                                                                                                                                                                                                                                  SHA-512:003E5C1E2ECCCC48D14F3159DE71A5B0F1471275D4051C7AC42A3CFB80CAF651A5D04C4D8B868158211E8BC4E08554AF771993B0710E6625AA3AE912A33F5487
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_HK AM "AM". ::msgcat::mcset en_HK PM "PM". ::msgcat::mcset en_HK DATE_FORMAT "%B %e, %Y". ::msgcat::mcset en_HK TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset en_HK DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.78446779523026
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoK6qH5oKi+3vG5oKi+3v6X5oKv+3vnFDoAov:4EnLzu8vqHr3vQ3v6O3v9dy
                                                                                                                                                                                                                                  MD5:30E351D26DC3D514BC4BF4E4C1C34D6F
                                                                                                                                                                                                                                  SHA1:FA87650F840E691643F36D78F7326E925683D0A8
                                                                                                                                                                                                                                  SHA-256:E7868C80FD59D18BB15345D29F5292856F639559CFFD42EE649C16C7938BF58D
                                                                                                                                                                                                                                  SHA-512:5AAC8A55239A909207E73EFB4123692D027F7728157D07FAFB629AF5C6DB84B35CF11411E561851F7CDB6F25AEC174E85A1982C4B79C7586644E74512F5FBDDA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_IE DATE_FORMAT "%d/%m/%y". ::msgcat::mcset en_IE TIME_FORMAT "%T". ::msgcat::mcset en_IE TIME_FORMAT_12 "%T". ::msgcat::mcset en_IE DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):310
                                                                                                                                                                                                                                  Entropy (8bit):4.756550208645364
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoKr3v5oKrGaoKr5vvNLoKrw3vULoKr5o+3voA6:4EnLzu8si2vvNa3vuF3vo3
                                                                                                                                                                                                                                  MD5:1423A9CF5507A198580D84660D829133
                                                                                                                                                                                                                                  SHA1:70362593A2B04CF965213F318B10E92E280F338D
                                                                                                                                                                                                                                  SHA-256:71E5367FE839AFC4338C50D450F111728E097538ECACCC1B17B10238001B0BB1
                                                                                                                                                                                                                                  SHA-512:C4F1AD41D44A2473531247036BEEF8402F7C77A21A33690480F169F35E78030942FD31C9331A82B8377D094E22D506C785D0311DBB9F1C2B4AD3575B3F0E76E3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_IN AM "AM". ::msgcat::mcset en_IN PM "PM". ::msgcat::mcset en_IN DATE_FORMAT "%d %B %Y". ::msgcat::mcset en_IN TIME_FORMAT "%H:%M:%S". ::msgcat::mcset en_IN DATE_TIME_FORMAT "%d %B %Y %H:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):300
                                                                                                                                                                                                                                  Entropy (8bit):4.89415873600679
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoyejbJFLo63vULo63v6p6HH5oy7+3vjb0y6:4EnLzu8YeJFL3vI3v6QtS3vK
                                                                                                                                                                                                                                  MD5:DB734349F7A1A83E1CB18814DB6572E8
                                                                                                                                                                                                                                  SHA1:3386B2599C7C170A03E4EED68C39EAC7ADD01708
                                                                                                                                                                                                                                  SHA-256:812DB204E4CB8266207A4E948FBA3DD1EFE4D071BBB793F9743A4320A1CEEBE3
                                                                                                                                                                                                                                  SHA-512:EF09006552C624A2F1C62155251A18BDA9EE85C9FC81ABBEDE8416179B1F82AD0D88E42AB0A10B4871EF4B7DB670E4A824392339976C3C95FB31F588CDE5840D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_NZ DATE_FORMAT "%e/%m/%Y". ::msgcat::mcset en_NZ TIME_FORMAT "%H:%M:%S". ::msgcat::mcset en_NZ TIME_FORMAT_12 "%I:%M:%S %P %z". ::msgcat::mcset en_NZ DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):321
                                                                                                                                                                                                                                  Entropy (8bit):4.775448167269054
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoJ5oXo2e4FLoe3v6aZo27+3v4x6HK:4EnLzu8l4Fj3v6aE3v4Iq
                                                                                                                                                                                                                                  MD5:787C83099B6E4E80AC81DD63BA519CBE
                                                                                                                                                                                                                                  SHA1:1971ACFAA5753D2914577DCC9EBDF43CF89C1D00
                                                                                                                                                                                                                                  SHA-256:BE107F5FAE1E303EA766075C52EF2146EF149EDA37662776E18E93685B176CDC
                                                                                                                                                                                                                                  SHA-512:527A36D64B4B5C909F69AA8609CFFEBBA19A378CEA618E1BB07EC2AED89E456E2292080C43917DF51B08534A1D0B35F2069008324C99A7688BBEDE49049CD8A2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_PH AM "AM". ::msgcat::mcset en_PH PM "PM". ::msgcat::mcset en_PH DATE_FORMAT "%B %e, %Y". ::msgcat::mcset en_PH TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset en_PH DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.865159200607995
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoQW53FD/LoQGuX3v6ZhLoQWa+3v3F0fJ:4EnLzu8283FD/LJ3v6Xc3v3F4
                                                                                                                                                                                                                                  MD5:3045036D8F0663E26796E4E8AFF144E2
                                                                                                                                                                                                                                  SHA1:6C9066396C107049D861CD0A9C98DE8753782571
                                                                                                                                                                                                                                  SHA-256:B8D354519BD4EB1004EB7B25F4E23FD3EE7F533A5F491A46D19FD520ED34C930
                                                                                                                                                                                                                                  SHA-512:EBA6CD05BD596D0E8C96BBCA86379F003AD31E564D9CB90C906AF4B3A776AA797FC18EC405781F83493BBB33510DEDC0E78504AD1E6977BE0F83B2959AD25B8A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_SG DATE_FORMAT "%d %b %Y". ::msgcat::mcset en_SG TIME_FORMAT_12 "%P %I:%M:%S". ::msgcat::mcset en_SG DATE_TIME_FORMAT "%d %b %Y %P %I:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):245
                                                                                                                                                                                                                                  Entropy (8bit):4.89152584889677
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoOr0l5oOK3v6wLoOs+3v0l6C:4EnLzu8WL3v663vlC
                                                                                                                                                                                                                                  MD5:F285A8BA3216DA69B764991124F2F75A
                                                                                                                                                                                                                                  SHA1:A5B853A39D944DB9BB1A4C0B9D55AFDEF0515548
                                                                                                                                                                                                                                  SHA-256:98CE9CA4BB590BA5F922D6A196E5381E19C64E7682CDBEF914F2DCE6745A7332
                                                                                                                                                                                                                                  SHA-512:05695E29BA10072954BC91885A07D74EFBCB81B0DE3961261381210A51968F99CE1801339A05B810A54295E53B0A7E1D75CA5350485A8DEBFFFCBD4945234382
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_ZA DATE_FORMAT "%Y/%m/%d". ::msgcat::mcset en_ZA TIME_FORMAT_12 "%I:%M:%S". ::msgcat::mcset en_ZA DATE_TIME_FORMAT "%Y/%m/%d %I:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.888960668540414
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoEmGvNLoEs6W3v6aZoEmT+3vR6HK:4EnLzu8urvNDs6W3v6a5J3voq
                                                                                                                                                                                                                                  MD5:D8878533B11C21445CAEFA324C638C7E
                                                                                                                                                                                                                                  SHA1:EFF82B28741FA16D2DFC93B5421F856D6F902509
                                                                                                                                                                                                                                  SHA-256:91088BBBF58A704185DEC13DBD421296BBD271A1AEBBCB3EF85A99CECD848FF8
                                                                                                                                                                                                                                  SHA-512:CBFD4FC093B3479AE9E90A5CA05EA1894F62DA9E0559ACC2BD37BBED1F0750ECFF13E6DF2078D68268192CA51A832E1BEED379E11380ADF3C91C1A01A352B20C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset en_ZW DATE_FORMAT "%d %B %Y". ::msgcat::mcset en_ZW TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset en_ZW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1231
                                                                                                                                                                                                                                  Entropy (8bit):4.282246801138565
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8CouOZBQpsS9C58mTXv8/s5pkPXvRvm:46nZ6psX8mT/cYpmfFm
                                                                                                                                                                                                                                  MD5:FE2F92E5C0AB19CDC7119E70187479F6
                                                                                                                                                                                                                                  SHA1:A14B9AA999C0BBD9B21E6A2B44A934D685897430
                                                                                                                                                                                                                                  SHA-256:50DF3E0E669502ED08DD778D0AFEDF0F71993BE388B0FCAA1065D1C91BD22D83
                                                                                                                                                                                                                                  SHA-512:72B4975DC2CAB725BD6557CAED41B9C9146E0DE167EE0A0723C3C90D7CF49FB1D749977042FFECBCD7D8F21509307AAB3CE80E3C51023D22072FB5B415801EA9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset eo DAYS_OF_WEEK_ABBREV [list \. "di"\. "lu"\. "ma"\. "me"\. "\u0135a"\. "ve"\. "sa"]. ::msgcat::mcset eo DAYS_OF_WEEK_FULL [list \. "diman\u0109o"\. "lundo"\. "mardo"\. "merkredo"\. "\u0135a\u016ddo"\. "vendredo"\. "sabato"]. ::msgcat::mcset eo MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "maj"\. "jun"\. "jul"\. "a\u016dg"\. "sep"\. "okt"\. "nov"\. "dec"\. ""]. ::msgcat::mcset eo MONTHS_FULL [list \. "januaro"\. "februaro"\. "marto"\. "aprilo"\. "majo"\. "junio"\. "julio"\. "a\u016dgusto"\. "septembro"\. "oktobro"\. "novembro"\. "decembro"\. ""]. ::msgcat::mcset eo BCE "aK". ::msgcat::mcset e
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1180
                                                                                                                                                                                                                                  Entropy (8bit):4.216657382642579
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8OJccwdQSBJr/S3tFA7C28/sF9AaD5rYrvtAvrG:46w3wdJB1/6FA22c49XrY7tWrG
                                                                                                                                                                                                                                  MD5:022CBA4FF73CF18D63D1B0C11D058B5D
                                                                                                                                                                                                                                  SHA1:8B2D0BE1BE354D639EC3373FE20A0F255E312EF6
                                                                                                                                                                                                                                  SHA-256:FFF2F08A5BE202C81E469E16D4DE1F8A0C1CFE556CDA063DA071279F29314837
                                                                                                                                                                                                                                  SHA-512:5142AD14C614E6BA5067B371102F7E81B14EB7AF3E40D05C674CFF1052DA4D172768636D34FF1DEE2499E43B2FEB4771CB1B67EDA10B887DE50E15DCD58A5283
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es DAYS_OF_WEEK_ABBREV [list \. "dom"\. "lun"\. "mar"\. "mi\u00e9"\. "jue"\. "vie"\. "s\u00e1b"]. ::msgcat::mcset es DAYS_OF_WEEK_FULL [list \. "domingo"\. "lunes"\. "martes"\. "mi\u00e9rcoles"\. "jueves"\. "viernes"\. "s\u00e1bado"]. ::msgcat::mcset es MONTHS_ABBREV [list \. "ene"\. "feb"\. "mar"\. "abr"\. "may"\. "jun"\. "jul"\. "ago"\. "sep"\. "oct"\. "nov"\. "dic"\. ""]. ::msgcat::mcset es MONTHS_FULL [list \. "enero"\. "febrero"\. "marzo"\. "abril"\. "mayo"\. "junio"\. "julio"\. "agosto"\. "septiembre"\. "octubre"\. "noviembre"\. "diciembre"\. ""]. ::msgcat::mcset es BCE "a.C.". ::msgcat::mcset es
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):242
                                                                                                                                                                                                                                  Entropy (8bit):4.830874390627383
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo8GUFLot/W3vULo8T+3v9y6:4EnLzu8KGUFN3v+K3v3
                                                                                                                                                                                                                                  MD5:C806EF01079E6B6B7EAE5D717DA2AAB3
                                                                                                                                                                                                                                  SHA1:3C553536241A5D2E95A3BA9024AAB46BB87FBAD9
                                                                                                                                                                                                                                  SHA-256:AF530ACD69676678C95B803A29A44642ED2D2F2D077CF0F47B53FF24BAC03B2E
                                                                                                                                                                                                                                  SHA-512:619905C2FB5F8D2BC2CBB9F8F0EA117C0AEFBDDE5E4F826FF962D7DC069D16D5DE12E27E898471DC6C039866FB64BBF62ED54DBC031E03C7D24FC2EA38DE5699
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_AR DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset es_AR TIME_FORMAT "%H:%M:%S". ::msgcat::mcset es_AR DATE_TIME_FORMAT "%d/%m/%Y %H:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.878640071219599
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoYePWHFLoU3v6rZoY7+3vPUe6HK:4EnLzu8OegFp3v6rHS3vs3q
                                                                                                                                                                                                                                  MD5:4C2B2A6FBC6B514EA09AA9EF98834F17
                                                                                                                                                                                                                                  SHA1:853FFCBB9A2253B7DC2B82C2BFC3B132500F7A9D
                                                                                                                                                                                                                                  SHA-256:24B58DE38CD4CB2ABD08D1EDA6C9454FFDE7ED1A33367B457D7702434A0A55EE
                                                                                                                                                                                                                                  SHA-512:3347F9C13896AF19F6BAFBEF225AF2A1F84F20F117E7F0CE3E5CAA783FDD88ABDFAF7C1286AE421BC609A39605E16627013945E4ACA1F7001B066E14CAB90BE7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_BO DATE_FORMAT "%d-%m-%Y". ::msgcat::mcset es_BO TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_BO DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.889615718638578
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmodvPWHFLok3v6rZodo+3vPUe6HK:4EnLzu8DgF93v6rC3vs3q
                                                                                                                                                                                                                                  MD5:B7E7BE63F24FC1D07F28C5F97637BA1C
                                                                                                                                                                                                                                  SHA1:8FE1D17696C910CF59467598233D55268BFE0D94
                                                                                                                                                                                                                                  SHA-256:12AD1546EB391989105D80B41A87686D3B30626D0C42A73705F33B2D711950CC
                                                                                                                                                                                                                                  SHA-512:FD8B83EF06B1E1111AFF186F5693B17526024CAD8CC99102818BE74FD885344D2F628A0541ABB485F38DB8DE7E29EA4EE4B28D8E5F6ECEF826BABE1013ABDFB8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_CL DATE_FORMAT "%d-%m-%Y". ::msgcat::mcset es_CL TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_CL DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.862231219172699
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo4FjbJFLo4F+3v6rZo4++3vjb0f6HK:4EnLzu8QJFL+3v6rv3vbq
                                                                                                                                                                                                                                  MD5:FD946BE4D44995911E79135E5B7BD3BB
                                                                                                                                                                                                                                  SHA1:3BA38CB03258CA834E37DBB4E3149D4CDA9B353B
                                                                                                                                                                                                                                  SHA-256:1B4979874C3F025317DFCF0B06FC8CEE080A28FF3E8EFE1DE9E899F6D4F4D21E
                                                                                                                                                                                                                                  SHA-512:FBD8087891BA0AE58D71A6D07482EED5E0EA5C658F0C82A9EC67DFC0D826059F1FC6FF404D6A6DC9619BD9249D4E4EC30D828B177E0939302196C51FA9B2FC4B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_CO DATE_FORMAT "%e/%m/%Y". ::msgcat::mcset es_CO TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_CO DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.873281593259653
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo76GUFLoTW3v6rZo76T+3v9f6HK:4EnLzu8d6GUF73v6rq6K3vMq
                                                                                                                                                                                                                                  MD5:F08EF3582AF2F88B71C599FBEA38BFD9
                                                                                                                                                                                                                                  SHA1:456C90C09C2A8919DC948E86170F523062F135DB
                                                                                                                                                                                                                                  SHA-256:7AC5FC35BC422A5445603E0430236E62CCA3558787811DE22305F72D439EB4BB
                                                                                                                                                                                                                                  SHA-512:7187FC4CE0533F14BBA073039A0B86D610618573BA9A936CBE7682ED2939384C6BB9E0A407C016A42702E83627CCE394618ACB58419EA36908AA37F59165E371
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_CR DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset es_CR TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_CR DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.8668686830029335
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmomerQZnFLou3v6rZom7+3vrQZg6HK:4EnLzu8xkZFH3v6rM3vkrq
                                                                                                                                                                                                                                  MD5:44F2EE567A3E9A021A3C16062CEAE220
                                                                                                                                                                                                                                  SHA1:180E938584F0A57AC0C3F85E6574BC48291D820E
                                                                                                                                                                                                                                  SHA-256:847C14C297DBE4D8517DEBAA8ED555F3DAEDF843D6BAD1F411598631A0BD3507
                                                                                                                                                                                                                                  SHA-512:BEB005D006E432963F9C1EF474A1E3669C8B7AF0681681E74DDA8FE9C8EE04D307EF85CF0257DA72663026138D38807A6ABA1255337CF8CC724ED1993039B40C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_DO DATE_FORMAT "%m/%d/%Y". ::msgcat::mcset es_DO TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_DO DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.86970949384834
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmozgUFLoro+3v6rZoz9+3v9f6HK:4EnLzu8ZgUFcF3v6ruI3vMq
                                                                                                                                                                                                                                  MD5:CCB036C33BA7C8E488D37E754075C6CF
                                                                                                                                                                                                                                  SHA1:336548C8D361B1CAA8BDF698E148A88E47FB27A6
                                                                                                                                                                                                                                  SHA-256:2086EE8D7398D5E60E5C3048843B388437BD6F2507D2293CA218936E3BF61E59
                                                                                                                                                                                                                                  SHA-512:05058262E222653CF3A4C105319B74E07322AEE726CC11AEB2B562F01FF2476E3169EA829BF8B66E1B76617CB58E45423480E5A6CB3B3D4B33AA4DDDFA52D111
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_EC DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset es_EC TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_EC DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.86395314548955
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmohvjbJFLoI3v6rZoho+3vjb0f6HK:4EnLzu8PJFB3v6r23vbq
                                                                                                                                                                                                                                  MD5:1E6062716A094CC3CE1F2C97853CD3CD
                                                                                                                                                                                                                                  SHA1:499F69E661B3B5747227B31DE4539CAF355CCAAC
                                                                                                                                                                                                                                  SHA-256:1BC22AF98267D635E3F07615A264A716940A2B1FAA5CAA3AFF54D4C5A4A34370
                                                                                                                                                                                                                                  SHA-512:7C3FB65EC76A2F35354E93A47C3A59848170AAF504998CEF66AEBAAD39D303EC67BE212C6FACC98305E35FFEBF23CCB7E34396F11987E81D76B3685E6B5E89B3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_GT DATE_FORMAT "%e/%m/%Y". ::msgcat::mcset es_GT TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_GT DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.902544453689719
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoIvriP/FLoP3v6rZoIo+3vrig6HK:4EnLzu8w+nF+3v6rP3v+lq
                                                                                                                                                                                                                                  MD5:AAE4A89F6AB01044D6BA3511CBE6FE66
                                                                                                                                                                                                                                  SHA1:639A94279453B0028995448FD2E221C1BDE23CEE
                                                                                                                                                                                                                                  SHA-256:A2D25880C64309552AACED082DEED1EE006482A14CAB97DB524E9983EE84ACFC
                                                                                                                                                                                                                                  SHA-512:E2BE94973C931B04C730129E9B9746BB76E7AC7F5AAA8D7899903B8C86B4E3D4A955E9580CF2C64DE48AFD6A2A9386337C2F8A8128A511AFBFBBA09CC032A76E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_HN DATE_FORMAT "%m-%d-%Y". ::msgcat::mcset es_HN TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_HN DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.863953145489551
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoPjbJFLoH+3v6rZoI+3vjb0f6HK:4EnLzu8NJF73v6rE3vbq
                                                                                                                                                                                                                                  MD5:F60290CF48AA4EDCA938E496F43135FD
                                                                                                                                                                                                                                  SHA1:0EE5A36277EA4E7A1F4C6D1D9EE32D90918DA25C
                                                                                                                                                                                                                                  SHA-256:D0FAA9D7997D5696BFF92384144E0B9DFB2E4C38375817613F81A89C06EC6383
                                                                                                                                                                                                                                  SHA-512:380DFCD951D15E53FCB1DEF4B892C8FD65CEFBF0857D5A7347FF3ED34F69ADD53AEEF895EDCFC6D2F24A65AB8F67CF813AEA2045EDBF3BF182BD0635B5ACB1A4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_MX DATE_FORMAT "%e/%m/%Y". ::msgcat::mcset es_MX TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_MX DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.872124246425178
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoe/GriP/FLo3W3v6rZoe/T+3vrig6HK:4EnLzu8Ae+nFmW3v6rxS3v+lq
                                                                                                                                                                                                                                  MD5:2C4C45C450FEA6BA0421281F1CF55A2A
                                                                                                                                                                                                                                  SHA1:5249E31611A670EAEEF105AB4AD2E5F14B355CAE
                                                                                                                                                                                                                                  SHA-256:4B28B46981BBB78CBD2B22060E2DD018C66FCFF1CEE52755425AD4900A90D6C3
                                                                                                                                                                                                                                  SHA-512:969A4566C7B5FAF36204865D5BC22C849FBB44F0D16B04B9A9473B05DBABF22AEB9B77F282A44BB85D7E2A56C4E5BCE59E4E4CDEB3F6DD52AF47C65C709A3690
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_NI DATE_FORMAT "%m-%d-%Y". ::msgcat::mcset es_NI TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_NI DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.860352858208512
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoX5rQZnFLoHE3v6rZoXa+3vrQZg6HK:4EnLzu8vkZF93v6rm3vkrq
                                                                                                                                                                                                                                  MD5:148626186A258E58851CC0A714B4CFD6
                                                                                                                                                                                                                                  SHA1:7F14D46F66D8A94A493702DCDE7A50C1D71774B2
                                                                                                                                                                                                                                  SHA-256:6832DC5AB9F610883784CF702691FCF16850651BC1C6A77A0EFA81F43BC509AC
                                                                                                                                                                                                                                  SHA-512:2B452D878728BFAFEA9A60030A26E1E1E44CE0BB26C7D9B8DB1D7C4F1AD3217770374BD4EDE784D0A341AB5427B08980FF4A62141FAF7024AB17296FE98427AC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_PA DATE_FORMAT "%m/%d/%Y". ::msgcat::mcset es_PA TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_PA DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.8632965835916195
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoIgUFLoQ9X3v6rZoI9+3v9f6HK:4EnLzu8jUFZ3v6rS3vMq
                                                                                                                                                                                                                                  MD5:74F014096C233B4D1D38A9DFB15B01BB
                                                                                                                                                                                                                                  SHA1:75C28321AFED3D9CDA3EBF3FD059CDEA597BB13A
                                                                                                                                                                                                                                  SHA-256:CC826C93682EF19D29AB6304657E07802C70CF18B1E5EA99C3480DF6D2383983
                                                                                                                                                                                                                                  SHA-512:24E7C3914BF095B55DE7F01CB537E20112E10CF741333FD0185FEF0B0E3A1CD9651C2B2EDC470BCF18F51ADB352CA7550CFBF4F79342DCA33F7E0841AEDEBA8D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_PE DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset es_PE TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_PE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.859298425911738
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo06GriP/FLoeW3v6rZo06T+3vrig6HK:4EnLzu8ZG+nFy3v6rAK3v+lq
                                                                                                                                                                                                                                  MD5:AEB569C12A50B8C4A57C8034F666C1B3
                                                                                                                                                                                                                                  SHA1:24D8B096DD8F1CFA101D6F36606D003D4FCC7B4D
                                                                                                                                                                                                                                  SHA-256:19563225CE7875696C6AA2C156E6438292DE436B58F8D7C23253E3132069F9A2
                                                                                                                                                                                                                                  SHA-512:B5432D7A80028C3AD3A7819A5766B07EDB56CEE493C0903EDFA72ACEE0C2FFAA955A8850AA48393782471905FFF72469F508B19BE83CC626478072FFF6B60B5D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_PR DATE_FORMAT "%m-%d-%Y". ::msgcat::mcset es_PR TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_PR DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.871431420165191
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo/5UFLovE3v6rZo/a+3v9f6HK:4EnLzu8XUF13v6re3vMq
                                                                                                                                                                                                                                  MD5:D24FF8FAEE658DD516AC298B887D508A
                                                                                                                                                                                                                                  SHA1:61990E6F3E399B87060E522ABCDE77A832019167
                                                                                                                                                                                                                                  SHA-256:94FF64201C27AB04F362617DD56B7D85B223BCCA0735124196E7669270C591F0
                                                                                                                                                                                                                                  SHA-512:1409E1338988BC70C19DA2F6C12A39E311CF91F6BB759575C95E125EA67949F17BBE450B2CD29E3F6FDA1421C742859CB990921949C6940B34D7A8B8545FF8F0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_PY DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset es_PY TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_PY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.883202808381857
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmofriP/FLo3+3v6rZoY+3vrig6HK:4EnLzu89+nFO+3v6rw3v+lq
                                                                                                                                                                                                                                  MD5:6A013D20A3C983639EAF89B93AB2037C
                                                                                                                                                                                                                                  SHA1:9ABEC22E82C1638B9C8E197760C66E370299BB93
                                                                                                                                                                                                                                  SHA-256:E3268C95E9B7D471F5FD2436C17318D5A796220BA39CEBEBCD39FBB0141A49CE
                                                                                                                                                                                                                                  SHA-512:C4FE0493A2C45DA792D0EE300EC1D30E25179209FE39ACCD74B23ACDFF0A72DEEEED1A1D12842101E0A4E57E8FEADF54F926347B6E9B987B70A52E0557919FC2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_SV DATE_FORMAT "%m-%d-%Y". ::msgcat::mcset es_SV TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_SV DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.877844330421912
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmooygUFLooq9X3v6rZooy9+3v9f6HK:4EnLzu8SrUFzsX3v6rZJ3vMq
                                                                                                                                                                                                                                  MD5:40250432AD0DC4FF168619719F91DBCA
                                                                                                                                                                                                                                  SHA1:D38532CA84E80FE70C69108711E3F9A7DFD5230F
                                                                                                                                                                                                                                  SHA-256:BA557A3C656275A0C870FB8466F2237850F5A7CF2D001919896725BB3D3EAA4B
                                                                                                                                                                                                                                  SHA-512:26FB4B3332E2C06628869D4C63B7BAB4F42FF73D1D4FD8603323A93067F60D9505C70D1A14D7E34A9880E2993183FC09D43013F3BEB8BC48732F08181643D05D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_UY DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset es_UY TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_UY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.882638228899482
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoXrUFLoXK3v6rZoXs+3v9f6HK:4EnLzu8VUFH3v6r83vMq
                                                                                                                                                                                                                                  MD5:F3A789CBC6B9DD4F5BA5182C421A9F78
                                                                                                                                                                                                                                  SHA1:7C2AF280C90B0104AB49B2A527602374254274CE
                                                                                                                                                                                                                                  SHA-256:64F796C5E3E300448A1F309A0DA7D43548CC40511036FF3A3E0C917E32147D62
                                                                                                                                                                                                                                  SHA-512:822C0D27D2A72C9D5336C1BCEDC13B564F0FB12146CF8D30FBE77B9C4728C4B3BF456AC62DACD2962A6B5B84761354B31CD505105EDB060BF202BA0B0A830772
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset es_VE DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset es_VE TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset es_VE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1206
                                                                                                                                                                                                                                  Entropy (8bit):4.321464868793769
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8W1Yn1YZ1waUuvVTGiMiLpBgoVTJ01iLTh/w2SJmG5F1svtFmsv5d:46K1y1Mv9GrM9oc/FSJmG5F1KtFmK5d
                                                                                                                                                                                                                                  MD5:3B4BEE5DD7441A63A31F89D6DFA059BA
                                                                                                                                                                                                                                  SHA1:BEE39E45FA3A76B631B4C2D0F937FF6041E09332
                                                                                                                                                                                                                                  SHA-256:CCC2B4738DB16FAFB48BFC77C9E2F8BE17BC19E4140E48B61F3EF1CE7C9F3A8C
                                                                                                                                                                                                                                  SHA-512:AEC24C75CB00A506A46CC631A2A804C59FBE4F8EBCB86CBA0F4EE5DF7B7C12ED7D25845150599837B364E40BBFDB68244991ED5AF59C9F7792F8362A1E728883
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset et DAYS_OF_WEEK_ABBREV [list \. "P"\. "E"\. "T"\. "K"\. "N"\. "R"\. "L"]. ::msgcat::mcset et DAYS_OF_WEEK_FULL [list \. "p\u00fchap\u00e4ev"\. "esmasp\u00e4ev"\. "teisip\u00e4ev"\. "kolmap\u00e4ev"\. "neljap\u00e4ev"\. "reede"\. "laup\u00e4ev"]. ::msgcat::mcset et MONTHS_ABBREV [list \. "Jaan"\. "Veebr"\. "M\u00e4rts"\. "Apr"\. "Mai"\. "Juuni"\. "Juuli"\. "Aug"\. "Sept"\. "Okt"\. "Nov"\. "Dets"\. ""]. ::msgcat::mcset et MONTHS_FULL [list \. "Jaanuar"\. "Veebruar"\. "M\u00e4rts"\. "Aprill"\. "Mai"\. "Juuni"\. "Juuli"\. "August"\. "September"\. "Oktoober"\. "November"\. "Detsember"\. ""]. ::msgcat::mcset et
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):985
                                                                                                                                                                                                                                  Entropy (8bit):3.9137059580146376
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu80P6/XTPi6/XTotXSSzTGsy+trjz4HsKI:46qWKWoX75Bb4Mv
                                                                                                                                                                                                                                  MD5:E27FEB15A6C300753506FC706955AC90
                                                                                                                                                                                                                                  SHA1:FDFAC22CC0839B29799001838765EB4A232FD279
                                                                                                                                                                                                                                  SHA-256:7DCC4966A5C13A52B6D1DB62BE200B9B5A1DECBACCFCAF15045DD03A2C3E3FAA
                                                                                                                                                                                                                                  SHA-512:C54A0F72BC0DAF6A411466565467A2783690EA19F4D401A5448908944A0A6F3F74A7976FA0F851F15B6A97C6D6A3C41FB8BBC8EA42B5D5E3C17A5C8A37436FC5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset eu DAYS_OF_WEEK_ABBREV [list \. "igandea"\. "astelehena"\. "asteartea"\. "asteazkena"\. "osteguna"\. "ostirala"\. "larunbata"]. ::msgcat::mcset eu DAYS_OF_WEEK_FULL [list \. "igandea"\. "astelehena"\. "asteartea"\. "asteazkena"\. "osteguna"\. "ostirala"\. "larunbata"]. ::msgcat::mcset eu MONTHS_ABBREV [list \. "urt"\. "ots"\. "mar"\. "api"\. "mai"\. "eka"\. "uzt"\. "abu"\. "ira"\. "urr"\. "aza"\. "abe"\. ""]. ::msgcat::mcset eu MONTHS_FULL [list \. "urtarrila"\. "otsaila"\. "martxoa"\. "apirila"\. "maiatza"\. "ekaina"\. "uztaila"\. "abuztua"\. "iraila"\. "urria"\. "azaroa"\. "abendua"\. ""].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):287
                                                                                                                                                                                                                                  Entropy (8bit):4.8689948586471825
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoszFnJF+l6VALoszw3vG5oszw3v6X5osz++3v/R3v:4EnLzu8gL+l6Vt3vf3v6P3vZf
                                                                                                                                                                                                                                  MD5:D20788793E6CC1CD07B3AFD2AA135CB6
                                                                                                                                                                                                                                  SHA1:3503FCB9490261BA947E89D5494998CEBB157223
                                                                                                                                                                                                                                  SHA-256:935164A2D2D14815906B438562889B31139519B3A8E8DB3D2AC152A77EC591DC
                                                                                                                                                                                                                                  SHA-512:F65E7D27BD0A99918D6F21C425238000563C2E3A4162D6806EEAC7C9DCB9798987AFFB8BE01899D577078F6297AF468DBAEBEB6375C09ABF332EB44E328F0E8B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset eu_ES DATE_FORMAT "%a, %Yeko %bren %da". ::msgcat::mcset eu_ES TIME_FORMAT "%T". ::msgcat::mcset eu_ES TIME_FORMAT_12 "%T". ::msgcat::mcset eu_ES DATE_TIME_FORMAT "%y-%m-%d %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1664
                                                                                                                                                                                                                                  Entropy (8bit):4.1508548760580295
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8BMnqZEjgYDT0/y3xg2LSREyqyxDfsycNp/Tpn29Ey5ykDDzi:46cGTYDT0/ya4KIySNnCz2
                                                                                                                                                                                                                                  MD5:7E74DE42FBDA63663B58B2E58CF30549
                                                                                                                                                                                                                                  SHA1:CB210740F56208E8E621A45D545D7DEFCAE8BCAF
                                                                                                                                                                                                                                  SHA-256:F9CA4819E8C8B044D7D68C97FC67E0F4CCD6245E30024161DAB24D0F7C3A9683
                                                                                                                                                                                                                                  SHA-512:A03688894BD44B6AB87DC6CAB0A5EC348C9117697A2F9D00E27E850F23EFDC2ADBD53CAC6B9ED33756D3A87C9211B6EE8DF06020F6DA477B9948F52E96071F76
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fa DAYS_OF_WEEK_ABBREV [list \. "\u06cc\u2214"\. "\u062f\u2214"\. "\u0633\u2214"\. "\u0686\u2214"\. "\u067e\u2214"\. "\u062c\u2214"\. "\u0634\u2214"]. ::msgcat::mcset fa DAYS_OF_WEEK_FULL [list \. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\. "\u062f\u0648\u0634\u0646\u0628\u0647"\. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\. "\u062c\u0645\u0639\u0647"\. "\u0634\u0646\u0628\u0647"]. ::msgcat::mcset fa MONTHS_ABBREV [list \. "\u0698\u0627\u0646"\. "\u0641\u0648\u0631"\. "\u0645\u0627\u0631"\. "\u0622\u0648\u0631"\. "\u0645\u0640\u0647"\. "\u0698\u0648\u0646"\. "\u0698\u0648\u06cc"\. "\u0627\u0648\u062a"\. "\u0633\u067e\u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1957
                                                                                                                                                                                                                                  Entropy (8bit):4.433104256056609
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8XMnSZEjgYDT0g3xg2LSREyqyxDf5cNp/Tpn29Ey5ykDDzJ6v3Nev0Nv0f:46OeTYDT0ga4K9SNnCz0v9o0JI
                                                                                                                                                                                                                                  MD5:E6DBD1544A69BFC653865B723395E79C
                                                                                                                                                                                                                                  SHA1:5E4178E7282807476BD0D6E1F2E320E42FA0DE77
                                                                                                                                                                                                                                  SHA-256:6360CE0F31EE593E311B275F3C1F1ED427E237F31010A4280EF2C58AA6F2633A
                                                                                                                                                                                                                                  SHA-512:8D77DCB4333F043502CED7277AEEB0453A2C019E1A46826A0FE90F0C480A530F5646A4F76ECC1C15825601FC8B646ED7C78E53996E2908B341BA4ED1392B95F0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fa_IN DAYS_OF_WEEK_ABBREV [list \. "\u06cc\u2214"\. "\u062f\u2214"\. "\u0633\u2214"\. "\u0686\u2214"\. "\u067e\u2214"\. "\u062c\u2214"\. "\u0634\u2214"]. ::msgcat::mcset fa_IN DAYS_OF_WEEK_FULL [list \. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\. "\u062f\u0648\u0634\u0646\u0628\u0647"\. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\. "\u062c\u0645\u0639\u0647"\. "\u0634\u0646\u0628\u0647"]. ::msgcat::mcset fa_IN MONTHS_ABBREV [list \. "\u0698\u0627\u0646"\. "\u0641\u0648\u0631"\. "\u0645\u0627\u0631"\. "\u0622\u0648\u0631"\. "\u0645\u0640\u0647"\. "\u0698\u0648\u0646"\. "\u0698\u0648\u06cc"\. "\u0627\u0648\u062a"\. "\u063
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):417
                                                                                                                                                                                                                                  Entropy (8bit):5.087144086729547
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu82vGz7AhF/Q3vf3v6TANv+K3vz7AA7:4azu8vPm/ivfvF9xvP9
                                                                                                                                                                                                                                  MD5:044BAAA627AD3C3585D229865A678357
                                                                                                                                                                                                                                  SHA1:9D64038C00253A7EEDA4921B9C5E34690E185061
                                                                                                                                                                                                                                  SHA-256:CF492CBD73A6C230725225D70566B6E46D5730BD3F63879781DE4433965620BE
                                                                                                                                                                                                                                  SHA-512:DA138F242B44111FAFE9EFE986EB987C26A64D9316EA5644AC4D3D4FEC6DF9F5D55F342FC194BC487A1B7C740F931D883A574863B48396D837D1E270B733F735
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fa_IR AM "\u0635\u0628\u062d". ::msgcat::mcset fa_IR PM "\u0639\u0635\u0631". ::msgcat::mcset fa_IR DATE_FORMAT "%d\u2044%m\u2044%Y". ::msgcat::mcset fa_IR TIME_FORMAT "%S:%M:%H". ::msgcat::mcset fa_IR TIME_FORMAT_12 "%S:%M:%l %P". ::msgcat::mcset fa_IR DATE_TIME_FORMAT "%d\u2044%m\u2044%Y %S:%M:%H %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1145
                                                                                                                                                                                                                                  Entropy (8bit):4.249302428029841
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8ZeTWSS/DatuUSlWCBTtotL8W183eYKvt3v3eG:46sWp/DatBSPtoNmpMt/J
                                                                                                                                                                                                                                  MD5:34FE8E2D987FE534BD88291046F6820B
                                                                                                                                                                                                                                  SHA1:B173700C176336BD1B123C2A055A685F73B60C07
                                                                                                                                                                                                                                  SHA-256:BE0D2DCE08E6CD786BC3B07A1FB1ADC5B2CF12053C99EACDDAACDDB8802DFB9C
                                                                                                                                                                                                                                  SHA-512:4AC513F092D2405FEF6E30C828AE94EDBB4B0B0E1C68C1168EB2498C186DB054EBF697D6B55B49F865A2284F75B7D5490AFE7A80F887AE8312E6F9A5EFE16390
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fi DAYS_OF_WEEK_ABBREV [list \. "su"\. "ma"\. "ti"\. "ke"\. "to"\. "pe"\. "la"]. ::msgcat::mcset fi DAYS_OF_WEEK_FULL [list \. "sunnuntai"\. "maanantai"\. "tiistai"\. "keskiviikko"\. "torstai"\. "perjantai"\. "lauantai"]. ::msgcat::mcset fi MONTHS_ABBREV [list \. "tammi"\. "helmi"\. "maalis"\. "huhti"\. "touko"\. "kes\u00e4"\. "hein\u00e4"\. "elo"\. "syys"\. "loka"\. "marras"\. "joulu"\. ""]. ::msgcat::mcset fi MONTHS_FULL [list \. "tammikuu"\. "helmikuu"\. "maaliskuu"\. "huhtikuu"\. "toukokuu"\. "kes\u00e4kuu"\. "hein\u00e4kuu"\. "elokuu"\. "syyskuu"\. "lokakuu"\. "marraskuu"\. "joulukuu"\. ""]. ::msgcat
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):986
                                                                                                                                                                                                                                  Entropy (8bit):4.07740021579371
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu87mY5mvAqO6RxmtV5qHbMj6aywE1ZD4ScMfRDc6VZTEpSecbLwJQT1Y4:4azu874/RqEXsSpffTBtbQQT1t
                                                                                                                                                                                                                                  MD5:996B699F6821A055B826415446A11C8E
                                                                                                                                                                                                                                  SHA1:C382039ED7D2AE8D96CF2EA55FA328AE9CFD2F7D
                                                                                                                                                                                                                                  SHA-256:F249DD1698ED1687E13654C04D08B829193027A2FECC24222EC854B59350466A
                                                                                                                                                                                                                                  SHA-512:AB6F5ABC9823C7F7A67BA1E821680ACD37761F83CD1F46EC731AB2B72AA34C2E523ACE288E9DE70DB3D58E11F5CB42ECB5A5E4E39BFD7DFD284F1FF6B637E11D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fo DAYS_OF_WEEK_ABBREV [list \. "sun"\. "m\u00e1n"\. "t\u00fds"\. "mik"\. "h\u00f3s"\. "fr\u00ed"\. "ley"]. ::msgcat::mcset fo DAYS_OF_WEEK_FULL [list \. "sunnudagur"\. "m\u00e1nadagur"\. "t\u00fdsdagur"\. "mikudagur"\. "h\u00f3sdagur"\. "fr\u00edggjadagur"\. "leygardagur"]. ::msgcat::mcset fo MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "mai"\. "jun"\. "jul"\. "aug"\. "sep"\. "okt"\. "nov"\. "des"\. ""]. ::msgcat::mcset fo MONTHS_FULL [list \. "januar"\. "februar"\. "mars"\. "apr\u00edl"\. "mai"\. "juni"\. "juli"\. "august"\. "september"\. "oktober"\. "november"\. "desember"\. ""].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.816022066048386
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoZA4HFLoZd3vG5oZd3v6X5oZd+3vnFDoAov:4EnLzu8kyFO3vf3v6f3v9dy
                                                                                                                                                                                                                                  MD5:A76D09A4FA15A2C985CA6BDD22989D6A
                                                                                                                                                                                                                                  SHA1:E6105EBCDC547FE2E2FE9EDDC9C573BBDAD85AD0
                                                                                                                                                                                                                                  SHA-256:7145B57AC5C074BCA968580B337C04A71BBD6EFB93AFAF291C1361FD700DC791
                                                                                                                                                                                                                                  SHA-512:D16542A1CCDC3F5C2A20300B7E38F43F94F7753E0E99F08EB7240D4F286B263815AD481B29F4E96F268E24BA17C5E135E356448685E1BF65B2B63CE6146AA54C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fo_FO DATE_FORMAT "%d/%m-%Y". ::msgcat::mcset fo_FO TIME_FORMAT "%T". ::msgcat::mcset fo_FO TIME_FORMAT_12 "%T". ::msgcat::mcset fo_FO DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1205
                                                                                                                                                                                                                                  Entropy (8bit):4.313638548211754
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8qW09HSZ2p60wTyVz5bGzJzzTK+VUuG4CNnvxvB:46JYY5moleiUb42vlB
                                                                                                                                                                                                                                  MD5:B475F8E7D7065A67E73B1E5CDBF9EB1F
                                                                                                                                                                                                                                  SHA1:1B689EDC29F8BC4517936E5D77A084083F12AE31
                                                                                                                                                                                                                                  SHA-256:7A87E418B6D8D14D8C11D63708B38D607D28F7DDBF39606C7D8FBA22BE7892CA
                                                                                                                                                                                                                                  SHA-512:EA77EFF9B23A02F59526499615C08F1314A91AB41561856ED7DF45930FDD8EC11A105218890FD012045C4CC40621C226F94BDC3BEB62B83EA8FAA7AEC20516E7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fr DAYS_OF_WEEK_ABBREV [list \. "dim."\. "lun."\. "mar."\. "mer."\. "jeu."\. "ven."\. "sam."]. ::msgcat::mcset fr DAYS_OF_WEEK_FULL [list \. "dimanche"\. "lundi"\. "mardi"\. "mercredi"\. "jeudi"\. "vendredi"\. "samedi"]. ::msgcat::mcset fr MONTHS_ABBREV [list \. "janv."\. "f\u00e9vr."\. "mars"\. "avr."\. "mai"\. "juin"\. "juil."\. "ao\u00fbt"\. "sept."\. "oct."\. "nov."\. "d\u00e9c."\. ""]. ::msgcat::mcset fr MONTHS_FULL [list \. "janvier"\. "f\u00e9vrier"\. "mars"\. "avril"\. "mai"\. "juin"\. "juillet"\. "ao\u00fbt"\. "septembre"\. "octobre"\. "novembre"\. "d\u00e9cembre"\. ""]. ::msgcat::mcset fr BCE "a
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.863262857917797
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoXqH5oIX3vG5oIX3v6X5og+3vnFDoAov:4EnLzu81qHd3v63v6Y3v9dy
                                                                                                                                                                                                                                  MD5:483652B6A3D8010C3CDB6CAD0AD95E72
                                                                                                                                                                                                                                  SHA1:8FCDB01D0729E9F1A0CAC56F79EDB79A37734AF5
                                                                                                                                                                                                                                  SHA-256:980E703DFB1EEDE7DE48C958F6B501ED4251F69CB0FBCE0FCA85555F5ACF134A
                                                                                                                                                                                                                                  SHA-512:0282B8F3884BB4406F69AF2D2F44E431FB8077FEA86D09ED5607BC0932A049853D0C5CAF0B57EF0289F42A8265F76CC4B10111A28B1E0E9BD54E9319B25D8DB6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fr_BE DATE_FORMAT "%d/%m/%y". ::msgcat::mcset fr_BE TIME_FORMAT "%T". ::msgcat::mcset fr_BE TIME_FORMAT_12 "%T". ::msgcat::mcset fr_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.843031408533295
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmooI9jo13vG5o13v6X5o1+3vnFDoAov:4EnLzu8eI9Q3vB3v613v9dy
                                                                                                                                                                                                                                  MD5:017D816D73DAB852546169F3EC2D16F2
                                                                                                                                                                                                                                  SHA1:3145BB54D9E1E4D9166186D5B43F411CE0250594
                                                                                                                                                                                                                                  SHA-256:F16E212D5D1F6E83A9FC4E56874E4C7B8F1947EE882610A73199480319EFA529
                                                                                                                                                                                                                                  SHA-512:4D4EF395B15F750F16EC64162BE8AB4B082C6CD1877CA63D5EA4A5E940A7F98E46D792115FD105B293DC43714E8662BC4411E14E93F09769A064622E52EDE258
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fr_CA DATE_FORMAT "%Y-%m-%d". ::msgcat::mcset fr_CA TIME_FORMAT "%T". ::msgcat::mcset fr_CA TIME_FORMAT_12 "%T". ::msgcat::mcset fr_CA DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):281
                                                                                                                                                                                                                                  Entropy (8bit):4.866549204705568
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoFt2poF+3vG5oF+3v6X5o++3vnFDoAov:4EnLzu8btn+3vB+3v6+3v9dy
                                                                                                                                                                                                                                  MD5:8B27EFF0D45F536852E7A819500B7F93
                                                                                                                                                                                                                                  SHA1:CAED7D4334BAD8BE586A1AEEE270FB6913A03512
                                                                                                                                                                                                                                  SHA-256:AB160BFDEB5C3ADF071E01C78312A81EE4223BBF5470AB880972BBF5965291F3
                                                                                                                                                                                                                                  SHA-512:52DD94F524C1D9AB13F5933265691E8C44B2946F507DE30D789FDCFEA7839A4076CB55A01CEB49194134D7BC84E4F490341AAB9DFB75BB960B03829D6550872B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset fr_CH DATE_FORMAT "%d. %m. %y". ::msgcat::mcset fr_CH TIME_FORMAT "%T". ::msgcat::mcset fr_CH TIME_FORMAT_12 "%T". ::msgcat::mcset fr_CH DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1141
                                                                                                                                                                                                                                  Entropy (8bit):4.24180563443443
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8qppr5xqPs5Jpwe3zESbs5JpbxK+dfJ:46ct5XGe3zwXu4fJ
                                                                                                                                                                                                                                  MD5:88D5CB026EBC3605E8693D9A82C2D050
                                                                                                                                                                                                                                  SHA1:C2A613DC7C367A841D99DE15876F5E7A8027BBF8
                                                                                                                                                                                                                                  SHA-256:057C75C1AD70653733DCE43EA5BF151500F39314E8B0236EE80F8D5DB623627F
                                                                                                                                                                                                                                  SHA-512:253575BFB722CF06937BBE4E9867704B95EFE7B112B370E1430A2027A1818BD2560562A43AD2D067386787899093B25AE84ABFE813672A15A649FEF487E31F7A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ga DAYS_OF_WEEK_ABBREV [list \. "Domh"\. "Luan"\. "M\u00e1irt"\. "C\u00e9ad"\. "D\u00e9ar"\. "Aoine"\. "Sath"]. ::msgcat::mcset ga DAYS_OF_WEEK_FULL [list \. "D\u00e9 Domhnaigh"\. "D\u00e9 Luain"\. "D\u00e9 M\u00e1irt"\. "D\u00e9 C\u00e9adaoin"\. "D\u00e9ardaoin"\. "D\u00e9 hAoine"\. "D\u00e9 Sathairn"]. ::msgcat::mcset ga MONTHS_ABBREV [list \. "Ean"\. "Feabh"\. "M\u00e1rta"\. "Aib"\. "Beal"\. "Meith"\. "I\u00fail"\. "L\u00fan"\. "MF\u00f3mh"\. "DF\u00f3mh"\. "Samh"\. "Noll"\. ""]. ::msgcat::mcset ga MONTHS_FULL [list \. "Ean\u00e1ir"\. "Feabhra"\. "M\u00e1rta"\. "Aibre\u00e1n"\. "M\u00ed na Bealtaine"\. "Meith"\. "I\u00fail"\. "L\u00fanasa"
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.7755422576113595
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmobHAyg0obHAqo+3vG5obHAqo+3v6X5obHAy9+3vnFDoAov:4EnLzu8s33vj3v6r3v9dy
                                                                                                                                                                                                                                  MD5:04452D43DA05A94414973F45CDD12869
                                                                                                                                                                                                                                  SHA1:AEEDCC2177B592A0025A1DBCFFC0EF3634DBF562
                                                                                                                                                                                                                                  SHA-256:2072E48C98B480DB5677188836485B4605D5A9D99870AC73B5BFE9DCC6DB46F4
                                                                                                                                                                                                                                  SHA-512:5A01156FD5AB662EE9D626518B4398A161BAF934E3A618B3A18839A944AEEAEE6FE1A5279D7750511B126DB3AD2CC992CDA067573205ACBC211C34C8A099305F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ga_IE DATE_FORMAT "%d.%m.%y". ::msgcat::mcset ga_IE TIME_FORMAT "%T". ::msgcat::mcset ga_IE TIME_FORMAT_12 "%T". ::msgcat::mcset ga_IE DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):950
                                                                                                                                                                                                                                  Entropy (8bit):4.037076523160125
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8LpP8ihyz/ptFOBViNef9kekIsnyFo0:46J0i0zRtUB0c9dkVneo0
                                                                                                                                                                                                                                  MD5:B940E67011DDBAD6192E9182C5F0CCC0
                                                                                                                                                                                                                                  SHA1:83A284899785956ECB015BBB871E7E04A7C36585
                                                                                                                                                                                                                                  SHA-256:C71A07169CDBE9962616D28F38C32D641DA277E53E67F8E3A69EB320C1E2B88C
                                                                                                                                                                                                                                  SHA-512:28570CB14452CA5285D97550EA77C9D8F71C57DE6C1D144ADB00B93712F588AF900DA32C10C3A81C7A2DEE11A3DC843780D24218F53920AB72E90321677CC9E8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset gl DAYS_OF_WEEK_ABBREV [list \. "Dom"\. "Lun"\. "Mar"\. "M\u00e9r"\. "Xov"\. "Ven"\. "S\u00e1b"]. ::msgcat::mcset gl DAYS_OF_WEEK_FULL [list \. "Domingo"\. "Luns"\. "Martes"\. "M\u00e9rcores"\. "Xoves"\. "Venres"\. "S\u00e1bado"]. ::msgcat::mcset gl MONTHS_ABBREV [list \. "Xan"\. "Feb"\. "Mar"\. "Abr"\. "Mai"\. "Xu\u00f1"\. "Xul"\. "Ago"\. "Set"\. "Out"\. "Nov"\. "Dec"\. ""]. ::msgcat::mcset gl MONTHS_FULL [list \. "Xaneiro"\. "Febreiro"\. "Marzo"\. "Abril"\. "Maio"\. "Xu\u00f1o"\. "Xullo"\. "Agosto"\. "Setembro"\. "Outubro"\. "Novembro"\. "Decembro"\. ""].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.839318757139709
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoPhkgvNLoPxsF3v6aZoPhk9+3vR6HK:4EnLzu8NrvNEK3v6a2J3voq
                                                                                                                                                                                                                                  MD5:3FCDF0FC39C8E34F6270A646A996F663
                                                                                                                                                                                                                                  SHA1:6999E82148E1D1799C389BCC6C6952D5514F4A4B
                                                                                                                                                                                                                                  SHA-256:BC2B0424CF27BEF67F309E2B6DFFEF4D39C46F15D91C15E83E070C7FD4E20C9C
                                                                                                                                                                                                                                  SHA-512:CDB9ED694A7E555EB321F559E9B0CC0998FD526ADEF33AD08C56943033351D70900CD6EC62D380E23AB9F65CCFB85F4EEEB4E17FA8CC05E56C2AC57FBEDE721E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset gl_ES DATE_FORMAT "%d %B %Y". ::msgcat::mcset gl_ES TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset gl_ES DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1037
                                                                                                                                                                                                                                  Entropy (8bit):4.13549698574103
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu81WjLHkFQSMnKIeCPHy3CAVfbku5SJ:460jwyLTySI4J
                                                                                                                                                                                                                                  MD5:3350E1228CF7157ECE68762F967F2F32
                                                                                                                                                                                                                                  SHA1:2D0411DA2F6E0441B1A8683687178E9EB552B835
                                                                                                                                                                                                                                  SHA-256:75AA686FF901C9E66E51D36E8E78E5154B57EE9045784568F6A8798EA9689207
                                                                                                                                                                                                                                  SHA-512:1D0B44F00A5E6D7B8CECB67EAF060C6053045610CF7246208C8E63E7271C7780587A184D38ECFDFDCFB976F9433FEFDA0BAF8981FCD197554D0874ED1E6B6428
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset gv DAYS_OF_WEEK_ABBREV [list \. "Jed"\. "Jel"\. "Jem"\. "Jerc"\. "Jerd"\. "Jeh"\. "Jes"]. ::msgcat::mcset gv DAYS_OF_WEEK_FULL [list \. "Jedoonee"\. "Jelhein"\. "Jemayrt"\. "Jercean"\. "Jerdein"\. "Jeheiney"\. "Jesarn"]. ::msgcat::mcset gv MONTHS_ABBREV [list \. "J-guer"\. "T-arree"\. "Mayrnt"\. "Avrril"\. "Boaldyn"\. "M-souree"\. "J-souree"\. "Luanistyn"\. "M-fouyir"\. "J-fouyir"\. "M.Houney"\. "M.Nollick"\. ""]. ::msgcat::mcset gv MONTHS_FULL [list \. "Jerrey-geuree"\. "Toshiaght-arree"\. "Mayrnt"\. "Averil"\. "Boaldyn"\. "Mean-souree"\. "Jerrey-souree"\. "Luanistyn"\. "Mean-fouyir"\. "Jerrey-fouyir"\. "Mee Houney"\.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.890913756172577
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoQbtvvNLoQLE3v6aZoQbto+3vR6HK:4EnLzu8CbtvvNBLE3v6avbtF3voq
                                                                                                                                                                                                                                  MD5:A65040748621B18B1F88072883891280
                                                                                                                                                                                                                                  SHA1:4D0ED6668A99BAC9B273B0FA8BC74EB6BB9DDFC8
                                                                                                                                                                                                                                  SHA-256:823AF00F4E44613E929D32770EDB214132B6E210E872751624824DA5F0B78448
                                                                                                                                                                                                                                  SHA-512:16FFD4107C3B85619629B2CD8A48AB9BC3763FA6E4FE4AE910EDF3B42209CEEB8358D4E7E531C2417875D05E5F801BB19B10130FA8BF70E44CFD8F1BA06F6B6E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset gv_GB DATE_FORMAT "%d %B %Y". ::msgcat::mcset gv_GB TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset gv_GB DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1938
                                                                                                                                                                                                                                  Entropy (8bit):4.234997703698801
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8Hdd4CLxLtmCLoCLHCL3CLXLICLP1ptzLzCJCLt5LL53h5Lq+p5LcL3pLzCt:4655ftB9hMcGlhO8/n/0ecOfC3
                                                                                                                                                                                                                                  MD5:FFD5D8007D78770EA0E7E5643F1BD20A
                                                                                                                                                                                                                                  SHA1:40854EB81EE670086D0D0C0C2F0F9D8406DF6B47
                                                                                                                                                                                                                                  SHA-256:D27ADAF74EBB18D6964882CF931260331B93AE4B283427F9A0DB147A83DE1D55
                                                                                                                                                                                                                                  SHA-512:EFBDADE1157C7E1CB8458CBA89913FB44DC2399AD860FCAEDA588B99230B0934EDAAF8BAB1742E03F06FA8047D3605E8D63BB23EC4B32155C256D07C46ABBFEE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset he DAYS_OF_WEEK_ABBREV [list \. "\u05d0"\. "\u05d1"\. "\u05d2"\. "\u05d3"\. "\u05d4"\. "\u05d5"\. "\u05e9"]. ::msgcat::mcset he DAYS_OF_WEEK_FULL [list \. "\u05d9\u05d5\u05dd \u05e8\u05d0\u05e9\u05d5\u05df"\. "\u05d9\u05d5\u05dd \u05e9\u05e0\u05d9"\. "\u05d9\u05d5\u05dd \u05e9\u05dc\u05d9\u05e9\u05d9"\. "\u05d9\u05d5\u05dd \u05e8\u05d1\u05d9\u05e2\u05d9"\. "\u05d9\u05d5\u05dd \u05d7\u05de\u05d9\u05e9\u05d9"\. "\u05d9\u05d5\u05dd \u05e9\u05d9\u05e9\u05d9"\. "\u05e9\u05d1\u05ea"]. ::msgcat::mcset he MONTHS_ABBREV [list \. "\u05d9\u05e0\u05d5"\. "\u05e4\u05d1\u05e8"\. "\u05de\u05e8\u05e5"\. "\u05d0\u05e4\u05e8"\. "\u05de\u05d0\u05d9"\. "\u05d9\u05d5\u05e0"\. "\u05d9\u05d5\u05dc"\. "\u05d0\u05d5\u05d2"\. "\u05e1\u05e4\u05d8"\.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1738
                                                                                                                                                                                                                                  Entropy (8bit):4.1505681803025185
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8dVYe48VcOVcz1HtDVcqiVca4mGE18VcRBkEVcRfVcRMsVcqiVca4mGE18VI:465v4bNVO7GQbBkDuM4O7GQbBkDuh3x
                                                                                                                                                                                                                                  MD5:349823390798DF68270E4DB46C3CA863
                                                                                                                                                                                                                                  SHA1:814F9506FCD8B592C22A47023E73457C469B2F53
                                                                                                                                                                                                                                  SHA-256:FAFE65DB09BDCB863742FDA8705BCD1C31B59E0DD8A3B347EA6DEC2596CEE0E9
                                                                                                                                                                                                                                  SHA-512:4D12213EA9A3EAD6828E21D3B5B73931DC922EBE8FD2373E3A3E106DF1784E0BCE2C9D1FBEAE0D433449BE6D28A0F2F50F49AB8C208E69D413C6787ADF52915E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset hi DAYS_OF_WEEK_FULL [list \. "\u0930\u0935\u093f\u0935\u093e\u0930"\. "\u0938\u094b\u092e\u0935\u093e\u0930"\. "\u092e\u0902\u0917\u0932\u0935\u093e\u0930"\. "\u092c\u0941\u0927\u0935\u093e\u0930"\. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\. "\u0936\u0928\u093f\u0935\u093e\u0930"]. ::msgcat::mcset hi MONTHS_ABBREV [list \. "\u091c\u0928\u0935\u0930\u0940"\. "\u092b\u093c\u0930\u0935\u0930\u0940"\. "\u092e\u093e\u0930\u094d\u091a"\. "\u0905\u092a\u094d\u0930\u0947\u0932"\. "\u092e\u0908"\. "\u091c\u0942\u0928"\. "\u091c\u0941\u0932\u093e\u0908"\. "\u0905\u0917\u0938\u094d\u0924"\. "\u0938\u093f\u0924\u092e\u094d\u092c\u0930"\. "\u0905\u0915\u094d\u091f\u0942\u092c\u0930"\. "\u0928\u0935\u092e\u094d\u092c\u093
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.882853646266983
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmocv+9/Loz3v6rZoco+3v+6f6HK:4EnLzu8+vWq3v6rpF3vmq
                                                                                                                                                                                                                                  MD5:BC86C58492BCB8828489B871D2A727F0
                                                                                                                                                                                                                                  SHA1:22EEC74FC011063071A40C3860AE8EF38D898582
                                                                                                                                                                                                                                  SHA-256:29C7CA358FFFCAF94753C7CC2F63B58386234B75552FA3272C2E36F253770C3F
                                                                                                                                                                                                                                  SHA-512:ABFE093952144A285F7A86800F5933F7242CB224D917B4BAA4FD2CA48792BEFCBEE9AB7073472510B53D31083719EC68A77DD896410B3DC3C6E2CCD60C2E92F9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset hi_IN DATE_FORMAT "%d %M %Y". ::msgcat::mcset hi_IN TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset hi_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1121
                                                                                                                                                                                                                                  Entropy (8bit):4.291836444825864
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu84VBVgqoLpYDThoLZDT25KNWg1gqNvEKvOAl:46nNYPSLZP2ZVqJTO+
                                                                                                                                                                                                                                  MD5:46FD3DF765F366C60B91FA0C4DE147DE
                                                                                                                                                                                                                                  SHA1:5E006D1ACA7BBDAC9B8A65EFB26FAFC03C6E9FDE
                                                                                                                                                                                                                                  SHA-256:9E14D8F7F54BE953983F198C8D59F38842C5F73419A5E81BE6460B3623E7307A
                                                                                                                                                                                                                                  SHA-512:3AC26C55FB514D9EA46EF57582A2E0B64822E90C889F4B83A62EE255744FEBE0A012079DD764E0F6C7338B3580421C5B6C8575E0B85632015E3689CF58D9EB77
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset hr DAYS_OF_WEEK_ABBREV [list \. "ned"\. "pon"\. "uto"\. "sri"\. "\u010det"\. "pet"\. "sub"]. ::msgcat::mcset hr DAYS_OF_WEEK_FULL [list \. "nedjelja"\. "ponedjeljak"\. "utorak"\. "srijeda"\. "\u010detvrtak"\. "petak"\. "subota"]. ::msgcat::mcset hr MONTHS_ABBREV [list \. "sij"\. "vel"\. "o\u017eu"\. "tra"\. "svi"\. "lip"\. "srp"\. "kol"\. "ruj"\. "lis"\. "stu"\. "pro"\. ""]. ::msgcat::mcset hr MONTHS_FULL [list \. "sije\u010danj"\. "velja\u010da"\. "o\u017eujak"\. "travanj"\. "svibanj"\. "lipanj"\. "srpanj"\. "kolovoz"\. "rujan"\. "listopad"\. "studeni"\. "prosinac"\. ""]. ::msgcat::mcset hr DATE_FORMAT "
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1327
                                                                                                                                                                                                                                  Entropy (8bit):4.447184847972284
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8Xjv5ZemNruwcVNtZHTE9wocxPvt9vq:46fBZemNqwIZHTEE3t5q
                                                                                                                                                                                                                                  MD5:0561E62941F6ED8965DFC4E2B424E028
                                                                                                                                                                                                                                  SHA1:C622B21C0DBA83F943FBD10C746E5FABE20235B2
                                                                                                                                                                                                                                  SHA-256:314F4180C05DE4A4860F65AF6460900FFF77F12C08EDD728F68CA0065126B9AE
                                                                                                                                                                                                                                  SHA-512:CAD01C963145463612BBAE4B9F5C80B83B228C0181C2500CE8CE1394E1A32CCA3587221F1406F6343029059F5AD47E8FD5514535DCEA45BBA6B2AE76993DFFBD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset hu DAYS_OF_WEEK_ABBREV [list \. "V"\. "H"\. "K"\. "Sze"\. "Cs"\. "P"\. "Szo"]. ::msgcat::mcset hu DAYS_OF_WEEK_FULL [list \. "vas\u00e1rnap"\. "h\u00e9tf\u0151"\. "kedd"\. "szerda"\. "cs\u00fct\u00f6rt\u00f6k"\. "p\u00e9ntek"\. "szombat"]. ::msgcat::mcset hu MONTHS_ABBREV [list \. "jan."\. "febr."\. "m\u00e1rc."\. "\u00e1pr."\. "m\u00e1j."\. "j\u00fan."\. "j\u00fal."\. "aug."\. "szept."\. "okt."\. "nov."\. "dec."\. ""]. ::msgcat::mcset hu MONTHS_FULL [list \. "janu\u00e1r"\. "febru\u00e1r"\. "m\u00e1rcius"\. "\u00e1prilis"\. "m\u00e1jus"\. "j\u00fanius"\. "j\u00falius"\. "augusztus"\. "szeptember"\. "okt\u00f3ber"\. "nove
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):914
                                                                                                                                                                                                                                  Entropy (8bit):3.9322448438499125
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8acGEXctI9tdb/7579g6tdhUgQbVg:46GBEXKI9tdHtdwg
                                                                                                                                                                                                                                  MD5:CE834C7E0C3170B733122FF8BF38C28D
                                                                                                                                                                                                                                  SHA1:693ACC2A0972156B984106AFD07911AF14C4F19C
                                                                                                                                                                                                                                  SHA-256:1F1B0F5DEDE0263BD81773A78E98AF551F36361ACCB315B618C8AE70A5FE781E
                                                                                                                                                                                                                                  SHA-512:23BFC6E2CDB7BA75AAC3AA75869DF4A235E4526E8E83D73551B3BC2CE89F3675EBFA75BC94177F2C2BD6AC58C1B125BE65F8489BC4F85FA701415DB9768F7A80
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset id DAYS_OF_WEEK_ABBREV [list \. "Min"\. "Sen"\. "Sel"\. "Rab"\. "Kam"\. "Jum"\. "Sab"]. ::msgcat::mcset id DAYS_OF_WEEK_FULL [list \. "Minggu"\. "Senin"\. "Selasa"\. "Rabu"\. "Kamis"\. "Jumat"\. "Sabtu"]. ::msgcat::mcset id MONTHS_ABBREV [list \. "Jan"\. "Peb"\. "Mar"\. "Apr"\. "Mei"\. "Jun"\. "Jul"\. "Agu"\. "Sep"\. "Okt"\. "Nov"\. "Des"\. ""]. ::msgcat::mcset id MONTHS_FULL [list \. "Januari"\. "Pebruari"\. "Maret"\. "April"\. "Mei"\. "Juni"\. "Juli"\. "Agustus"\. "September"\. "Oktober"\. "November"\. "Desember"\. ""].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.857986813915644
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo0kGvNLo0F/W3v6aZo0kT+3vR6HK:4EnLzu8NGvNS3v6aQK3voq
                                                                                                                                                                                                                                  MD5:A285817AAABD5203706D5F2A34158C03
                                                                                                                                                                                                                                  SHA1:18FD0178051581C9F019604499BF91B16712CC91
                                                                                                                                                                                                                                  SHA-256:DB81643BA1FD115E9D547943A889A56DFC0C81B63F21B1EDC1955C6884C1B2F5
                                                                                                                                                                                                                                  SHA-512:0B6C684F2E5122681309A6212980C95C14172723F12D4864AF8A8A913DC7081BC42AC39CF087D29770B4A1F0B3B1F712856CBF05D1975FFFC008C16A91081A00
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset id_ID DATE_FORMAT "%d %B %Y". ::msgcat::mcset id_ID TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset id_ID DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1255
                                                                                                                                                                                                                                  Entropy (8bit):4.391152464169964
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8qVXVDWpXMVmDz1ZVcWVzbQ1/xZ9b3eYXvhv3eT3:462hVW5JDz1ZVUbpfV83
                                                                                                                                                                                                                                  MD5:6695839F1C4D2A92552CB1647FD14DA5
                                                                                                                                                                                                                                  SHA1:04CB1976846A78EA9593CB3706C9D61173CE030C
                                                                                                                                                                                                                                  SHA-256:6767115FFF2DA05F49A28BAD78853FAC6FC716186B985474D6D30764E1727C40
                                                                                                                                                                                                                                  SHA-512:208766038A6A1D748F4CB2660F059AD355A5439EA6D8326F4F410B2DFBBDEECB55D4CE230C01C519B08CAB1CF5E5B3AC61E7BA86020A7BDA1AFEA624F3828521
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset is DAYS_OF_WEEK_ABBREV [list \. "sun."\. "m\u00e1n."\. "\u00feri."\. "mi\u00f0."\. "fim."\. "f\u00f6s."\. "lau."]. ::msgcat::mcset is DAYS_OF_WEEK_FULL [list \. "sunnudagur"\. "m\u00e1nudagur"\. "\u00feri\u00f0judagur"\. "mi\u00f0vikudagur"\. "fimmtudagur"\. "f\u00f6studagur"\. "laugardagur"]. ::msgcat::mcset is MONTHS_ABBREV [list \. "jan."\. "feb."\. "mar."\. "apr."\. "ma\u00ed"\. "j\u00fan."\. "j\u00fal."\. "\u00e1g\u00fa."\. "sep."\. "okt."\. "n\u00f3v."\. "des."\. ""]. ::msgcat::mcset is MONTHS_FULL [list \. "jan\u00faar"\. "febr\u00faar"\. "mars"\. "apr\u00edl"\. "ma\u00ed"\. "j\u00fan\u00ed"\. "j\u00fal\u00ed"\. "\u00e1g\u00fast"\.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1240
                                                                                                                                                                                                                                  Entropy (8bit):4.207511774275323
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8iYJcc8jYShjLhQ6I3S68gvNvlNUhsFNlVGvNmv5svc:46Wi38jBJLhQ6I3EgFtNo4NlVGlw5Kc
                                                                                                                                                                                                                                  MD5:8E205D032206D794A681E2A994532FA6
                                                                                                                                                                                                                                  SHA1:47098672D339624474E8854EB0512D54A0CA49E7
                                                                                                                                                                                                                                  SHA-256:C7D84001855586A0BAB236A6A5878922D9C4A2EA1799BF18544869359750C0DF
                                                                                                                                                                                                                                  SHA-512:139219DBD014CCA15922C45C7A0468F62E864F18CC16C7B8506258D1ECD766E1EFF6EAE4DFDAF72898B9AF1A5E6CE8D7BB0F1A93A6604D2539F2645C9ED8D146
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset it DAYS_OF_WEEK_ABBREV [list \. "dom"\. "lun"\. "mar"\. "mer"\. "gio"\. "ven"\. "sab"]. ::msgcat::mcset it DAYS_OF_WEEK_FULL [list \. "domenica"\. "luned\u00ec"\. "marted\u00ec"\. "mercoled\u00ec"\. "gioved\u00ec"\. "venerd\u00ec"\. "sabato"]. ::msgcat::mcset it MONTHS_ABBREV [list \. "gen"\. "feb"\. "mar"\. "apr"\. "mag"\. "giu"\. "lug"\. "ago"\. "set"\. "ott"\. "nov"\. "dic"\. ""]. ::msgcat::mcset it MONTHS_FULL [list \. "gennaio"\. "febbraio"\. "marzo"\. "aprile"\. "maggio"\. "giugno"\. "luglio"\. "agosto"\. "settembre"\. "ottobre"\. "novembre"\. "dicembre"\. ""]. ::msgcat::mcset it BCE "aC". ::msgc
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):244
                                                                                                                                                                                                                                  Entropy (8bit):4.851375233848049
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoi5jLWNLoyJ+3vULoia+3vjLtA6:4EnLzu8m3WNJ+3v23v3t3
                                                                                                                                                                                                                                  MD5:8666E24230AED4DC76DB93BE1EA07FF6
                                                                                                                                                                                                                                  SHA1:7C688C8693C76AEE07FB32637CD58E47A85760F3
                                                                                                                                                                                                                                  SHA-256:2EE356FFA2491A5A60BDF7D7FEBFAC426824904738615A0C1D07AEF6BDA3B76F
                                                                                                                                                                                                                                  SHA-512:BCCE87FB94B28B369B9EE48D792A399DB8250D0D3D73FC05D053276A7475229EF1555D5E516D780092496F0E5F229A9912A45FB5A88C024FCEBF08E654D37B07
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset it_CH DATE_FORMAT "%e. %B %Y". ::msgcat::mcset it_CH TIME_FORMAT "%H:%M:%S". ::msgcat::mcset it_CH DATE_TIME_FORMAT "%e. %B %Y %H:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1664
                                                                                                                                                                                                                                  Entropy (8bit):4.88149888596689
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8VcQHxbtVLKMwvtFwvQv4fTweLvDvTwS0Zu+jqgv:46RbItt4mCEebzES0njqq
                                                                                                                                                                                                                                  MD5:430DEB41034402906156D7E23971CD2C
                                                                                                                                                                                                                                  SHA1:0952FFBD241B5111714275F5CD8FB5545067FFEC
                                                                                                                                                                                                                                  SHA-256:38DCA9B656241884923C451A369B90A9F1D76F9029B2E98E04784323169C3251
                                                                                                                                                                                                                                  SHA-512:AE5DF1B79AE34DF4CC1EB00406FFF49541A95E2C732E3041CCE321F2F3FA6461BB45C6524A5FEB77E18577206CBD88A83FBF20B4B058BAE9B889179C93221557
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ja DAYS_OF_WEEK_ABBREV [list \. "\u65e5"\. "\u6708"\. "\u706b"\. "\u6c34"\. "\u6728"\. "\u91d1"\. "\u571f"]. ::msgcat::mcset ja DAYS_OF_WEEK_FULL [list \. "\u65e5\u66dc\u65e5"\. "\u6708\u66dc\u65e5"\. "\u706b\u66dc\u65e5"\. "\u6c34\u66dc\u65e5"\. "\u6728\u66dc\u65e5"\. "\u91d1\u66dc\u65e5"\. "\u571f\u66dc\u65e5"]. ::msgcat::mcset ja MONTHS_FULL [list \. "1\u6708"\. "2\u6708"\. "3\u6708"\. "4\u6708"\. "5\u6708"\. "6\u6708"\. "7\u6708"\. "8\u6708"\. "9\u6708"\. "10\u6708"\. "11\u6708"\. "12\u6708"]. ::msgcat::mcset ja BCE "\u7d00\u5143\u524d". ::msgcat::mcset ja CE "\u897f\u66a6". ::msgcat::mcset ja AM "\u5348\u524d". ::msgcat::mcset ja PM "\u5348\u5f8c". ::msgcat::mcset ja DATE_FORMAT "%Y/%m/%
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):978
                                                                                                                                                                                                                                  Entropy (8bit):4.013253613061898
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu83jGeo9sbjCjS3jCwjLj+zSsS9CfzTA2Qcl:46OOsJzTvl
                                                                                                                                                                                                                                  MD5:AE55E001BBE3272CE13369C836139EF3
                                                                                                                                                                                                                                  SHA1:D912A0AEBA08BC97D80E9B7A55CE146956C90BCC
                                                                                                                                                                                                                                  SHA-256:1B00229DF5A979A040339BBC72D448F39968FEE5CC24F07241C9F6129A9B53DD
                                                                                                                                                                                                                                  SHA-512:E53E8DB56AD367E832A121D637CA4755E6C8768C063E4BE43E6193C5F71ED7AA10F7223AC85750C0CAD543CF4A0BFE578CBA2877F176A5E58DCA2BAA2F7177FB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset kl DAYS_OF_WEEK_ABBREV [list \. "sab"\. "ata"\. "mar"\. "pin"\. "sis"\. "tal"\. "arf"]. ::msgcat::mcset kl DAYS_OF_WEEK_FULL [list \. "sabaat"\. "ataasinngorneq"\. "marlunngorneq"\. "pingasunngorneq"\. "sisamanngorneq"\. "tallimanngorneq"\. "arfininngorneq"]. ::msgcat::mcset kl MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "maj"\. "jun"\. "jul"\. "aug"\. "sep"\. "okt"\. "nov"\. "dec"\. ""]. ::msgcat::mcset kl MONTHS_FULL [list \. "januari"\. "februari"\. "martsi"\. "aprili"\. "maji"\. "juni"\. "juli"\. "augustusi"\. "septemberi"\. "oktoberi"\. "novemberi"\. "decemberi"\. ""].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.83493357349932
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoEpb53FD/LoEpLE3vG5oEpLE3v6X5oEpba+3vnFDoAov:4EnLzu8KF3FD/1w3vMw3v6T/3v9dy
                                                                                                                                                                                                                                  MD5:4B8E5B6EB7C27A02DBC0C766479B068D
                                                                                                                                                                                                                                  SHA1:E97A948FFE6C8DE99F91987155DF0A81A630950E
                                                                                                                                                                                                                                  SHA-256:F99DA45138A8AEBFD92747FC28992F0C315C6C4AD97710EAF9427263BFFA139C
                                                                                                                                                                                                                                  SHA-512:D726494A6F4E1FB8C71B8B56E9B735C1837D8D22828D006EF386E41AD15CD1E4CF14DAC01966B9AFE41F7B6A44916EFC730CF038B4EC393043AE9021D11DACF2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset kl_GL DATE_FORMAT "%d %b %Y". ::msgcat::mcset kl_GL TIME_FORMAT "%T". ::msgcat::mcset kl_GL TIME_FORMAT_12 "%T". ::msgcat::mcset kl_GL DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1566
                                                                                                                                                                                                                                  Entropy (8bit):4.552910804130986
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8cVBfHVnYgY+YGkYeY02Y7YkMXjDHMXjqKKyvtuvFd8vUPvwEq:46ojlmpYEY7XjDsXj+0t4zaU3wt
                                                                                                                                                                                                                                  MD5:A4C37AF81FC4AA6003226A95539546C1
                                                                                                                                                                                                                                  SHA1:A18A7361783896C691BD5BE8B3A1FCCCCB015F43
                                                                                                                                                                                                                                  SHA-256:F6E2B0D116D2C9AC90DDA430B6892371D87A4ECFB6955318978ED6F6E9D546A6
                                                                                                                                                                                                                                  SHA-512:FBE6BA258C250BD90FADCC42AC18A17CC4E7B040F160B94075AF1F42ECD43EEA6FE49DA52CF9B5BBB5D965D6AB7C4CC4053A78E865241F891E13F94EB20F0472
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ko DAYS_OF_WEEK_ABBREV [list \. "\uc77c"\. "\uc6d4"\. "\ud654"\. "\uc218"\. "\ubaa9"\. "\uae08"\. "\ud1a0"]. ::msgcat::mcset ko DAYS_OF_WEEK_FULL [list \. "\uc77c\uc694\uc77c"\. "\uc6d4\uc694\uc77c"\. "\ud654\uc694\uc77c"\. "\uc218\uc694\uc77c"\. "\ubaa9\uc694\uc77c"\. "\uae08\uc694\uc77c"\. "\ud1a0\uc694\uc77c"]. ::msgcat::mcset ko MONTHS_ABBREV [list \. "1\uc6d4"\. "2\uc6d4"\. "3\uc6d4"\. "4\uc6d4"\. "5\uc6d4"\. "6\uc6d4"\. "7\uc6d4"\. "8\uc6d4"\. "9\uc6d4"\. "10\uc6d4"\. "11\uc6d4"\. "12\uc6d4"\. ""]. ::msgcat::mcset ko MONTHS_FULL [list \. "1\uc6d4"\. "2\uc6d4"\. "3\uc6d4"\. "4\uc6d4"\. "5\uc6d4"\. "6\uc6d4"\. "7\uc6d4"\. "8\uc6d4"\.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):346
                                                                                                                                                                                                                                  Entropy (8bit):5.015790750376121
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo56SFZhjNo56m5Ybo56TGMZo56a/W3v6mfvLo56TT+3vOAEP:4EnLzu8r62vjs6m5YS6TGN6a+3v6o66J
                                                                                                                                                                                                                                  MD5:9C7E97A55A957AB1D1B5E988AA514724
                                                                                                                                                                                                                                  SHA1:592F8FF9FABBC7BF48539AF748DCFC9241AED82D
                                                                                                                                                                                                                                  SHA-256:31A4B74F51C584354907251C55FE5CE894D2C9618156A1DC6F5A979BC350DB17
                                                                                                                                                                                                                                  SHA-512:9D04DF2A87AFE24C339E1A0F6358FE995CBCAF8C7B08A1A7953675E2C2C1EDBCAF297B23C2B9BEC398DFEE6D1D75CE32E31389A7199466A38BC83C8DBBA67C77
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ko_KR BCE "\uae30\uc6d0\uc804". ::msgcat::mcset ko_KR CE "\uc11c\uae30". ::msgcat::mcset ko_KR DATE_FORMAT "%Y.%m.%d". ::msgcat::mcset ko_KR TIME_FORMAT_12 "%P %l:%M:%S". ::msgcat::mcset ko_KR DATE_TIME_FORMAT "%Y.%m.%d %P %l:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1958
                                                                                                                                                                                                                                  Entropy (8bit):4.1451019501109965
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8Z448VcOVczWdSVcqVcR0q4vTqBBiXCVcqVcR0q4vTqBBiaMv:46u48h0qpBBaR0qpBBVu
                                                                                                                                                                                                                                  MD5:E7938CB3AF53D42B4142CB104AB04B3B
                                                                                                                                                                                                                                  SHA1:6205BD2336857F368CABF89647F54D94E093A77B
                                                                                                                                                                                                                                  SHA-256:D236D5B27184B1E813E686D901418117F22D67024E6944018FC4B633DF9FF744
                                                                                                                                                                                                                                  SHA-512:CE77CE2EC773F3A1A3CD68589C26F7089E8133ADE601CE899EEB0B13648051344A94E69AEC2C8C58349456E52B11EB7545C8926E3F08DB643EE551C641FF38DB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset kok DAYS_OF_WEEK_FULL [list \. "\u0906\u0926\u093f\u0924\u094d\u092f\u0935\u093e\u0930"\. "\u0938\u094b\u092e\u0935\u093e\u0930"\. "\u092e\u0902\u0917\u0933\u093e\u0930"\. "\u092c\u0941\u0927\u0935\u093e\u0930"\. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\. "\u0936\u0928\u093f\u0935\u093e\u0930"]. ::msgcat::mcset kok MONTHS_ABBREV [list \. "\u091c\u093e\u0928\u0947\u0935\u093e\u0930\u0940"\. "\u092b\u0947\u092c\u0943\u0935\u093e\u0930\u0940"\. "\u092e\u093e\u0930\u094d\u091a"\. "\u090f\u092a\u094d\u0930\u093f\u0932"\. "\u092e\u0947"\. "\u091c\u0942\u0928"\. "\u091c\u0941\u0932\u0948"\. "\u0913\u0917\u0938\u094d\u091f"\. "\u0938\u0947\u092a\u094d\u091f\u0947\u0902\u092c\u0930"\. "\u0913\u0915\u094d\u091f\u094b\u092c\u0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):254
                                                                                                                                                                                                                                  Entropy (8bit):4.8580653411441155
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo5VsNv+9/Lo5VsU3v6rZo5VsNo+3v+6f6HK:4EnLzu8rVsNvWiVsU3v6rAVsNF3vmq
                                                                                                                                                                                                                                  MD5:A3B27D44ED430AEC7DF2A47C19659CC4
                                                                                                                                                                                                                                  SHA1:700E4B9C395B540BFCE9ABDC81E6B9B758893DC9
                                                                                                                                                                                                                                  SHA-256:BEE07F14C7F4FC93B62AC318F89D2ED0DD6FF30D2BF21C2874654FF0292A6C4B
                                                                                                                                                                                                                                  SHA-512:79E9D8B817BDB6594A7C95991B2F6D7571D1C2976E74520D28223CF9F05EAA2128A44BC83A94089F09011FFCA9DB5E2D4DD74B59DE2BADC022E1571C595FE36C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset kok_IN DATE_FORMAT "%d %M %Y". ::msgcat::mcset kok_IN TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset kok_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):966
                                                                                                                                                                                                                                  Entropy (8bit):3.9734955453120504
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu8z4md0eKwCW44mtls79cp32AqghoPx9ab43gWgw3SeWOdSyECYf5AQZ0eD:4azu806vCmgs7aB2seFkhq+9
                                                                                                                                                                                                                                  MD5:413A264B40EEBEB28605481A3405D27D
                                                                                                                                                                                                                                  SHA1:9C2EFA6326C62962DCD83BA8D16D89616D2C5B77
                                                                                                                                                                                                                                  SHA-256:F49F4E1C7142BF7A82FC2B9FC075171AE45903FE69131478C15219D72BBAAD33
                                                                                                                                                                                                                                  SHA-512:CF0559DB130B8070FEC93A64F5317A2C9CDE7D5EAFD1E92E76EAAE0740C6429B7AB7A60BD833CCA4ABCC0AADEBC6A68F854FF654E0707091023D275404172427
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset kw DAYS_OF_WEEK_ABBREV [list \. "Sul"\. "Lun"\. "Mth"\. "Mhr"\. "Yow"\. "Gwe"\. "Sad"]. ::msgcat::mcset kw DAYS_OF_WEEK_FULL [list \. "De Sul"\. "De Lun"\. "De Merth"\. "De Merher"\. "De Yow"\. "De Gwener"\. "De Sadorn"]. ::msgcat::mcset kw MONTHS_ABBREV [list \. "Gen"\. "Whe"\. "Mer"\. "Ebr"\. "Me"\. "Evn"\. "Gor"\. "Est"\. "Gwn"\. "Hed"\. "Du"\. "Kev"\. ""]. ::msgcat::mcset kw MONTHS_FULL [list \. "Mys Genver"\. "Mys Whevrel"\. "Mys Merth"\. "Mys Ebrel"\. "Mys Me"\. "Mys Evan"\. "Mys Gortheren"\. "Mye Est"\. "Mys Gwyngala"\. "Mys Hedra"\. "Mys Du"\. "Mys Kevardhu"\. ""].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.914818138642697
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoh6AvvNLoh633v6aZoh6Ao+3vR6HK:4EnLzu8z6AvvN6633v6aY6AF3voq
                                                                                                                                                                                                                                  MD5:D325ADCF1F81F40D7B5D9754AE0542F3
                                                                                                                                                                                                                                  SHA1:7A6BCD6BE5F41F84B600DF355CB00ECB9B4AE8C0
                                                                                                                                                                                                                                  SHA-256:7A8A539C8B990AEFFEA06188B98DC437FD2A6E89FF66483EF334994E73FD0EC9
                                                                                                                                                                                                                                  SHA-512:A05BBB3F80784B9C8BBA3FE618FEE154EE40D240ED4CFF7CD6EEE3D97BC4F065EFF585583123F1FFD8ABA1A194EB353229E15ED5CD43759D4D356EC5BE8DCD73
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset kw_GB DATE_FORMAT "%d %B %Y". ::msgcat::mcset kw_GB TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset kw_GB DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1255
                                                                                                                                                                                                                                  Entropy (8bit):4.4416408590245
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8FHYI4/+HYZoNPW43VvJZb3lSuRnixx/x5JfbiMQeTVYkG2CvRksvQ:46hHNHhu43VxZb3lSuRwxZ5VbiMQeTVL
                                                                                                                                                                                                                                  MD5:73F0A9C360A90CB75C6DA7EF87EF512F
                                                                                                                                                                                                                                  SHA1:582EB224C9715C8336B4D1FCE7DDEC0D89F5AD71
                                                                                                                                                                                                                                  SHA-256:510D8EED3040B50AFAF6A3C85BC98847F1B4D5D8A685C5EC06ACC2491B890101
                                                                                                                                                                                                                                  SHA-512:B5482C7448BFC44B05FCF7EB0642B0C7393F4438082A507A94C13F56F12A115A5CE7F0744518BB0B2FAF759D1AD7744B0BEDB98F563C2A4AB11BC4619D7CEA22
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset lt DAYS_OF_WEEK_ABBREV [list \. "Sk"\. "Pr"\. "An"\. "Tr"\. "Kt"\. "Pn"\. "\u0160t"]. ::msgcat::mcset lt DAYS_OF_WEEK_FULL [list \. "Sekmadienis"\. "Pirmadienis"\. "Antradienis"\. "Tre\u010diadienis"\. "Ketvirtadienis"\. "Penktadienis"\. "\u0160e\u0161tadienis"]. ::msgcat::mcset lt MONTHS_ABBREV [list \. "Sau"\. "Vas"\. "Kov"\. "Bal"\. "Geg"\. "Bir"\. "Lie"\. "Rgp"\. "Rgs"\. "Spa"\. "Lap"\. "Grd"\. ""]. ::msgcat::mcset lt MONTHS_FULL [list \. "Sausio"\. "Vasario"\. "Kovo"\. "Baland\u017eio"\. "Gegu\u017e\u0117s"\. "Bir\u017eelio"\. "Liepos"\. "Rugpj\u016b\u010dio"\. "Rugs\u0117jo"\. "Spalio"\. "Lapkri\u010dio"\. "G
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1219
                                                                                                                                                                                                                                  Entropy (8bit):4.39393801727056
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8lmZG0me3AEcGo49bJcpF9gT9PCbF5uld0vVcASAr8svJ5vk3:46TGAE8Q/PG5dv//Lk3
                                                                                                                                                                                                                                  MD5:D5DEB8EFFE6298858F9D1B9FAD0EA525
                                                                                                                                                                                                                                  SHA1:973DF40D0464BCE10EB5991806D9990B65AB0F82
                                                                                                                                                                                                                                  SHA-256:FD95B38A3BEBD59468BDC2890BAC59DF31C352E17F2E77C82471E1CA89469802
                                                                                                                                                                                                                                  SHA-512:F024E3D6D30E8E5C3316364A905C8CCAC87427BFC2EC10E72065F1DD114A112A61FDECDF1C4EC9C3D8BB9A54D18ED4AE9D57B07DA4AFFE480DE12F3D54BED928
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset lv DAYS_OF_WEEK_ABBREV [list \. "Sv"\. "P"\. "O"\. "T"\. "C"\. "Pk"\. "S"]. ::msgcat::mcset lv DAYS_OF_WEEK_FULL [list \. "sv\u0113tdiena"\. "pirmdiena"\. "otrdiena"\. "tre\u0161diena"\. "ceturdien"\. "piektdiena"\. "sestdiena"]. ::msgcat::mcset lv MONTHS_ABBREV [list \. "Jan"\. "Feb"\. "Mar"\. "Apr"\. "Maijs"\. "J\u016bn"\. "J\u016bl"\. "Aug"\. "Sep"\. "Okt"\. "Nov"\. "Dec"\. ""]. ::msgcat::mcset lv MONTHS_FULL [list \. "janv\u0101ris"\. "febru\u0101ris"\. "marts"\. "apr\u012blis"\. "maijs"\. "j\u016bnijs"\. "j\u016blijs"\. "augusts"\. "septembris"\. "oktobris"\. "novembris"\. "decembris"\. ""]. ::msgcat
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2105
                                                                                                                                                                                                                                  Entropy (8bit):4.237536682442766
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46UcQdZnlcQfAQPWQEHKr9nGUeDjDpxpWQ1Q3QuQoQLX9TSQ2QIQPQHp7+8i:hNdR7cr9nMvXI0i7F89TSn1KX
                                                                                                                                                                                                                                  MD5:CD589758D4F4B522781A10003D3E1791
                                                                                                                                                                                                                                  SHA1:D953DD123D54B02BAF4B1AE0D36081CDFCA38444
                                                                                                                                                                                                                                  SHA-256:F384DD88523147CEF42AA871D323FC4CBEE338FF67CC5C95AEC7940C0E531AE3
                                                                                                                                                                                                                                  SHA-512:2EA1E71CD1E958F83277006343E85513D112CBB3C22CBFF29910CB1FC37F2389B3F1DCB2533EC59F9E642624869E5C61F289FDC010B55C6EECEF378F2D92DB0B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset mk DAYS_OF_WEEK_ABBREV [list \. "\u043d\u0435\u0434."\. "\u043f\u043e\u043d."\. "\u0432\u0442."\. "\u0441\u0440\u0435."\. "\u0447\u0435\u0442."\. "\u043f\u0435\u0442."\. "\u0441\u0430\u0431."]. ::msgcat::mcset mk DAYS_OF_WEEK_FULL [list \. "\u043d\u0435\u0434\u0435\u043b\u0430"\. "\u043f\u043e\u043d\u0435\u0434\u0435\u043b\u043d\u0438\u043a"\. "\u0432\u0442\u043e\u0440\u043d\u0438\u043a"\. "\u0441\u0440\u0435\u0434\u0430"\. "\u0447\u0435\u0442\u0432\u0440\u0442\u043e\u043a"\. "\u043f\u0435\u0442\u043e\u043a"\. "\u0441\u0430\u0431\u043e\u0442\u0430"]. ::msgcat::mcset mk MONTHS_ABBREV [list \. "\u0458\u0430\u043d."\. "\u0444\u0435\u0432."\. "\u043c\u0430\u0440."\. "\u0430\u043f\u0440."\. "\u043c\u0430\u0458."\. "\u0458\u0443\u043d."\. "\u0458\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1807
                                                                                                                                                                                                                                  Entropy (8bit):4.160320823510059
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8ocYe48VcOVczyVczoRSVcqVcR0q4vTqBBiPNVcqVcR0q4vTqBBil:46R48h0qpBBkI0qpBBe
                                                                                                                                                                                                                                  MD5:791408BAE710B77A27AD664EC3325E1C
                                                                                                                                                                                                                                  SHA1:E760B143A854838E18FFB66500F4D312DD80634E
                                                                                                                                                                                                                                  SHA-256:EB2E2B7A41854AF68CEF5881CF1FBF4D38E70D2FAB2C3F3CE5901AA5CC56FC15
                                                                                                                                                                                                                                  SHA-512:FE91EF67AB9313909FE0C29D5FBE2298EE35969A26A63D94A406BFDA7BCF932F2211F94C0E3C1D718DBC2D1145283C768C23487EEB253249ACFE76E8D1F1D1E5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset mr DAYS_OF_WEEK_FULL [list \. "\u0930\u0935\u093f\u0935\u093e\u0930"\. "\u0938\u094b\u092e\u0935\u093e\u0930"\. "\u092e\u0902\u0917\u0933\u0935\u093e\u0930"\. "\u092e\u0902\u0917\u0933\u0935\u093e\u0930"\. "\u0917\u0941\u0930\u0941\u0935\u093e\u0930"\. "\u0936\u0941\u0915\u094d\u0930\u0935\u093e\u0930"\. "\u0936\u0928\u093f\u0935\u093e\u0930"]. ::msgcat::mcset mr MONTHS_ABBREV [list \. "\u091c\u093e\u0928\u0947\u0935\u093e\u0930\u0940"\. "\u092b\u0947\u092c\u0943\u0935\u093e\u0930\u0940"\. "\u092e\u093e\u0930\u094d\u091a"\. "\u090f\u092a\u094d\u0930\u093f\u0932"\. "\u092e\u0947"\. "\u091c\u0942\u0928"\. "\u091c\u0941\u0932\u0948"\. "\u0913\u0917\u0938\u094d\u091f"\. "\u0938\u0947\u092a\u094d\u091f\u0947\u0902\u092c\u0930"\. "\u0913\u0915\u094d\u091f\u094b\u092c\u0930"\.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.847742455062573
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoGNv+9/LoGU3v6rZoGNo+3v+6f6HK:4EnLzu8GvWe3v6r5F3vmq
                                                                                                                                                                                                                                  MD5:899E845D33CAAFB6AD3B1F24B3F92843
                                                                                                                                                                                                                                  SHA1:FC17A6742BF87E81BBD4D5CB7B4DCED0D4DD657B
                                                                                                                                                                                                                                  SHA-256:F75A29BB323DB4354B0C759CB1C8C5A4FFC376DFFD74274CA60A36994816A75C
                                                                                                                                                                                                                                  SHA-512:99D05FCE8A9C9BE06FDA8B54D4DE5497141F6373F470B2AB24C2D00B9C56031350F5DCDA2283A0E6F5B09FF21218FC3C7E2A6AB8ECC5BB020546FD62BDC8FF99
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset mr_IN DATE_FORMAT "%d %M %Y". ::msgcat::mcset mr_IN TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset mr_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):910
                                                                                                                                                                                                                                  Entropy (8bit):3.9292866027924838
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu82mCBuvFYcEfmt1qWjefjESRsToOqrlHvFguSixTRs1OAfC67:4azu82nBuHEfKxjeby7cl9gbZUAfCc
                                                                                                                                                                                                                                  MD5:441CC737D383D8213F64B62A5DBEEC3E
                                                                                                                                                                                                                                  SHA1:34FBE99FB25A0DCA2FDA2C008AC8127BA2BC273B
                                                                                                                                                                                                                                  SHA-256:831F611EE851A64BF1BA5F9A5441EC1D50722FA9F15B4227707FE1927F754DE4
                                                                                                                                                                                                                                  SHA-512:0474B2127890F63814CD9E77D156B5E4FC45EB3C17A57719B672AC9E3A6EEA9934F0BE158F76808B34A11DA844AB900652C18E512830278DFED2666CD005FBE5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ms DAYS_OF_WEEK_ABBREV [list \. "Aha"\. "Isn"\. "Sei"\. "Rab"\. "Kha"\. "Jum"\. "Sab"]. ::msgcat::mcset ms DAYS_OF_WEEK_FULL [list \. "Ahad"\. "Isnin"\. "Selasa"\. "Rahu"\. "Khamis"\. "Jumaat"\. "Sabtu"]. ::msgcat::mcset ms MONTHS_ABBREV [list \. "Jan"\. "Feb"\. "Mac"\. "Apr"\. "Mei"\. "Jun"\. "Jul"\. "Ogos"\. "Sep"\. "Okt"\. "Nov"\. "Dis"\. ""]. ::msgcat::mcset ms MONTHS_FULL [list \. "Januari"\. "Februari"\. "Mac"\. "April"\. "Mei"\. "Jun"\. "Julai"\. "Ogos"\. "September"\. "Oktober"\. "November"\. "Disember"\. ""].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):259
                                                                                                                                                                                                                                  Entropy (8bit):4.770028367699931
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoChFflD/LoChF+3v6xH5oCh++3vflm6PYv:4EnLzu8IPflD/ne3v6Tl3vflm6q
                                                                                                                                                                                                                                  MD5:8261689A45FB754158B10B044BDC4965
                                                                                                                                                                                                                                  SHA1:6FFC9B16A0600D9BC457322F1316BC175309C6CA
                                                                                                                                                                                                                                  SHA-256:D05948D75C06669ADDB9708BC5FB48E6B651D4E62EF1B327EF8A3F605FD5271C
                                                                                                                                                                                                                                  SHA-512:0321A5C17B3E33FDE9480AC6014B373D1663219D0069388920D277AA61341B8293883517C900030177FF82D65340E6C9E3ED051B27708DD093055E3BE64B2AF3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ms_MY DATE_FORMAT "%A %d %b %Y". ::msgcat::mcset ms_MY TIME_FORMAT_12 "%I:%M:%S %z". ::msgcat::mcset ms_MY DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):690
                                                                                                                                                                                                                                  Entropy (8bit):4.48913642143724
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu8+YmWjjRgWfjxBTo4erxy1IGZzNN+3v6amK3vZsq:4azu8+YZjjRXbfNedy1IG5N6vjmsvGq
                                                                                                                                                                                                                                  MD5:CE7E67A03ED8C3297C6A5B634B55D144
                                                                                                                                                                                                                                  SHA1:3DA5ACC0F52518541810E7F2FE57751955E12BDA
                                                                                                                                                                                                                                  SHA-256:D115718818E3E3367847CE35BB5FF0361D08993D9749D438C918F8EB87AD8814
                                                                                                                                                                                                                                  SHA-512:3754AA7B7D27A813C6113D2AA834A951FED1B81E4DACE22C81E0583F29BBC73C014697F39A2067DEC622D98EACD70D26FD40F80CF6D09E1C949F01FADED52C74
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset mt DAYS_OF_WEEK_ABBREV [list \. "\u0126ad"\. "Tne"\. "Tli"\. "Erb"\. "\u0126am"\. "\u0120im"]. ::msgcat::mcset mt MONTHS_ABBREV [list \. "Jan"\. "Fra"\. "Mar"\. "Apr"\. "Mej"\. "\u0120un"\. "Lul"\. "Awi"\. "Set"\. "Ott"\. "Nov"]. ::msgcat::mcset mt BCE "QK". ::msgcat::mcset mt CE "". ::msgcat::mcset mt DATE_FORMAT "%A, %e ta %B, %Y". ::msgcat::mcset mt TIME_FORMAT_12 "%l:%M:%S %P". ::msgcat::mcset mt DATE_TIME_FORMAT "%A, %e ta %B, %Y %l:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1157
                                                                                                                                                                                                                                  Entropy (8bit):4.24006506188001
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8CKEj4/xasSpfiTBtHQT1V/W3WNfvZv3l:46KU/0s2iTeVOiHN1
                                                                                                                                                                                                                                  MD5:D5509ABF5CBFB485C20A26FCC6B1783E
                                                                                                                                                                                                                                  SHA1:53A298FBBF09AE2E223B041786443A3D8688C9EB
                                                                                                                                                                                                                                  SHA-256:BC401889DD934C49D10D99B471441BE2B536B1722739C7B0AB7DE7629680F602
                                                                                                                                                                                                                                  SHA-512:BDAFBA46EF44151CFD9EF7BC1909210F6DB2BAC20C31ED21AE3BE7EAC785CD4F545C4590CF551C0D066F982E2050F5844BDDC569F32C5804DBDE657F4511A6FE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset nb DAYS_OF_WEEK_ABBREV [list \. "s\u00f8"\. "ma"\. "ti"\. "on"\. "to"\. "fr"\. "l\u00f8"]. ::msgcat::mcset nb DAYS_OF_WEEK_FULL [list \. "s\u00f8ndag"\. "mandag"\. "tirsdag"\. "onsdag"\. "torsdag"\. "fredag"\. "l\u00f8rdag"]. ::msgcat::mcset nb MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "mai"\. "jun"\. "jul"\. "aug"\. "sep"\. "okt"\. "nov"\. "des"\. ""]. ::msgcat::mcset nb MONTHS_FULL [list \. "januar"\. "februar"\. "mars"\. "april"\. "mai"\. "juni"\. "juli"\. "august"\. "september"\. "oktober"\. "november"\. "desember"\. ""]. ::msgcat::mcset nb BCE "f.Kr.". ::msgcat::mcset nb CE "e.Kr.".
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1079
                                                                                                                                                                                                                                  Entropy (8bit):4.158523842311663
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu84LFiS8LMKZoNfSZTNTQhFCNZvtWvg:46Oi5LMKZASZTEF2Ntgg
                                                                                                                                                                                                                                  MD5:98820DFF7E1C8A9EAB8C74B0B25DEB5D
                                                                                                                                                                                                                                  SHA1:5357063D5699188E544D244EC4AEFDDF7606B922
                                                                                                                                                                                                                                  SHA-256:49128B36B88E380188059C4B593C317382F32E29D1ADC18D58D14D142459A2BB
                                                                                                                                                                                                                                  SHA-512:26AB945B7BA00433BEC85ACC1D90D1D3B70CE505976CABE1D75A7134E00CD591AC27463987C515EEA079969DBCF200DA9C8538CAAF178A1EE17C9B0284260C45
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset nl DAYS_OF_WEEK_ABBREV [list \. "zo"\. "ma"\. "di"\. "wo"\. "do"\. "vr"\. "za"]. ::msgcat::mcset nl DAYS_OF_WEEK_FULL [list \. "zondag"\. "maandag"\. "dinsdag"\. "woensdag"\. "donderdag"\. "vrijdag"\. "zaterdag"]. ::msgcat::mcset nl MONTHS_ABBREV [list \. "jan"\. "feb"\. "mrt"\. "apr"\. "mei"\. "jun"\. "jul"\. "aug"\. "sep"\. "okt"\. "nov"\. "dec"\. ""]. ::msgcat::mcset nl MONTHS_FULL [list \. "januari"\. "februari"\. "maart"\. "april"\. "mei"\. "juni"\. "juli"\. "augustus"\. "september"\. "oktober"\. "november"\. "december"\. ""]. ::msgcat::mcset nl DATE_FORMAT "%e %B %Y". ::msgcat::mcset nl TIME_FORM
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.817188474504631
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmo4gPI5og9X3vG5og9X3v6X5o49+3vnFDoAov:4EnLzu8WgAhF3v8F3v6JI3v9dy
                                                                                                                                                                                                                                  MD5:B08E30850CA849068D06A99B4E216892
                                                                                                                                                                                                                                  SHA1:11B5E95FF4D822E76A1B9C28EEC2BC5E95E5E362
                                                                                                                                                                                                                                  SHA-256:9CD54EC24CBDBEC5E4FE543DDA8CA95390678D432D33201FA1C32B61F8FE225A
                                                                                                                                                                                                                                  SHA-512:9AF147C2F22B11115E32E0BFD0126FE7668328E7C67B349A781F42B0022A334E53DDF3FCCC2C34C91BFBB45602A002D0D7B569B5E1FE9F0EE6C4570400CB0B0C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset nl_BE DATE_FORMAT "%d-%m-%y". ::msgcat::mcset nl_BE TIME_FORMAT "%T". ::msgcat::mcset nl_BE TIME_FORMAT_12 "%T". ::msgcat::mcset nl_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1148
                                                                                                                                                                                                                                  Entropy (8bit):4.207752506572597
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8eNsP2/xhsSpf2TBtHQT15j63WN7v9v3l:46it/vs22Te5OiL51
                                                                                                                                                                                                                                  MD5:2266607EF358B632696C7164E61358B5
                                                                                                                                                                                                                                  SHA1:A380863A8320DAB1D5A2D60C22ED5F7DB5C7BAF7
                                                                                                                                                                                                                                  SHA-256:5EE93A8C245722DEB64B68EFF50C081F24DA5DE43D999C006A10C484E1D3B4ED
                                                                                                                                                                                                                                  SHA-512:2A8DEF754A25736D14B958D8B0CEA0DC41C402A9EFA25C9500BA861A7E8D74C79939C1969AC694245605C17D33AD3984F6B9ACCA4BE03EFC41A878772BB5FD86
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset nn DAYS_OF_WEEK_ABBREV [list \. "su"\. "m\u00e5"\. "ty"\. "on"\. "to"\. "fr"\. "lau"]. ::msgcat::mcset nn DAYS_OF_WEEK_FULL [list \. "sundag"\. "m\u00e5ndag"\. "tysdag"\. "onsdag"\. "torsdag"\. "fredag"\. "laurdag"]. ::msgcat::mcset nn MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "mai"\. "jun"\. "jul"\. "aug"\. "sep"\. "okt"\. "nov"\. "des"\. ""]. ::msgcat::mcset nn MONTHS_FULL [list \. "januar"\. "februar"\. "mars"\. "april"\. "mai"\. "juni"\. "juli"\. "august"\. "september"\. "oktober"\. "november"\. "desember"\. ""]. ::msgcat::mcset nn BCE "f.Kr.". ::msgcat::mcset nn CE "e.Kr.". ::msgca
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1211
                                                                                                                                                                                                                                  Entropy (8bit):4.392723231340452
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu854moKR4mtPoTckd8EnO6z3K4jwxI1LRhtm3ni8FwxIBgdE4RsMZmB0CLs:4azu8yNgyJxPEyRhonO+AjTg0Okvpvn
                                                                                                                                                                                                                                  MD5:31A9133E9DCA7751B4C3451D60CCFFA0
                                                                                                                                                                                                                                  SHA1:FB97A5830965716E77563BE6B7EB1C6A0EA6BF40
                                                                                                                                                                                                                                  SHA-256:C39595DDC0095EB4AE9E66DB02EE175B31AC3DA1F649EB88FA61B911F838F753
                                                                                                                                                                                                                                  SHA-512:329EE7FE79783C83361A0C5FFFD7766B64B8544D1AD63C57AEAA2CC6A526E01D9C4D7765C73E88F86DAE57477459EA330A0C42F39E441B50DE9B0F429D01EAE8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset pl DAYS_OF_WEEK_ABBREV [list \. "N"\. "Pn"\. "Wt"\. "\u015ar"\. "Cz"\. "Pt"\. "So"]. ::msgcat::mcset pl DAYS_OF_WEEK_FULL [list \. "niedziela"\. "poniedzia\u0142ek"\. "wtorek"\. "\u015broda"\. "czwartek"\. "pi\u0105tek"\. "sobota"]. ::msgcat::mcset pl MONTHS_ABBREV [list \. "sty"\. "lut"\. "mar"\. "kwi"\. "maj"\. "cze"\. "lip"\. "sie"\. "wrz"\. "pa\u017a"\. "lis"\. "gru"\. ""]. ::msgcat::mcset pl MONTHS_FULL [list \. "stycze\u0144"\. "luty"\. "marzec"\. "kwiecie\u0144"\. "maj"\. "czerwiec"\. "lipiec"\. "sierpie\u0144"\. "wrzesie\u0144"\. "pa\u017adziernik"\. "listopad"\. "grudzie\u0144"\. ""]. ::msgcat::m
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1127
                                                                                                                                                                                                                                  Entropy (8bit):4.325163993882846
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8pYpzzktTYyUgC0CIKjblie5f9kwAAs+CFsFoD6GADvtU6svO:46dCzWTh2AA9/2F4oD6GAztU6KO
                                                                                                                                                                                                                                  MD5:D827F76D1ED6CB89839CAC2B56FD7252
                                                                                                                                                                                                                                  SHA1:140D6BC1F6CEF5FD0A390B3842053BF54B54B4E2
                                                                                                                                                                                                                                  SHA-256:9F2BFFA3B4D8783B2CFB2CED9CC4319ACF06988F61829A1E5291D55B19854E88
                                                                                                                                                                                                                                  SHA-512:B662336699E23E371F0148EDD742F71874A7A28DFA81F0AFAE91C8C9494CEA1904FEA0C21264CF2A253E0FB1360AD35B28CFC4B74E4D7B2DBB0E453E96F7EB93
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset pt DAYS_OF_WEEK_ABBREV [list \. "Dom"\. "Seg"\. "Ter"\. "Qua"\. "Qui"\. "Sex"\. "S\u00e1b"]. ::msgcat::mcset pt DAYS_OF_WEEK_FULL [list \. "Domingo"\. "Segunda-feira"\. "Ter\u00e7a-feira"\. "Quarta-feira"\. "Quinta-feira"\. "Sexta-feira"\. "S\u00e1bado"]. ::msgcat::mcset pt MONTHS_ABBREV [list \. "Jan"\. "Fev"\. "Mar"\. "Abr"\. "Mai"\. "Jun"\. "Jul"\. "Ago"\. "Set"\. "Out"\. "Nov"\. "Dez"\. ""]. ::msgcat::mcset pt MONTHS_FULL [list \. "Janeiro"\. "Fevereiro"\. "Mar\u00e7o"\. "Abril"\. "Maio"\. "Junho"\. "Julho"\. "Agosto"\. "Setembro"\. "Outubro"\. "Novembro"\. "Dezembro"\. ""]. ::msgcat::mcset pt DATE_FO
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):279
                                                                                                                                                                                                                                  Entropy (8bit):4.8127929329126085
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmofm6GPWHFLofAW3vG5ofAW3v6X5ofm6T+3vnFDoAov:4EnLzu8hNGgF493vr93v6uNK3v9dy
                                                                                                                                                                                                                                  MD5:4EE34960147173A12020A583340E92F8
                                                                                                                                                                                                                                  SHA1:78D91A80E2426A84BC88EE97DA28EC0E4BE8DE45
                                                                                                                                                                                                                                  SHA-256:E383B20484EE90C00054D52DD5AF473B2AC9DC50C14D459A579EF5F44271D256
                                                                                                                                                                                                                                  SHA-512:EDFF8FB9A86731FFF005AFBBBB522F69B2C6033F59ECCD5E35A8B6A9E0F9AF23C52FFDCC22D893915AD1854E8104C81DA8C5BD8C794C7E645AFB82001B4BFC24
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset pt_BR DATE_FORMAT "%d-%m-%Y". ::msgcat::mcset pt_BR TIME_FORMAT "%T". ::msgcat::mcset pt_BR TIME_FORMAT_12 "%T". ::msgcat::mcset pt_BR DATE_TIME_FORMAT "%a %d %b %Y %T %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1172
                                                                                                                                                                                                                                  Entropy (8bit):4.279005910896047
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8/0oFUBZNk1Mkp3pFukZEoVYfPcF+T1vWFMvUvWI3:46kNkKkpLEoSfPcFgvWFqSWI3
                                                                                                                                                                                                                                  MD5:0F5C8A7022DB1203442241ABEB5901FF
                                                                                                                                                                                                                                  SHA1:C54C8BF05E8E6C2C0901D3C88C89DDCF35A26924
                                                                                                                                                                                                                                  SHA-256:D2E14BE188350D343927D5380EB5672039FE9A37E9A9957921B40E4619B36027
                                                                                                                                                                                                                                  SHA-512:13ACF499FA803D4446D8EC67119BC8257B1F093084B83D854643CEA918049F96C8FA08DC5F896EECA80A5FD552D90E5079937B1A3894D89A589E468172856163
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ro DAYS_OF_WEEK_ABBREV [list \. "D"\. "L"\. "Ma"\. "Mi"\. "J"\. "V"\. "S"]. ::msgcat::mcset ro DAYS_OF_WEEK_FULL [list \. "duminic\u0103"\. "luni"\. "mar\u0163i"\. "miercuri"\. "joi"\. "vineri"\. "s\u00eemb\u0103t\u0103"]. ::msgcat::mcset ro MONTHS_ABBREV [list \. "Ian"\. "Feb"\. "Mar"\. "Apr"\. "Mai"\. "Iun"\. "Iul"\. "Aug"\. "Sep"\. "Oct"\. "Nov"\. "Dec"\. ""]. ::msgcat::mcset ro MONTHS_FULL [list \. "ianuarie"\. "februarie"\. "martie"\. "aprilie"\. "mai"\. "iunie"\. "iulie"\. "august"\. "septembrie"\. "octombrie"\. "noiembrie"\. "decembrie"\. ""]. ::msgcat::mcset ro BCE "d.C.". ::msgcat::mcset ro CE
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2039
                                                                                                                                                                                                                                  Entropy (8bit):4.225775794669275
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46CpQ7kvicQfAQPlQoBBCZAitBmZ/QhQoQaQPTeQgQonQ4FQEWFkt3Wd:hCpgkvzRo6QBw53weFHXFgIGd
                                                                                                                                                                                                                                  MD5:3A7181CE08259FF19D2C27CF8C6752B3
                                                                                                                                                                                                                                  SHA1:97DFFB1E224CEDB5427841C3B59F85376CD4423B
                                                                                                                                                                                                                                  SHA-256:C2A3A0BE5BC5A46A6A63C4DE34E317B402BAD40C22FB2936E1A4F53C1E2F625F
                                                                                                                                                                                                                                  SHA-512:CC9620BA4601E53B22CCFC66A0B53C26224158379DF6BA2D4704A2FE11222DFBDAE3CA9CF51576B4084B8CCA8DB13FDE81396E38F94BCD0C8EA21C5D77680394
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ru DAYS_OF_WEEK_ABBREV [list \. "\u0412\u0441"\. "\u041f\u043d"\. "\u0412\u0442"\. "\u0421\u0440"\. "\u0427\u0442"\. "\u041f\u0442"\. "\u0421\u0431"]. ::msgcat::mcset ru DAYS_OF_WEEK_FULL [list \. "\u0432\u043e\u0441\u043a\u0440\u0435\u0441\u0435\u043d\u044c\u0435"\. "\u043f\u043e\u043d\u0435\u0434\u0435\u043b\u044c\u043d\u0438\u043a"\. "\u0432\u0442\u043e\u0440\u043d\u0438\u043a"\. "\u0441\u0440\u0435\u0434\u0430"\. "\u0447\u0435\u0442\u0432\u0435\u0440\u0433"\. "\u043f\u044f\u0442\u043d\u0438\u0446\u0430"\. "\u0441\u0443\u0431\u0431\u043e\u0442\u0430"]. ::msgcat::mcset ru MONTHS_ABBREV [list \. "\u044f\u043d\u0432"\. "\u0444\u0435\u0432"\. "\u043c\u0430\u0440"\. "\u0430\u043f\u0440"\. "\u043c\u0430\u0439"\. "\u0438\u044e\u043d"\. "\u0438\u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):242
                                                                                                                                                                                                                                  Entropy (8bit):4.8961185447535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoVAgWFLoVY9X3vtfNrFLoVA9+3vW6Q9:4EnLzu8DFWFgaX3vtNS/3vWH9
                                                                                                                                                                                                                                  MD5:E719F47462123A8E7DABADD2D362B4D8
                                                                                                                                                                                                                                  SHA1:332E4CC96E7A01DA7FB399EA14770A5C5185B9F2
                                                                                                                                                                                                                                  SHA-256:AE5D3DF23F019455F3EDFC3262AAC2B00098881F09B9A934C0D26C0AB896700C
                                                                                                                                                                                                                                  SHA-512:93C19D51B633A118AB0D172C5A0991E5084BD54B2E61469D800F80B251A57BD1392BA66FD627586E75B1B075A7C9C2C667654F5783C423819FBDEA640A210BFA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ru_UA DATE_FORMAT "%d.%m.%Y". ::msgcat::mcset ru_UA TIME_FORMAT "%k:%M:%S". ::msgcat::mcset ru_UA DATE_TIME_FORMAT "%d.%m.%Y %k:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1160
                                                                                                                                                                                                                                  Entropy (8bit):4.287536872407747
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8YYy/FY+Cnwj4EbJK5O9g+tQhgQmy/L6GWGvtlMsvWT9:46al4ETw/rWQtVWh
                                                                                                                                                                                                                                  MD5:C7BBD44BD3C30C6116A15C77B15F8E79
                                                                                                                                                                                                                                  SHA1:37CD1477A3318838E8D5C93D596A23F99C8409F2
                                                                                                                                                                                                                                  SHA-256:00F119701C9F3EBA273701A6A731ADAFD7B8902F6BCCF34E61308984456E193A
                                                                                                                                                                                                                                  SHA-512:DAFBDA53CF6AD57A4F6A078E9EF8ED3CACF2F8809DC2AEFB812A4C3ACCD51D954C52079FA26828D670BF696E14989D3FE3C249F1E612B7C759770378919D8BBC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset sh DAYS_OF_WEEK_ABBREV [list \. "Ned"\. "Pon"\. "Uto"\. "Sre"\. "\u010cet"\. "Pet"\. "Sub"]. ::msgcat::mcset sh DAYS_OF_WEEK_FULL [list \. "Nedelja"\. "Ponedeljak"\. "Utorak"\. "Sreda"\. "\u010cetvrtak"\. "Petak"\. "Subota"]. ::msgcat::mcset sh MONTHS_ABBREV [list \. "Jan"\. "Feb"\. "Mar"\. "Apr"\. "Maj"\. "Jun"\. "Jul"\. "Avg"\. "Sep"\. "Okt"\. "Nov"\. "Dec"\. ""]. ::msgcat::mcset sh MONTHS_FULL [list \. "Januar"\. "Februar"\. "Mart"\. "April"\. "Maj"\. "Juni"\. "Juli"\. "Avgust"\. "Septembar"\. "Oktobar"\. "Novembar"\. "Decembar"\. ""]. ::msgcat::mcset sh BCE "p. n. e.". ::msgcat::mcset sh CE "n. e."
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1203
                                                                                                                                                                                                                                  Entropy (8bit):4.335103779497533
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu834j4PV3sSAT3fk3TEJbAT3T1cPyF3eYuCvte/v3eG:46TUG3sPk3TEkcPyFpuEtenJ
                                                                                                                                                                                                                                  MD5:B2EF88014D274C8001B36739F5F566CE
                                                                                                                                                                                                                                  SHA1:1044145C1714FD44D008B13A31BC778DFBE47950
                                                                                                                                                                                                                                  SHA-256:043DECE6EA7C83956B3300B95F8A0E92BADAA8FC29D6C510706649D1D810679A
                                                                                                                                                                                                                                  SHA-512:820EB42D94BEE21FDB990FC27F7900CF676AFC59520F3EE78FB72D6D7243A17A234D4AE964E5D52AD7CBC7DD9A593F672BAD8A80EC48B25B344AA6950EF52ECF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset sk DAYS_OF_WEEK_ABBREV [list \. "Ne"\. "Po"\. "Ut"\. "St"\. "\u0160t"\. "Pa"\. "So"]. ::msgcat::mcset sk DAYS_OF_WEEK_FULL [list \. "Nede\u013ee"\. "Pondelok"\. "Utorok"\. "Streda"\. "\u0160tvrtok"\. "Piatok"\. "Sobota"]. ::msgcat::mcset sk MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "m\u00e1j"\. "j\u00fan"\. "j\u00fal"\. "aug"\. "sep"\. "okt"\. "nov"\. "dec"\. ""]. ::msgcat::mcset sk MONTHS_FULL [list \. "janu\u00e1r"\. "febru\u00e1r"\. "marec"\. "apr\u00edl"\. "m\u00e1j"\. "j\u00fan"\. "j\u00fal"\. "august"\. "september"\. "okt\u00f3ber"\. "november"\. "december"\. ""]. ::msgcat::mcset sk BCE
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1164
                                                                                                                                                                                                                                  Entropy (8bit):4.26110325084843
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8PyUpd4+RfscasS9CErTByism1KSCvt1vJo6:462U/ENsqrTtVEtRx
                                                                                                                                                                                                                                  MD5:2566BDE28B17C526227634F1B4FC7047
                                                                                                                                                                                                                                  SHA1:BE6940EC9F4C5E228F043F9D46A42234A02F4A03
                                                                                                                                                                                                                                  SHA-256:BD488C9D791ABEDF698B66B768E2BF24251FFEAF06F53FB3746CAB457710FF77
                                                                                                                                                                                                                                  SHA-512:CC684BFC82CA55240C5B542F3F63E0FF43AEF958469B3978E414261BC4FADB50A0AE3554CF2468AC88E4DDB70D2258296C0A2FBB69312223EED56C7C03FEC17C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset sl DAYS_OF_WEEK_ABBREV [list \. "Ned"\. "Pon"\. "Tor"\. "Sre"\. "\u010cet"\. "Pet"\. "Sob"]. ::msgcat::mcset sl DAYS_OF_WEEK_FULL [list \. "Nedelja"\. "Ponedeljek"\. "Torek"\. "Sreda"\. "\u010cetrtek"\. "Petek"\. "Sobota"]. ::msgcat::mcset sl MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "maj"\. "jun"\. "jul"\. "avg"\. "sep"\. "okt"\. "nov"\. "dec"\. ""]. ::msgcat::mcset sl MONTHS_FULL [list \. "januar"\. "februar"\. "marec"\. "april"\. "maj"\. "junij"\. "julij"\. "avgust"\. "september"\. "oktober"\. "november"\. "december"\. ""]. ::msgcat::mcset sl BCE "pr.n.\u0161.". ::msgcat::mcset sl CE "p
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1267
                                                                                                                                                                                                                                  Entropy (8bit):4.339253133089184
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu82qJw7W5wO6jwbNU7FtHhoJCLov4v2:46iWrvGtBo6+O2
                                                                                                                                                                                                                                  MD5:931A009F7E8A376972DE22AD5670EC88
                                                                                                                                                                                                                                  SHA1:44AEF01F568250851099BAA8A536FBBACD3DEBBB
                                                                                                                                                                                                                                  SHA-256:CB27007E138315B064576C17931280CFE6E6929EFC3DAFD7171713D204CFC3BF
                                                                                                                                                                                                                                  SHA-512:47B230271CD362990C581CD6C06B0BCEA23E10E03D927C7C28415739DB3541D69D1B87DF554E9B4F00ECCAAB0F6AC0565F9EB0DEA8B75C54A90B2D53C928D379
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset sq DAYS_OF_WEEK_ABBREV [list \. "Die"\. "H\u00ebn"\. "Mar"\. "M\u00ebr"\. "Enj"\. "Pre"\. "Sht"]. ::msgcat::mcset sq DAYS_OF_WEEK_FULL [list \. "e diel"\. "e h\u00ebn\u00eb"\. "e mart\u00eb"\. "e m\u00ebrkur\u00eb"\. "e enjte"\. "e premte"\. "e shtun\u00eb"]. ::msgcat::mcset sq MONTHS_ABBREV [list \. "Jan"\. "Shk"\. "Mar"\. "Pri"\. "Maj"\. "Qer"\. "Kor"\. "Gsh"\. "Sht"\. "Tet"\. "N\u00ebn"\. "Dhj"\. ""]. ::msgcat::mcset sq MONTHS_FULL [list \. "janar"\. "shkurt"\. "mars"\. "prill"\. "maj"\. "qershor"\. "korrik"\. "gusht"\. "shtator"\. "tetor"\. "n\u00ebntor"\. "dhjetor"\. ""]. ::msgcat::mcset sq BCE "p.e.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2035
                                                                                                                                                                                                                                  Entropy (8bit):4.24530896413441
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46qoQCSdQqQP4QSsIVKP10NupiuQxQaQLlKnM28nGtfR:hjIX15VKP6NmBU3YKnFbp
                                                                                                                                                                                                                                  MD5:5CA16D93718AAA813ADE746440CF5CE6
                                                                                                                                                                                                                                  SHA1:A142733052B87CA510B8945256399CE9F873794C
                                                                                                                                                                                                                                  SHA-256:313E8CDBBC0288AED922B9927A7331D0FAA2E451D4174B1F5B76C5C9FAEC8F9B
                                                                                                                                                                                                                                  SHA-512:4D031F9BA75D45EC89B2C74A870CCDA41587650D7F9BC91395F68B70BA3CD7A7105E70C19D139D20096533E06F5787C00EA850E27C4ADCF5A28572480D39B639
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset sr DAYS_OF_WEEK_ABBREV [list \. "\u041d\u0435\u0434"\. "\u041f\u043e\u043d"\. "\u0423\u0442\u043e"\. "\u0421\u0440\u0435"\. "\u0427\u0435\u0442"\. "\u041f\u0435\u0442"\. "\u0421\u0443\u0431"]. ::msgcat::mcset sr DAYS_OF_WEEK_FULL [list \. "\u041d\u0435\u0434\u0435\u0459\u0430"\. "\u041f\u043e\u043d\u0435\u0434\u0435\u0459\u0430\u043a"\. "\u0423\u0442\u043e\u0440\u0430\u043a"\. "\u0421\u0440\u0435\u0434\u0430"\. "\u0427\u0435\u0442\u0432\u0440\u0442\u0430\u043a"\. "\u041f\u0435\u0442\u0430\u043a"\. "\u0421\u0443\u0431\u043e\u0442\u0430"]. ::msgcat::mcset sr MONTHS_ABBREV [list \. "\u0408\u0430\u043d"\. "\u0424\u0435\u0431"\. "\u041c\u0430\u0440"\. "\u0410\u043f\u0440"\. "\u041c\u0430\u0458"\. "\u0408\u0443\u043d"\. "\u0408\u0443\u043b"\.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1167
                                                                                                                                                                                                                                  Entropy (8bit):4.2825791311526515
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8JLmAQVm/xTsS9CfxTlijQkcjKxFvivn:46hVQc/psJxT8kyhkn
                                                                                                                                                                                                                                  MD5:496D9183E2907199056CA236438498E1
                                                                                                                                                                                                                                  SHA1:D9C3BB4AEBD9BFD942593694E796A8C2FB9217B8
                                                                                                                                                                                                                                  SHA-256:4F32E1518BE3270F4DB80136FAC0031C385DD3CE133FAA534F141CF459C6113A
                                                                                                                                                                                                                                  SHA-512:FA7FDEDDC42C36D0A60688CDBFE9A2060FE6B2644458D1EBFC817F1E5D5879EB3E3C78B5E53E9D3F42E2E4D84C93C4A7377170986A437EFF404F310D1D72F135
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset sv DAYS_OF_WEEK_ABBREV [list \. "s\u00f6"\. "m\u00e5"\. "ti"\. "on"\. "to"\. "fr"\. "l\u00f6"]. ::msgcat::mcset sv DAYS_OF_WEEK_FULL [list \. "s\u00f6ndag"\. "m\u00e5ndag"\. "tisdag"\. "onsdag"\. "torsdag"\. "fredag"\. "l\u00f6rdag"]. ::msgcat::mcset sv MONTHS_ABBREV [list \. "jan"\. "feb"\. "mar"\. "apr"\. "maj"\. "jun"\. "jul"\. "aug"\. "sep"\. "okt"\. "nov"\. "dec"\. ""]. ::msgcat::mcset sv MONTHS_FULL [list \. "januari"\. "februari"\. "mars"\. "april"\. "maj"\. "juni"\. "juli"\. "augusti"\. "september"\. "oktober"\. "november"\. "december"\. ""]. ::msgcat::mcset sv BCE "f.Kr.". ::msgcat::mcset sv C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):991
                                                                                                                                                                                                                                  Entropy (8bit):4.024338627988864
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu8r4mc4Go/4mtVfqRvodJ3fjESBToOqe3lHvFgdF6A3ixTZ6OM5mSYoC6Vy:4azu88kGDiq1qhbJ75V9gZSpgmSm9
                                                                                                                                                                                                                                  MD5:4DB24BA796D86ADF0441D2E75DE0C07E
                                                                                                                                                                                                                                  SHA1:9935B36FF2B1C6DFDE3EC375BC471A0E93D1F7E3
                                                                                                                                                                                                                                  SHA-256:6B5AB8AE265DB436B15D32263A8870EC55C7C0C07415B3F9BAAC37F73BC704E5
                                                                                                                                                                                                                                  SHA-512:BE7ED0559A73D01537A1E51941ED19F0FEC3F14F9527715CB119E89C97BD31CC6102934B0349D8D0554F5EDD9E3A02978F7DE4919C000A77BD353F7033A4A95B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset sw DAYS_OF_WEEK_ABBREV [list \. "Jpi"\. "Jtt"\. "Jnn"\. "Jtn"\. "Alh"\. "Iju"\. "Jmo"]. ::msgcat::mcset sw DAYS_OF_WEEK_FULL [list \. "Jumapili"\. "Jumatatu"\. "Jumanne"\. "Jumatano"\. "Alhamisi"\. "Ijumaa"\. "Jumamosi"]. ::msgcat::mcset sw MONTHS_ABBREV [list \. "Jan"\. "Feb"\. "Mar"\. "Apr"\. "Mei"\. "Jun"\. "Jul"\. "Ago"\. "Sep"\. "Okt"\. "Nov"\. "Des"\. ""]. ::msgcat::mcset sw MONTHS_FULL [list \. "Januari"\. "Februari"\. "Machi"\. "Aprili"\. "Mei"\. "Juni"\. "Julai"\. "Agosti"\. "Septemba"\. "Oktoba"\. "Novemba"\. "Desemba"\. ""]. ::msgcat::mcset sw BCE "KK". ::msgcat::mcset sw CE "BK".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1835
                                                                                                                                                                                                                                  Entropy (8bit):4.018233695396
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu83w0xn8dnzhmmlmYgtg+CKf6CO5ztFSLt8tCtGtv+CKf6CO5ztFSLt8tCtNu:46k0dgmmlmYgtE/t1H
                                                                                                                                                                                                                                  MD5:2D9C969318D1740049D28EBBD4F62C1D
                                                                                                                                                                                                                                  SHA1:121665081AFC33DDBCF679D7479BF0BC47FEF716
                                                                                                                                                                                                                                  SHA-256:30A142A48E57F194ECC3AA9243930F3E6E1B4E8B331A8CDD2705EC9C280DCCBB
                                                                                                                                                                                                                                  SHA-512:7C32907C39BFB89F558692535041B2A7FA18A64E072F5CF9AB95273F3AC5A7C480B4F953B13484A07AA4DA822613E27E78CC7B02ACE7A61E58FDB5507D7579C3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ta DAYS_OF_WEEK_FULL [list \. "\u0b9e\u0bbe\u0baf\u0bbf\u0bb1\u0bc1"\. "\u0ba4\u0bbf\u0b99\u0bcd\u0b95\u0bb3\u0bcd"\. "\u0b9a\u0bc6\u0bb5\u0bcd\u0bb5\u0bbe\u0baf\u0bcd"\. "\u0baa\u0bc1\u0ba4\u0ba9\u0bcd"\. "\u0bb5\u0bbf\u0baf\u0bbe\u0bb4\u0ba9\u0bcd"\. "\u0bb5\u0bc6\u0bb3\u0bcd\u0bb3\u0bbf"\. "\u0b9a\u0ba9\u0bbf"]. ::msgcat::mcset ta MONTHS_ABBREV [list \. "\u0b9c\u0ba9\u0bb5\u0bb0\u0bbf"\. "\u0baa\u0bc6\u0baa\u0bcd\u0bb0\u0bb5\u0bb0\u0bbf"\. "\u0bae\u0bbe\u0bb0\u0bcd\u0b9a\u0bcd"\. "\u0b8f\u0baa\u0bcd\u0bb0\u0bb2\u0bcd"\. "\u0bae\u0bc7"\. "\u0b9c\u0bc2\u0ba9\u0bcd"\. "\u0b9c\u0bc2\u0bb2\u0bc8"\. "\u0b86\u0b95\u0bb8\u0bcd\u0b9f\u0bcd"\. "\u0b9a\u0bc6\u0baa\u0bcd\u0b9f\u0bae\u0bcd\u0baa\u0bb0\u0bcd"\. "\u0b85\u0b95\u0bcd\u0b9f\u0bcb\u0baa\u0bb0\u0bcd"\. "\u0ba8\u0bb
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):251
                                                                                                                                                                                                                                  Entropy (8bit):4.815592015875268
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmosDv+9/LosK3v6rZosDo+3v+6f6HK:4EnLzu8eDvWbK3v6r5DF3vmq
                                                                                                                                                                                                                                  MD5:293456B39BE945C55536A5DD894787F0
                                                                                                                                                                                                                                  SHA1:94DEF0056C7E3082E58266BCE436A61C045EA394
                                                                                                                                                                                                                                  SHA-256:AA57D5FB5CC3F59EC6A3F99D7A5184403809AA3A3BC02ED0842507D4218B683D
                                                                                                                                                                                                                                  SHA-512:AB763F2932F2FF48AC18C8715F661F7405607E1818B53E0D0F32184ABE67714F03A39A9D0637D0D93CE43606C3E1D702D2A3F8660C288F61DFE852747B652B59
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset ta_IN DATE_FORMAT "%d %M %Y". ::msgcat::mcset ta_IN TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset ta_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2102
                                                                                                                                                                                                                                  Entropy (8bit):4.034298184367717
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46x9mcib30Rgu1je5YdnULEP8l1je5YdnULEPt:hnIb39ufbufV
                                                                                                                                                                                                                                  MD5:0B9B124076C52A503A906059F7446077
                                                                                                                                                                                                                                  SHA1:F43A0F6CCBDDBDD5EA140C7FA55E9A82AB910A03
                                                                                                                                                                                                                                  SHA-256:42C34D02A6079C4D0D683750B3809F345637BC6D814652C3FB0B344B66B70C79
                                                                                                                                                                                                                                  SHA-512:234B9ACA1823D1D6B82583727B4EA68C014D59916B410CB9B158FA1954B6FC3767A261BD0B9F592AF0663906ADF11C2C9A3CC0A325CB1FF58F42A884AF7CB015
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset te DAYS_OF_WEEK_ABBREV [list \. "\u0c06\u0c26\u0c3f"\. "\u0c38\u0c4b\u0c2e"\. "\u0c2e\u0c02\u0c17\u0c33"\. "\u0c2c\u0c41\u0c27"\. "\u0c17\u0c41\u0c30\u0c41"\. "\u0c36\u0c41\u0c15\u0c4d\u0c30"\. "\u0c36\u0c28\u0c3f"]. ::msgcat::mcset te DAYS_OF_WEEK_FULL [list \. "\u0c06\u0c26\u0c3f\u0c35\u0c3e\u0c30\u0c02"\. "\u0c38\u0c4b\u0c2e\u0c35\u0c3e\u0c30\u0c02"\. "\u0c2e\u0c02\u0c17\u0c33\u0c35\u0c3e\u0c30\u0c02"\. "\u0c2c\u0c41\u0c27\u0c35\u0c3e\u0c30\u0c02"\. "\u0c17\u0c41\u0c30\u0c41\u0c35\u0c3e\u0c30\u0c02"\. "\u0c36\u0c41\u0c15\u0c4d\u0c30\u0c35\u0c3e\u0c30\u0c02"\. "\u0c36\u0c28\u0c3f\u0c35\u0c3e\u0c30\u0c02"]. ::msgcat::mcset te MONTHS_ABBREV [list \. "\u0c1c\u0c28\u0c35\u0c30\u0c3f"\. "\u0c2b\u0c3f\u0c2c\u0c4d\u0c30\u0c35\u0c30\u0c3f"\. "\u0c2e\u0c3e\u0c30\u0c4d\u0c1a\u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):411
                                                                                                                                                                                                                                  Entropy (8bit):5.01781242466238
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu8CjZWsn0sEjoD0sLvUFS3v6r5F3vMq:4azu84Z1nnEjoDnLvUFEvS5NvMq
                                                                                                                                                                                                                                  MD5:443E34E2E2BC7CB64A8BA52D99D6B4B6
                                                                                                                                                                                                                                  SHA1:D323C03747FE68E9B73F7E5C1E10B168A40F2A2F
                                                                                                                                                                                                                                  SHA-256:88BDAF4B25B684B0320A2E11D3FE77DDDD25E3B17141BD7ED1D63698C480E4BA
                                                                                                                                                                                                                                  SHA-512:5D8B267530EC1480BF3D571AABC2DA7B4101EACD7FB03B49049709E39D665DD7ACB66FD785BA2B5203DDC54C520434219D2D9974A1E9EE74C659FFAEA6B694E0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset te_IN AM "\u0c2a\u0c42\u0c30\u0c4d\u0c35\u0c3e\u0c39\u0c4d\u0c28". ::msgcat::mcset te_IN PM "\u0c05\u0c2a\u0c30\u0c3e\u0c39\u0c4d\u0c28". ::msgcat::mcset te_IN DATE_FORMAT "%d/%m/%Y". ::msgcat::mcset te_IN TIME_FORMAT_12 "%I:%M:%S %P". ::msgcat::mcset te_IN DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2305
                                                                                                                                                                                                                                  Entropy (8bit):4.324407451316591
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46P4QX/wQT0H/u3rPc8JD57XWWND8QM70xJi53Ljtef:hQ556rVDWZcLOO
                                                                                                                                                                                                                                  MD5:D145F9DF0E339A2538662BD752F02E16
                                                                                                                                                                                                                                  SHA1:AFD97F8E8CC14D306DEDD78F8F395738E38A8569
                                                                                                                                                                                                                                  SHA-256:F9641A6EBE3845CE5D36CED473749F5909C90C52E405F074A6DA817EF6F39867
                                                                                                                                                                                                                                  SHA-512:E17925057560462F730CF8288856E46FA1F1D2A10B5D4D343257B7687A3855014D5C65B6C85AC55A7C77B8B355DB19F053C74B91DFA7BE7E9F933D9D4DA117F7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset th DAYS_OF_WEEK_ABBREV [list \. "\u0e2d\u0e32."\. "\u0e08."\. "\u0e2d."\. "\u0e1e."\. "\u0e1e\u0e24."\. "\u0e28."\. "\u0e2a."]. ::msgcat::mcset th DAYS_OF_WEEK_FULL [list \. "\u0e27\u0e31\u0e19\u0e2d\u0e32\u0e17\u0e34\u0e15\u0e22\u0e4c"\. "\u0e27\u0e31\u0e19\u0e08\u0e31\u0e19\u0e17\u0e23\u0e4c"\. "\u0e27\u0e31\u0e19\u0e2d\u0e31\u0e07\u0e04\u0e32\u0e23"\. "\u0e27\u0e31\u0e19\u0e1e\u0e38\u0e18"\. "\u0e27\u0e31\u0e19\u0e1e\u0e24\u0e2b\u0e31\u0e2a\u0e1a\u0e14\u0e35"\. "\u0e27\u0e31\u0e19\u0e28\u0e38\u0e01\u0e23\u0e4c"\. "\u0e27\u0e31\u0e19\u0e40\u0e2a\u0e32\u0e23\u0e4c"]. ::msgcat::mcset th MONTHS_ABBREV [list \. "\u0e21.\u0e04."\. "\u0e01.\u0e1e."\. "\u0e21\u0e35.\u0e04."\. "\u0e40\u0e21.\u0e22."\. "\u0e1e.\u0e04."\. "\u0e21\u0e34.\u0e22."\. "\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1133
                                                                                                                                                                                                                                  Entropy (8bit):4.32041719596907
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu80VAFVsNTib5vk5CfYTnGk65GmogWFLNvoKvWI3:46j8NTgwVTnlSJWFLJvWI3
                                                                                                                                                                                                                                  MD5:3AFAD9AD82A9C8B754E2FE8FC0094BAB
                                                                                                                                                                                                                                  SHA1:4EE3E2DF86612DB314F8D3E7214D7BE241AA1A32
                                                                                                                                                                                                                                  SHA-256:DF7C4BA67457CB47EEF0F5CA8E028FF466ACDD877A487697DC48ECAC7347AC47
                                                                                                                                                                                                                                  SHA-512:79A6738A97B7DB9CA4AE9A3BA1C3E56BE9AC67E71AE12154FD37A37D78892B6414A49E10E007DE2EB314942DC017B87FAB7C64B74EC9B889DAEBFF9B3B78E644
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset tr DAYS_OF_WEEK_ABBREV [list \. "Paz"\. "Pzt"\. "Sal"\. "\u00c7ar"\. "Per"\. "Cum"\. "Cmt"]. ::msgcat::mcset tr DAYS_OF_WEEK_FULL [list \. "Pazar"\. "Pazartesi"\. "Sal\u0131"\. "\u00c7ar\u015famba"\. "Per\u015fembe"\. "Cuma"\. "Cumartesi"]. ::msgcat::mcset tr MONTHS_ABBREV [list \. "Oca"\. "\u015eub"\. "Mar"\. "Nis"\. "May"\. "Haz"\. "Tem"\. "A\u011fu"\. "Eyl"\. "Eki"\. "Kas"\. "Ara"\. ""]. ::msgcat::mcset tr MONTHS_FULL [list \. "Ocak"\. "\u015eubat"\. "Mart"\. "Nisan"\. "May\u0131s"\. "Haziran"\. "Temmuz"\. "A\u011fustos"\. "Eyl\u00fcl"\. "Ekim"\. "Kas\u0131m"\. "Aral\u0131k"\. ""]. ::msgcat::mcset tr D
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2113
                                                                                                                                                                                                                                  Entropy (8bit):4.227105489438195
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:46+ytFoQAQPHUKPo6eQ4QBuQ0WbQcJeyFQDWZlQD1QbS7XQn1Q7mDaSAJQ7GMLzM:hIpP5tzYhTUhAgEAE+
                                                                                                                                                                                                                                  MD5:458A38F894B296C83F85A53A92FF8520
                                                                                                                                                                                                                                  SHA1:CE26187875E334C712FDAB73E6B526247C6FE1CF
                                                                                                                                                                                                                                  SHA-256:CF2E78EF3322F0121E958098EF5F92DA008344657A73439EAC658CB6BF3D72BD
                                                                                                                                                                                                                                  SHA-512:3B8730C331CF29EF9DEDBC9D5A53C50D429931B8DA01EE0C20DAE25B995114966DB9BC576BE0696DEC088DB1D88B50DE2C376275AB5251F49F6544E546BBC531
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset uk DAYS_OF_WEEK_ABBREV [list \. "\u043d\u0434"\. "\u043f\u043d"\. "\u0432\u0442"\. "\u0441\u0440"\. "\u0447\u0442"\. "\u043f\u0442"\. "\u0441\u0431"]. ::msgcat::mcset uk DAYS_OF_WEEK_FULL [list \. "\u043d\u0435\u0434\u0456\u043b\u044f"\. "\u043f\u043e\u043d\u0435\u0434\u0456\u043b\u043e\u043a"\. "\u0432\u0456\u0432\u0442\u043e\u0440\u043e\u043a"\. "\u0441\u0435\u0440\u0435\u0434\u0430"\. "\u0447\u0435\u0442\u0432\u0435\u0440"\. "\u043f'\u044f\u0442\u043d\u0438\u0446\u044f"\. "\u0441\u0443\u0431\u043e\u0442\u0430"]. ::msgcat::mcset uk MONTHS_ABBREV [list \. "\u0441\u0456\u0447"\. "\u043b\u044e\u0442"\. "\u0431\u0435\u0440"\. "\u043a\u0432\u0456\u0442"\. "\u0442\u0440\u0430\u0432"\. "\u0447\u0435\u0440\u0432"\. "\u043b\u0438\u043f"\. "\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1421
                                                                                                                                                                                                                                  Entropy (8bit):4.382223858419589
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:4azu8pNu9UT5xDHy2W82yGWnf/oxHFBSWWS1D/avSv16:46Oixzy2IyhwZ17cU16
                                                                                                                                                                                                                                  MD5:3BD0AB95976D1B80A30547E4B23FD595
                                                                                                                                                                                                                                  SHA1:B3E5DC095973E46D8808326B2A1FC45046B5267F
                                                                                                                                                                                                                                  SHA-256:9C69094C0BD52D5AE8448431574EAE8EE4BE31EC2E8602366DF6C6BF4BC89A58
                                                                                                                                                                                                                                  SHA-512:2A68A7ADC385EDEA02E4558884A24DCC6328CC9F7D459CC03CC9F2D2F58CF6FF2103AD5B45C6D05B7E13F28408C6B05CDDF1DF60E822E5095F86A49052E19E59
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset vi DAYS_OF_WEEK_ABBREV [list \. "Th 2"\. "Th 3"\. "Th 4"\. "Th 5"\. "Th 6"\. "Th 7"\. "CN"]. ::msgcat::mcset vi DAYS_OF_WEEK_FULL [list \. "Th\u01b0\u0301 hai"\. "Th\u01b0\u0301 ba"\. "Th\u01b0\u0301 t\u01b0"\. "Th\u01b0\u0301 n\u0103m"\. "Th\u01b0\u0301 s\u00e1u"\. "Th\u01b0\u0301 ba\u0309y"\. "Chu\u0309 nh\u00e2\u0323t"]. ::msgcat::mcset vi MONTHS_ABBREV [list \. "Thg 1"\. "Thg 2"\. "Thg 3"\. "Thg 4"\. "Thg 5"\. "Thg 6"\. "Thg 7"\. "Thg 8"\. "Thg 9"\. "Thg 10"\. "Thg 11"\. "Thg 12"\. ""]. ::msgcat::mcset vi MONTHS_FULL [list \. "Th\u00e1ng m\u00f4\u0323t"\. "Th\u00e1ng hai"\. "Th\u00e1ng ba"\. "Th\u00e1ng t\u01b0"\. "Th\u00e1ng n\u0103m"\. "Th\u00e1ng s\
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (1598)
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3330
                                                                                                                                                                                                                                  Entropy (8bit):4.469203967086526
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:468jDI/Tw71xDqwPqDa8c3FLbYmhyvMDKbW0YGLuoEyzag29dL:hn7wRdNL
                                                                                                                                                                                                                                  MD5:9C33FFDD4C13D2357AB595EC3BA70F04
                                                                                                                                                                                                                                  SHA1:A87F20F7A331DEFC33496ECDA50D855C8396E040
                                                                                                                                                                                                                                  SHA-256:EF81B41EC69F67A394ECE2B3983B67B3D0C8813624C2BFA1D8A8C15B21608AC9
                                                                                                                                                                                                                                  SHA-512:E31EEE90660236BCD958F3C540F56B2583290BAD6086AE78198A0819A92CF2394C62DE3800FDDD466A8068F4CABDFBCA46A648D419B1D0103381BF428D721B13
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset zh DAYS_OF_WEEK_ABBREV [list \. "\u661f\u671f\u65e5"\. "\u661f\u671f\u4e00"\. "\u661f\u671f\u4e8c"\. "\u661f\u671f\u4e09"\. "\u661f\u671f\u56db"\. "\u661f\u671f\u4e94"\. "\u661f\u671f\u516d"]. ::msgcat::mcset zh DAYS_OF_WEEK_FULL [list \. "\u661f\u671f\u65e5"\. "\u661f\u671f\u4e00"\. "\u661f\u671f\u4e8c"\. "\u661f\u671f\u4e09"\. "\u661f\u671f\u56db"\. "\u661f\u671f\u4e94"\. "\u661f\u671f\u516d"]. ::msgcat::mcset zh MONTHS_ABBREV [list \. "\u4e00\u6708"\. "\u4e8c\u6708"\. "\u4e09\u6708"\. "\u56db\u6708"\. "\u4e94\u6708"\. "\u516d\u6708"\. "\u4e03\u6708"\. "\u516b\u6708"\. "\u4e5d\u6708"\. "\u5341\u6708"\. "\u5341\u4e00\u6708"\. "\u5341\u4e8c\u6708"\. ""]. ::msgcat::mcset zh MONTHS_FULL [list \.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):312
                                                                                                                                                                                                                                  Entropy (8bit):5.1281364096481665
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoX5HoHJ+3vtfNrFLoHJ+3v6MY+oXa+3vYq9:4EnLzu8d5eJ+3vtNEJ+3v6L1L3vYq9
                                                                                                                                                                                                                                  MD5:EB94B41551EAAFFA5DF4F406C7ACA3A4
                                                                                                                                                                                                                                  SHA1:B0553108BDE43AA7ED362E2BFFAF1ABCA1567491
                                                                                                                                                                                                                                  SHA-256:85F91CF6E316774AA5D0C1ECA85C88E591FD537165BB79929C5E6A1CA99E56C8
                                                                                                                                                                                                                                  SHA-512:A0980A6F1AD9236647E4F18CC104999DB2C523153E8716FD0CFE57320E906DF80378A5C0CDE132F2C53F160F5304EAF34910D7D1BB5753987D74AFBC0B6F75F3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset zh_CN DATE_FORMAT "%Y-%m-%e". ::msgcat::mcset zh_CN TIME_FORMAT "%k:%M:%S". ::msgcat::mcset zh_CN TIME_FORMAT_12 "%P%I\u65f6%M\u5206%S\u79d2". ::msgcat::mcset zh_CN DATE_TIME_FORMAT "%Y-%m-%e %k:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):752
                                                                                                                                                                                                                                  Entropy (8bit):4.660158381384211
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:4EnLzu8qmDBHZLX+TyW4OU5yPgM9Lz+SC3WwLNMW3v6G3v3Ww+:4azu8qyFOw3WwLrvTv3Ww+
                                                                                                                                                                                                                                  MD5:D8C6BFBFCE44B6A8A038BA44CB3DB550
                                                                                                                                                                                                                                  SHA1:FBD609576E65B56EDA67FD8A1801A27B43DB5486
                                                                                                                                                                                                                                  SHA-256:D123E0B4C2614F680808B58CCA0C140BA187494B2C8BCF8C604C7EB739C70882
                                                                                                                                                                                                                                  SHA-512:3455145CF5C77FC847909AB1A283452D0C877158616C8AA7BDFFC141B86B2E66F9FF45C3BB6A4A9D758D2F8FFCB1FE919477C4553EFE527C0EDC912EBBCAABCD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset zh_HK DAYS_OF_WEEK_ABBREV [list \. "\u65e5"\. "\u4e00"\. "\u4e8c"\. "\u4e09"\. "\u56db"\. "\u4e94"\. "\u516d"]. ::msgcat::mcset zh_HK MONTHS_ABBREV [list \. "1\u6708"\. "2\u6708"\. "3\u6708"\. "4\u6708"\. "5\u6708"\. "6\u6708"\. "7\u6708"\. "8\u6708"\. "9\u6708"\. "10\u6708"\. "11\u6708"\. "12\u6708"\. ""]. ::msgcat::mcset zh_HK DATE_FORMAT "%Y\u5e74%m\u6708%e\u65e5". ::msgcat::mcset zh_HK TIME_FORMAT_12 "%P%I:%M:%S". ::msgcat::mcset zh_HK DATE_TIME_FORMAT "%Y\u5e74%m\u6708%e\u65e5 %P%I:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):339
                                                                                                                                                                                                                                  Entropy (8bit):5.020358587042703
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoOpxoPpSocvNLohX3v6ZhLoh+3v6fJ:4EnLzu8WvNo3v6b3vu
                                                                                                                                                                                                                                  MD5:E0BC93B8F050D6D80B8173FF4FA4D7B7
                                                                                                                                                                                                                                  SHA1:231FF1B6F859D0261F15D2422DF09E756CE50CCB
                                                                                                                                                                                                                                  SHA-256:2683517766AF9DA0D87B7A862DE9ADEA82D9A1454FC773A9E3C1A6D92ABA947A
                                                                                                                                                                                                                                  SHA-512:8BA6EAC5F71167B83A58B47123ACF7939C348FE2A0CA2F092FE9F60C0CCFB901ADA0E8F2101C282C39BAE86C918390985731A8F66E481F8074732C37CD50727F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset zh_SG AM "\u4e0a\u5348". ::msgcat::mcset zh_SG PM "\u4e2d\u5348". ::msgcat::mcset zh_SG DATE_FORMAT "%d %B %Y". ::msgcat::mcset zh_SG TIME_FORMAT_12 "%P %I:%M:%S". ::msgcat::mcset zh_SG DATE_TIME_FORMAT "%d %B %Y %P %I:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):346
                                                                                                                                                                                                                                  Entropy (8bit):5.08314435797197
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSyEtJLlpuoo6dmoAykaRULH/XRxvBoAyjZRULH5oAyU/G0OZoAyxW3v6ZhLoAR:4EnLzu8I5xEOKRWW3v6w3v8AC
                                                                                                                                                                                                                                  MD5:9CD17E7F28186E0E71932CC241D1CBB1
                                                                                                                                                                                                                                  SHA1:AF1EE536AABB8198BA88D3474ED49F76A37E89FF
                                                                                                                                                                                                                                  SHA-256:D582406C51A3DB1EADF6507C50A1F85740FDA7DA8E27FC1438FEB6242900CB12
                                                                                                                                                                                                                                  SHA-512:4712DD6A27A09EA339615FC3D17BC8E4CD64FF12B2B8012E01FD4D3E7789263899FA05EDDB77044DC7B7D32B3DC55A52B8320D93499DF9A6799A8E4D07174525
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/loadICU.tcl -- do not edit.namespace eval ::tcl::clock {. ::msgcat::mcset zh_TW BCE "\u6c11\u570b\u524d". ::msgcat::mcset zh_TW CE "\u6c11\u570b". ::msgcat::mcset zh_TW DATE_FORMAT "%Y/%m/%e". ::msgcat::mcset zh_TW TIME_FORMAT_12 "%P %I:%M:%S". ::msgcat::mcset zh_TW DATE_TIME_FORMAT "%Y/%m/%e %P %I:%M:%S %z".}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Tcl script, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):32718
                                                                                                                                                                                                                                  Entropy (8bit):4.5415166585248645
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:UczgW5gzrui4sKDt9C7sGbHMmjJbuQH8A2Q:VgTrrvf7sGbHDFSQH8/Q
                                                                                                                                                                                                                                  MD5:1A7DF33BC47D63F9CE1D4FF70A974FA3
                                                                                                                                                                                                                                  SHA1:513EC2215E2124D9A6F6DF2549C1442109E117C0
                                                                                                                                                                                                                                  SHA-256:C5D74E1C927540A3F524E6B929D0956EFBA0797FB8D55918EF69D27DF57DEDA3
                                                                                                                                                                                                                                  SHA-512:F671D5A46382EDFBDA49A6EDB9E6CF2D5CEBD83CE4ADD6B717A478D52748332D41DA3743182D4555B801B96A318D29DFC6AC36B32983ADB32D329C24F8A3D713
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# optparse.tcl --.#.# (private) Option parsing package.# Primarily used internally by the safe:: code..#.#.WARNING: This code will go away in a future release.#.of Tcl. It is NOT supported and you should not rely.#.on it. If your code does rely on this package you.#.may directly incorporate this code into your application...package require Tcl 8.2.# When this version number changes, update the pkgIndex.tcl file.# and the install directory in the Makefiles..package provide opt 0.4.6..namespace eval ::tcl {.. # Exported APIs. namespace export OptKeyRegister OptKeyDelete OptKeyError OptKeyParse \. OptProc OptProcArgGiven OptParse \.. Lempty Lget \. Lassign Lvarpop Lvarpop1 Lvarset Lvarincr \. SetMax SetMin...################# Example of use / 'user documentation' ###################.. proc OptCreateTestProc {} {...# Defines ::tcl::OptParseTest as a test proc with parsed arguments..# (can't be defined before the code below is
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):607
                                                                                                                                                                                                                                  Entropy (8bit):4.652658850873767
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:jHxJRuMopS42wyGlTajUA43KXks4L1GbyvX6VxQ+pBbX:bvRmS42wyGlTah9XkbL7X6VxBB
                                                                                                                                                                                                                                  MD5:92FF1E42CFC5FECCE95068FC38D995B3
                                                                                                                                                                                                                                  SHA1:B2E71842F14D5422A9093115D52F19BCCA1BF881
                                                                                                                                                                                                                                  SHA-256:EB9925A8F0FCC7C2A1113968AB0537180E10C9187B139C8371ADF821C7B56718
                                                                                                                                                                                                                                  SHA-512:608D436395D055C5449A53208F3869B8793DF267B8476AD31BCDD9659A222797814832720C495D938E34BF7D253FFC3F01A73CC0399C0DFB9C85D2789C7F11C0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Tcl package index file, version 1.1.# This file is generated by the "pkg_mkIndex -direct" command.# and sourced either when an application starts up or.# by a "package unknown" script. It invokes the.# "package ifneeded" command to set up package-related.# information so that packages will be loaded automatically.# in response to "package require" commands. When this.# script is sourced, the variable $dir must contain the.# full path name of this file's directory...if {![package vsatisfies [package provide Tcl] 8.2]} {return}.package ifneeded opt 0.4.6 [list source [file join $dir optparse.tcl]].
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):22959
                                                                                                                                                                                                                                  Entropy (8bit):4.836555290409911
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:I72oQXm9jcLyBLWueSzvAXMiow90l3NhETrh4NLTluYhoNL3ZAqYi:I72oQXmgyBCqvAcFw2dhOrh4NZVhoN3F
                                                                                                                                                                                                                                  MD5:55E2DB5DCF8D49F8CD5B7D64FEA640C7
                                                                                                                                                                                                                                  SHA1:8FDC28822B0CC08FA3569A14A8C96EDCA03BFBBD
                                                                                                                                                                                                                                  SHA-256:47B6AF117199B1511F6103EC966A58E2FD41F0ABA775C44692B2069F6ED10BAD
                                                                                                                                                                                                                                  SHA-512:824C210106DE7EAE57A480E3F6E3A5C8FB8AC4BBF0A0A386D576D3EB2A3AC849BDFE638428184056DA9E81767E2B63EFF8E18068A1CF5149C9F8A018F817D3E5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# package.tcl --.#.# utility procs formerly in init.tcl which can be loaded on demand.# for package management..#.# Copyright (c) 1991-1993 The Regents of the University of California..# Copyright (c) 1994-1998 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..namespace eval tcl::Pkg {}..# ::tcl::Pkg::CompareExtension --.#.# Used internally by pkg_mkIndex to compare the extension of a file to a given.# extension. On Windows, it uses a case-insensitive comparison because the.# file system can be file insensitive..#.# Arguments:.# fileName.name of a file whose extension is compared.# ext..(optional) The extension to compare against; you must.#..provide the starting dot..#..Defaults to [info sharedlibextension].#.# Results:.# Returns 1 if the extension matches, 0 otherwise..proc tcl::Pkg::CompareExtension {fileName {ext {}}} {. global tcl_platform. if {$ext eq ""} {set ext
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):816
                                                                                                                                                                                                                                  Entropy (8bit):4.833285375693491
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:TcS2n1RBbgZKaNHaeYFSxYmXqt9IGUafZwXgEImK7k35IpbdELS8/McjbPgnE:TcHn5sZKGkwa/JxfJmRGNc93j7CE
                                                                                                                                                                                                                                  MD5:FCDAF75995F2CCE0A5D5943E9585590D
                                                                                                                                                                                                                                  SHA1:A0B1BD4E68DCE1768D3C5E0D3C7B31E28021D3BA
                                                                                                                                                                                                                                  SHA-256:EBE5A2B4CBBCD7FD3F7A6F76D68D7856301DB01B350C040942A7B806A46E0014
                                                                                                                                                                                                                                  SHA-512:A632D0169EE3B6E6B7EF73F5FBA4B7897F9491BDB389D78165E297252424546EFB43895D3DD530864B9FCF2ECF5BCE7DA8E55BA5B4F20E23E1E45ADDAF941C11
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# parray:.# Print the contents of a global array on stdout..#.# Copyright (c) 1991-1993 The Regents of the University of California..# Copyright (c) 1994 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..proc parray {a {pattern *}} {. upvar 1 $a array. if {![array exists array]} {..return -code error "\"$a\" isn't an array". }. set maxl 0. set names [lsort [array names array $pattern]]. foreach name $names {..if {[string length $name] > $maxl} {.. set maxl [string length $name]..}. }. set maxl [expr {$maxl + [string length $a] + 2}]. foreach name $names {..set nameString [format %s(%s) $a $name]..puts stdout [format "%-*s = %s" $maxl $nameString $array($name)]. }.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Tcl script, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):33439
                                                                                                                                                                                                                                  Entropy (8bit):4.750571844372246
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:OovFcXxzYqZ1//L2J4lb77BvnthiV0EnoQI4MnNhGQmzY3wKIYkA:OovFcqqZF2J4lb7Rrg0EnoQI4INhGrzu
                                                                                                                                                                                                                                  MD5:325A573F30C9EA70FD891E85664E662C
                                                                                                                                                                                                                                  SHA1:6EC3F21EBCFD269847C43891DAD96189FACF20E4
                                                                                                                                                                                                                                  SHA-256:89B74D2417EB27FEEA32B8666B08D28BC1FFE5DCF1652DBD8799F7555D79C71F
                                                                                                                                                                                                                                  SHA-512:149FE725A3234A2F8C3EE1B03119440E3CB16586F04451B6E62CED0097B1AD227C97B55F5A66631033A888E860AB61CAF7DDD014696276BC9226D87F15164E2F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# safe.tcl --.#.# This file provide a safe loading/sourcing mechanism for safe interpreters..# It implements a virtual path mecanism to hide the real pathnames from the.# slave. It runs in a master interpreter and sets up data structure and.# aliases that will be invoked when used from a slave interpreter..#.# See the safe.n man page for details..#.# Copyright (c) 1996-1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution of.# this file, and for a DISCLAIMER OF ALL WARRANTIES...#.# The implementation is based on namespaces. These naming conventions are.# followed:.# Private procs starts with uppercase..# Public procs are exported and starts with lowercase.#..# Needed utilities package.package require opt 0.4.1..# Create the safe namespace.namespace eval ::safe {. # Exported API:. namespace export interpCreate interpInit interpConfigure interpDelete \..interpAddToAccessPath interpFindInAccessPath setLogCmd.}..# Helper function to
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5415
                                                                                                                                                                                                                                  Entropy (8bit):4.701682771925196
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:esataNULULUVUhU5U1UIUZUJeUpgURUFD15Q0AkU6PkrBkGUjZKspDzmK5SMFTub:eNtEACkiwM3g4ePOiD15Q0AkU6PkrBko
                                                                                                                                                                                                                                  MD5:E127196E9174B429CC09C040158F6AAB
                                                                                                                                                                                                                                  SHA1:FF850F5D1BD8EFC1A8CB765FE8221330F0C6C699
                                                                                                                                                                                                                                  SHA-256:ABF7D9D1E86DE931096C21820BFA4FD70DB1F55005D2DB4AA674D86200867806
                                                                                                                                                                                                                                  SHA-512:C4B98EBC65E25DF41E6B9A93E16E608CF309FA0AE712578EE4974D84F7F33BCF2A6ED7626E88A343350E13DA0C5C1A88E24A87FCBD44F7DA5983BB3EF036A162
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Tcl autoload index file, version 2.0.# -*- tcl -*-.# This file is generated by the "auto_mkindex" command.# and sourced to set up indexing information for one or.# more commands. Typically each line is a command that.# sets an element in the auto_index array, where the.# element name is the name of a command and the value is.# a script that loads the command...set auto_index(auto_reset) [list source [file join $dir auto.tcl]].set auto_index(tcl_findLibrary) [list source [file join $dir auto.tcl]].set auto_index(auto_mkindex) [list source [file join $dir auto.tcl]].set auto_index(auto_mkindex_old) [list source [file join $dir auto.tcl]].set auto_index(::auto_mkindex_parser::init) [list source [file join $dir auto.tcl]].set auto_index(::auto_mkindex_parser::cleanup) [list source [file join $dir auto.tcl]].set auto_index(::auto_mkindex_parser::mkindex) [list source [file join $dir auto.tcl]].set auto_index(::auto_mkindex_parser::hook) [list source [file join $dir auto.tcl]].set auto_in
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):11633
                                                                                                                                                                                                                                  Entropy (8bit):4.706526847377957
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:CnjVD6gOGFpvXKPrzYkWo55z3ovPvKvaWZPZ9W6TV9ujpZw7K3mQ4auPltqQvu9:CGQvX+XYkn59YvPSvDJTV9174zuPltBC
                                                                                                                                                                                                                                  MD5:F9ED2096EEA0F998C6701DB8309F95A6
                                                                                                                                                                                                                                  SHA1:BCDB4F7E3DB3E2D78D25ED4E9231297465B45DB8
                                                                                                                                                                                                                                  SHA-256:6437BD7040206D3F2DB734FA482B6E79C68BCC950FBA80C544C7F390BA158F9B
                                                                                                                                                                                                                                  SHA-512:E4FB8F28DC72EA913F79CEDF5776788A0310608236D6607ADC441E7F3036D589FD2B31C446C187EF5827FD37DCAA26D9E94D802513E3BF3300E94DD939695B30
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# -*- tcl -*-.#.# Searching for Tcl Modules. Defines a procedure, declares it as the primary.# command for finding packages, however also uses the former 'package unknown'.# command as a fallback..#.# Locates all possible packages in a directory via a less restricted glob. The.# targeted directory is derived from the name of the requested package, i.e..# the TM scan will look only at directories which can contain the requested.# package. It will register all packages it found in the directory so that.# future requests have a higher chance of being fulfilled by the ifneeded.# database without having to come to us again..#.# We do not remember where we have been and simply rescan targeted directories.# when invoked again. The reasoning is this:.#.# - The only way we get back to the same directory is if someone is trying to.# [package require] something that wasn't there on the first scan..#.# Either.# 1) It is there now: If we rescan, you get it; if not you don't..#.# This co
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):141
                                                                                                                                                                                                                                  Entropy (8bit):4.951583909886815
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52DcsG/kXGm2OHnFvpsYvUdSalHFLd:SlSWB9X52DBGTm2OHnFvmYValHf
                                                                                                                                                                                                                                  MD5:6FB79707FD3A183F8A3C780CA2669D27
                                                                                                                                                                                                                                  SHA1:E703AB552B4231827ACD7872364C36C70988E4C0
                                                                                                                                                                                                                                  SHA-256:A5DC7BFB4F569361D438C8CF13A146CC2641A1A884ACF905BB51DA28FF29A900
                                                                                                                                                                                                                                  SHA-512:CDD3AD9AFFD246F4DFC40C1699E368FB2924E73928060B1178D298DCDB11DBD0E88BC10ED2FED265F7F7271AC5CCE14A60D65205084E9249154B8D54C2309E52
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Abidjan) {. {-9223372036854775808 -968 0 LMT}. {-1830383032 0 0 GMT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1393
                                                                                                                                                                                                                                  Entropy (8bit):3.9087586646312253
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52DUsmdHvdDZxdCjFaEu3MEANKSgI3u2VuTSr0l+pU4Y4Y0gK:cQ9elDZxdCwEu3MEANKSgsrVkvY64Y4
                                                                                                                                                                                                                                  MD5:FFEDB06126D6DA9F3BECA614428F51E9
                                                                                                                                                                                                                                  SHA1:2C549D1CF8636541D42BDC56D8E534A222E4642C
                                                                                                                                                                                                                                  SHA-256:567A0AD3D2C9E356A2E38A76AF4D5C4B8D5B950AF7B648A027FE816ACAE455AE
                                                                                                                                                                                                                                  SHA-512:E057EA59A47C881C60B2196554C9B24C00CB26345CA7E311B5409F6FBB31EBEDD13C41A4C3B0B68AE8B93F4819158D94610DE795112E77209F391AC31332BA2A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Accra) {. {-9223372036854775808 -52 0 LMT}. {-1640995148 0 0 GMT}. {-1556841600 1200 1 GMT}. {-1546388400 0 0 GMT}. {-1525305600 1200 1 GMT}. {-1514852400 0 0 GMT}. {-1493769600 1200 1 GMT}. {-1483316400 0 0 GMT}. {-1462233600 1200 1 GMT}. {-1451780400 0 0 GMT}. {-1430611200 1200 1 GMT}. {-1420158000 0 0 GMT}. {-1399075200 1200 1 GMT}. {-1388622000 0 0 GMT}. {-1367539200 1200 1 GMT}. {-1357086000 0 0 GMT}. {-1336003200 1200 1 GMT}. {-1325550000 0 0 GMT}. {-1304380800 1200 1 GMT}. {-1293927600 0 0 GMT}. {-1272844800 1200 1 GMT}. {-1262391600 0 0 GMT}. {-1241308800 1200 1 GMT}. {-1230855600 0 0 GMT}. {-1209772800 1200 1 GMT}. {-1199319600 0 0 GMT}. {-1178150400 1200 1 GMT}. {-1167697200 0 0 GMT}. {-1146614400 1200 1 GMT}. {-1136161200 0 0 GMT}. {-1115078400 1200 1 GMT}. {-1104625200 0 0 GMT}. {-1083542400 1200 1 GMT}. {-1073
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.766991307890532
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt2DczqIVDcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL2DnaDkr
                                                                                                                                                                                                                                  MD5:C203A97FC500E408AC841A6A5B21E14E
                                                                                                                                                                                                                                  SHA1:ED4C4AA578A16EB83220F37199460BFE207D2B44
                                                                                                                                                                                                                                  SHA-256:3EBC66964609493524809AD0A730FFFF036C38D9AB3770412841F80DFFC717D5
                                                                                                                                                                                                                                  SHA-512:2F1A4500F49AFD013BCA70089B1E24748D7E45D41F2C9D3D9AFDCC1778E750FFB020D34F622B071E80F80CC0FEFF080E8ACC1E7A8ABE8AD12C0F1A1DAA937FE5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Africa/Addis_Ababa) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1041
                                                                                                                                                                                                                                  Entropy (8bit):4.110061823095588
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52D7AmdHh5PMybVSqSFvvqXFaLSaSxmvWo/fmvCkQ6eW6Xs8QQB1r5Q:cQIefMyb8BF6XFaLSxktf1PW6X4q1K
                                                                                                                                                                                                                                  MD5:8221A83520B1D3DE02E886CFB1948DE3
                                                                                                                                                                                                                                  SHA1:0806A0898FDE6F5AE502C64515A1345D71B1F7D2
                                                                                                                                                                                                                                  SHA-256:5EE3B25676E813D89ED866D03B5C3388567D8307A2A60D1C4A34D938CBADF710
                                                                                                                                                                                                                                  SHA-512:2B8A837F7CF6DE43DF4072BF4A54226235DA8B8CA78EF55649C7BF133B2E002C614FE7C693004E3B17C25FBCECAAD5CD9B0A8CB0A5D32ADF68EA019203EE8704
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Algiers) {. {-9223372036854775808 732 0 LMT}. {-2486679072 561 0 PMT}. {-1855958961 0 0 WET}. {-1689814800 3600 1 WEST}. {-1680397200 0 0 WET}. {-1665363600 3600 1 WEST}. {-1648342800 0 0 WET}. {-1635123600 3600 1 WEST}. {-1616893200 0 0 WET}. {-1604278800 3600 1 WEST}. {-1585443600 0 0 WET}. {-1574038800 3600 1 WEST}. {-1552266000 0 0 WET}. {-1539997200 3600 1 WEST}. {-1531443600 0 0 WET}. {-956365200 3600 1 WEST}. {-950486400 0 0 WET}. {-942012000 3600 0 CET}. {-812502000 7200 1 CEST}. {-796262400 3600 0 CET}. {-781052400 7200 1 CEST}. {-766630800 3600 0 CET}. {-733280400 0 0 WET}. {-439430400 3600 0 CET}. {-212029200 0 0 WET}. {41468400 3600 1 WEST}. {54774000 0 0 WET}. {231724800 3600 1 WEST}. {246240000 3600 0 CET}. {259545600 7200 1 CEST}. {275274000 3600 0 CET}. {309740400 0 0 WET}. {325468800 3600 1 WEST}. {3418020
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.750118730136804
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt2DcjEUEH+DcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL2DGs+Dkr
                                                                                                                                                                                                                                  MD5:F8CEC826666174899C038EC9869576ED
                                                                                                                                                                                                                                  SHA1:4CAA32BB070F31BE919F5A03141711DB22072E2C
                                                                                                                                                                                                                                  SHA-256:D9C940B3BE2F9E424BC6F69D665C21FBCA7F33789E1FE1D27312C0B38B75E097
                                                                                                                                                                                                                                  SHA-512:DA890F5A6806AE6774CFC061DFD4AE069F78212AB063287146245692383022AABB3637DEB49C1D512DA3499DC4295541962DAC05729302B3314E7BF306E6CB41
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Africa/Asmara) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.755468133981916
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt2DcjAWDcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL2D8Dkr
                                                                                                                                                                                                                                  MD5:8B5DCBBDB2309381EAA8488E1551655F
                                                                                                                                                                                                                                  SHA1:65065868620113F759C5D37B89843A334E64D210
                                                                                                                                                                                                                                  SHA-256:F7C8CEE9FA2A4BF9F41ABA18010236AC4CCD914ACCA9E568C87EDA0503D54014
                                                                                                                                                                                                                                  SHA-512:B8E61E6D5057CD75D178B292CD19CBCED2A127099D95046A7448438BCC035DE4066FDD637E9055AC3914E4A8EAA1B0123FA0E90E4F7042B2C4551BB009F1D2E9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Africa/Asmera) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.83500517532947
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2DcxAQDcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2DwNDBP
                                                                                                                                                                                                                                  MD5:FCBE668127DFD81CB0F730C878EB2F1A
                                                                                                                                                                                                                                  SHA1:F27C9D96A04A12AC7423A60A756732B360D6847D
                                                                                                                                                                                                                                  SHA-256:6F462C2C5E190EFCA68E882CD61D5F3A8EF4890761376F22E9905B1B1B6FDE9F
                                                                                                                                                                                                                                  SHA-512:B0E6E4F5B46A84C2D02A0519831B98F336AA79079FF2CB9F290D782335FB4FB39A3453520424ED3761D801B9FBE39228B1D045C40EDD70B29801C26592F9805A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Africa/Bamako) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.834042129935993
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2Dcx2m/2DcGev:SlSWB9IZaM3y7V4FVAIgNT9L2Dw/2D4v
                                                                                                                                                                                                                                  MD5:7A017656AB8048BD67250207CA265717
                                                                                                                                                                                                                                  SHA1:F2BB86BC7B7AB886738A33ADA37C444D6873DB94
                                                                                                                                                                                                                                  SHA-256:E31F69E16450B91D79798C1064FEA18DE89D5FE343D2DE4A5190BCF15225E69D
                                                                                                                                                                                                                                  SHA-512:695FA7369341F1F4BC1B629CDAB1666BEFE2E7DB32D75E5038DC17526A3CCE293DB36AFEB0955B06F5834D43AEF140F7A66EC52598444DBE8C8B70429DBE5FC5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Bangui) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.839691887198201
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2Dcx79FHp4DcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2Dw7J4V
                                                                                                                                                                                                                                  MD5:149DD4375235B088386A2D187ED03FFB
                                                                                                                                                                                                                                  SHA1:5E879B778E2AB110AC7815D3D62A607A76AAB93B
                                                                                                                                                                                                                                  SHA-256:1769E15721DAFF477E655FF7A8491F4954FB2F71496287C6F9ED265FE5588E00
                                                                                                                                                                                                                                  SHA-512:4F997EDE6F04A89240E0950D605BB43D6814DCCA433F3A75F330FA13EE8729A10D20E9A0AAD6E6912370E350ABD5A65B878B914FCC9A5CA8503E3A5485E57B3E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Africa/Banjul) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):169
                                                                                                                                                                                                                                  Entropy (8bit):4.797400281087303
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52Dc5ixXGm2OHGVkevUdSaw7FFFkhSVPVFd:SlSWB9X52D4fm2OHCkeVawBFF2mh
                                                                                                                                                                                                                                  MD5:BA4959590575031330280A4ADC7017D1
                                                                                                                                                                                                                                  SHA1:34FBC2AFD2E13575D286062050D98ABC4BF7C7A6
                                                                                                                                                                                                                                  SHA-256:2C06A94A43AC7F0079E6FE371F0D5A06A7BF23A868AC3B10135BFC4266CD2D4E
                                                                                                                                                                                                                                  SHA-512:65E6161CB6AF053B53C7ABE1E4CAAD4F40E350D52BADCB95EB37138268D17CF48DDB0CA771F450ECD8E6A57C99BE2E8C2227A28B5C4AF3DE7F6D74F255118F04
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Bissau) {. {-9223372036854775808 -3740 0 LMT}. {-1830380400 -3600 0 -01}. {157770000 0 0 GMT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.856245693637169
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsfKGyVAIgNGEjKKW62Dc8ycXp75h4DcfKu:SlSWB9IZaM3y7fYVAIgNTj5W62DAmp1T
                                                                                                                                                                                                                                  MD5:3F6E187410D0109D05410EFC727FB5E5
                                                                                                                                                                                                                                  SHA1:CAB54D985823218E01EDF9165CABAB7A984EE93E
                                                                                                                                                                                                                                  SHA-256:9B2EEB0EF36F851349E254E1745D11B65CB30A16A2EE4A87004765688A5E0452
                                                                                                                                                                                                                                  SHA-512:E12D6DBEA8DE9E3FB236011B962FFE1AEB95E3353B13303C343565B60AA664508D51A011C66C3CE2460C52A901495F46D0500C9B74E19399AE66231E5D6200A0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Maputo)]} {. LoadTimeZoneFile Africa/Maputo.}.set TZData(:Africa/Blantyre) $TZData(:Africa/Maputo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.853052123353996
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2DciE0TMJZp4DcGev:SlSWB9IZaM3y7V4FVAIgNT9L2D4qGp4e
                                                                                                                                                                                                                                  MD5:4F5159996C16A171D9B011C79FDDBF63
                                                                                                                                                                                                                                  SHA1:51BCA6487762E42528C845CCA33173B3ED707B3F
                                                                                                                                                                                                                                  SHA-256:E73ADC4283ECA7D8504ABC6CB28D98EB071ED867F77DE9FADA777181533AD1D0
                                                                                                                                                                                                                                  SHA-512:6E5D4DF903968395DFDB834FBD4B2A0294E945A9939D05BED8533674EA0ACE8393731DDCDFACF7F2C9A00D38DC8F5EDB173B4025CF05122B0927829D07ED203F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Brazzaville) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.900915013374923
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsfKGyVAIgNGEjKKW62DclbDcfKu:SlSWB9IZaM3y7fYVAIgNTj5W62DkbDE/
                                                                                                                                                                                                                                  MD5:9E81B383C593422481B5066CF23B8CE1
                                                                                                                                                                                                                                  SHA1:8DD0408272CBE6DF1D5051CB4D9319B5A1BD770E
                                                                                                                                                                                                                                  SHA-256:9ADCD7CB6309049979ABF8D128C1D1BA35A02F405DB8DA8C39D474E8FA675E38
                                                                                                                                                                                                                                  SHA-512:9939ED703EC26350DE9CC59BF7A8C76B6B3FE3C67E47CCDDE86D87870711224ADEEC61D93AC7926905351B8333AD01FF235276A5AB766474B5884F8A0329C2CB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Maputo)]} {. LoadTimeZoneFile Africa/Maputo.}.set TZData(:Africa/Bujumbura) $TZData(:Africa/Maputo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3720
                                                                                                                                                                                                                                  Entropy (8bit):3.687670811431724
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5hRg1oCSY0WF6yU0yWZVYbZ0F0ZeTvc0jDlSBFX84aKqITVuV09ONWHr0L0335Kw:Fu0oVy0FUeLIvQV8c0OvOakCUUO
                                                                                                                                                                                                                                  MD5:1B38D083FC54E17D82935D400051F571
                                                                                                                                                                                                                                  SHA1:AE34C08176094F4C4BFEB4E1BBAE6034BCD03A11
                                                                                                                                                                                                                                  SHA-256:11283B69DE0D02EAB1ECF78392E3A4B32288CCFEF946F0432EC83327A51AEDDC
                                                                                                                                                                                                                                  SHA-512:581161079EC0F77EEB119C96879FD586AE49997BAD2C5124C360BCACF9136FF0A6AD70AE7D4C88F96BC94EEB87F628E8890E65DB9B0C96017659058D35436307
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Cairo) {. {-9223372036854775808 7509 0 LMT}. {-2185409109 7200 0 EET}. {-929844000 10800 1 EEST}. {-923108400 7200 0 EET}. {-906170400 10800 1 EEST}. {-892868400 7200 0 EET}. {-875844000 10800 1 EEST}. {-857790000 7200 0 EET}. {-844308000 10800 1 EEST}. {-825822000 7200 0 EET}. {-812685600 10800 1 EEST}. {-794199600 7200 0 EET}. {-779853600 10800 1 EEST}. {-762663600 7200 0 EET}. {-399088800 10800 1 EEST}. {-386650800 7200 0 EET}. {-368330400 10800 1 EEST}. {-355114800 7200 0 EET}. {-336790800 10800 1 EEST}. {-323654400 7200 0 EET}. {-305168400 10800 1 EEST}. {-292032000 7200 0 EET}. {-273632400 10800 1 EEST}. {-260496000 7200 0 EET}. {-242096400 10800 1 EEST}. {-228960000 7200 0 EET}. {-210560400 10800 1 EEST}. {-197424000 7200 0 EET}. {-178938000 10800 1 EEST}. {-165801600 7200 0 EET}. {-147402000 10800 1 EEST}. {-134265600 72
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1567
                                                                                                                                                                                                                                  Entropy (8bit):3.593430930151928
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5qSFbS4PUuMfMSAdZXfSGjX6JAzS26WZrW0SKQYXRWXpSjv:YmG0HZPcOQy1p
                                                                                                                                                                                                                                  MD5:9DB3A6EB1162C5D814B98265FB58D004
                                                                                                                                                                                                                                  SHA1:63ACAD6C18B49EF6794610ADED9865C8600A4D5C
                                                                                                                                                                                                                                  SHA-256:EF30CFFD1285339F4CC1B655CB4CB8C5D864C4B575D66F18919A35C084AA4E5F
                                                                                                                                                                                                                                  SHA-512:0581F6640BDDD8C33E82983F2186EB0952946C70A4B3F524EC78D1BE3EC1FA10BC3672A99CBA3475B28C0798D62A14F298207160F04EE0861EDDA352DA2BCCA0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Casablanca) {. {-9223372036854775808 -1820 0 LMT}. {-1773012580 0 0 +00}. {-956361600 3600 1 +00}. {-950490000 0 0 +00}. {-942019200 3600 1 +00}. {-761187600 0 0 +00}. {-617241600 3600 1 +00}. {-605149200 0 0 +00}. {-81432000 3600 1 +00}. {-71110800 0 0 +00}. {141264000 3600 1 +00}. {147222000 0 0 +00}. {199756800 3600 1 +00}. {207702000 0 0 +00}. {231292800 3600 1 +00}. {244249200 0 0 +00}. {265507200 3600 1 +00}. {271033200 0 0 +00}. {448243200 3600 0 +01}. {504918000 0 0 +00}. {1212278400 3600 1 +00}. {1220223600 0 0 +00}. {1243814400 3600 1 +00}. {1250809200 0 0 +00}. {1272758400 3600 1 +00}. {1281222000 0 0 +00}. {1301788800 3600 1 +00}. {1312066800 0 0 +00}. {1335664800 3600 1 +00}. {1342749600 0 0 +00}. {1345428000 3600 1 +00}. {1348970400 0 0 +00}. {1367114400 3600 1 +00}. {1373162400 0 0 +00}. {1376100000 3600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.800219030063992
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2DcnKe2DcGev:SlSWB9IZaM3y7V4FVAIgNT9L2Dml2D4v
                                                                                                                                                                                                                                  MD5:18C0C9E9D5154E20CC9301D5012066B9
                                                                                                                                                                                                                                  SHA1:8395E917261467EC5C27034C980EDD05F2242F40
                                                                                                                                                                                                                                  SHA-256:0595C402B8499FC1B67C196BEE24BCA4DE14D3E10B8DBBD2840D2B4C88D9DF28
                                                                                                                                                                                                                                  SHA-512:C53540E25B76DF8EC3E2A5F27B473F1D6615BFBD043E133867F3391B057D8552350F912DF55DD11C1357765EF76D8E286BBBE839F28295D09751243DC0201BDF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Douala) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1281
                                                                                                                                                                                                                                  Entropy (8bit):3.6551425401331312
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQbe5T7pkNUSMSA7ZXgUSGjX6JAWqS26WZrW0SKQYJZRWXpSjv:5opMfMSA7ZXfSGjX6JAzS26WZrW0SKQm
                                                                                                                                                                                                                                  MD5:8E9FF3CB18879B1C69A04F45715D24BB
                                                                                                                                                                                                                                  SHA1:EF391BF1C3E1DEC08D8158B82B2FB0ED3E69866E
                                                                                                                                                                                                                                  SHA-256:A6CFC4359B7E2D650B1851D805FF5CD4562D0D1253793EA0978819B9A2FCC0E2
                                                                                                                                                                                                                                  SHA-512:6BFF03EE8973E2204181967987930EECDD39789DB353DB2EFC786027A8013CFF4835FAB9E3F0AF935D2A2D49CCEBE565FD481BA230EDF4D22A7848D4781C877C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/El_Aaiun) {. {-9223372036854775808 -3168 0 LMT}. {-1136070432 -3600 0 -01}. {198291600 0 0 +00}. {199756800 3600 1 +00}. {207702000 0 0 +00}. {231292800 3600 1 +00}. {244249200 0 0 +00}. {265507200 3600 1 +00}. {271033200 0 0 +00}. {1212278400 3600 1 +00}. {1220223600 0 0 +00}. {1243814400 3600 1 +00}. {1250809200 0 0 +00}. {1272758400 3600 1 +00}. {1281222000 0 0 +00}. {1301788800 3600 1 +00}. {1312066800 0 0 +00}. {1335664800 3600 1 +00}. {1342749600 0 0 +00}. {1345428000 3600 1 +00}. {1348970400 0 0 +00}. {1367114400 3600 1 +00}. {1373162400 0 0 +00}. {1376100000 3600 1 +00}. {1382839200 0 0 +00}. {1396144800 3600 1 +00}. {1403920800 0 0 +00}. {1406944800 3600 1 +00}. {1414288800 0 0 +00}. {1427594400 3600 1 +00}. {1434247200 0 0 +00}. {1437271200 3600 1 +00}. {1445738400 0 0 +00}. {1459044000 3600 1 +00}. {146509200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.817633094200984
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2Dcu5sp4DcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2Dk4DBP
                                                                                                                                                                                                                                  MD5:035B36DF91F67179C8696158F58D0CE8
                                                                                                                                                                                                                                  SHA1:E43BFF33090324110048AC19CBA16C4ED8D8B3FE
                                                                                                                                                                                                                                  SHA-256:3101942D9F3B2E852C1D1EA7ED85826AB9EA0F8953B9A0E6BAC32818A2EC9EDD
                                                                                                                                                                                                                                  SHA-512:A7B52154C6085E5D234D6D658BA48D2C8EC093A429C3907BE7D16654F6EE9EBE8E3100187650956E5164B18340AB0C0979C1F4FA90EFE0CC423FBA5F14F45215
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Africa/Freetown) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.8512443534123255
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsfKGyVAIgNGEjKKW62DcHK0o/4DcfKu:SlSWB9IZaM3y7fYVAIgNTj5W62DAV+4G
                                                                                                                                                                                                                                  MD5:BA2C7443CFCB3E29DB84FEC16B3B3843
                                                                                                                                                                                                                                  SHA1:2BA7D68C48A79000B1C27588A20A751AA04C5779
                                                                                                                                                                                                                                  SHA-256:28C1453496C2604AA5C42A88A060157BDFE22F28EDD1FBC7CC63B02324ED8445
                                                                                                                                                                                                                                  SHA-512:B275ABAADA7352D303EFEAD66D897BE3099A33B80EA849F9F1D98D522AA9A3DC44E1D979C0ABF2D7886BACF2F86D25837C971ECE6B2AF731BE2EE0363939CBDE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Maputo)]} {. LoadTimeZoneFile Africa/Maputo.}.set TZData(:Africa/Gaborone) $TZData(:Africa/Maputo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.835896095919456
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsfKGyVAIgNGEjKKW62Dc0B5h4DcfKu:SlSWB9IZaM3y7fYVAIgNTj5W62Dlfh4G
                                                                                                                                                                                                                                  MD5:59137CFDB8E4B48599FB417E0D8A4A70
                                                                                                                                                                                                                                  SHA1:F13F9932C0445911E395377FB51B859E4F72862A
                                                                                                                                                                                                                                  SHA-256:E633C6B619782DA7C21D548E06E6C46A845033936346506EA0F2D4CCCDA46028
                                                                                                                                                                                                                                  SHA-512:2DCEB9A9FA59512ADCDE4946F055718A8C8236A912F6D521087FC348D52FFF462B5712633FDA5505876C500F5FD472381B3AC90CF1AEDF0C96EA08E0A0D3B7BA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Maputo)]} {. LoadTimeZoneFile Africa/Maputo.}.set TZData(:Africa/Harare) $TZData(:Africa/Maputo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):298
                                                                                                                                                                                                                                  Entropy (8bit):4.638948195674004
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52DWbAm2OHePP1mXs0//HF20706VcF206KsF:MBp52DWkmdHePP1mcUvFxJVcFEKsF
                                                                                                                                                                                                                                  MD5:256740512DCB35B4743D05CC24C636DB
                                                                                                                                                                                                                                  SHA1:1FD418712B3D7191549BC0808CF180A682AF7FC1
                                                                                                                                                                                                                                  SHA-256:768E9B2D9BE96295C35120414522FA6DD3EDA4500FE86B6D398AD452CAF6FA4B
                                                                                                                                                                                                                                  SHA-512:DCFF6C02D1328297BE24E0A640F5823BFD23BDE67047671AC18EB0B1F450C717E273B27A48857F54A18D6877AB8132AAED94B2D87D2F962DA43FE473FC3DDC94
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Johannesburg) {. {-9223372036854775808 6720 0 LMT}. {-2458173120 5400 0 SAST}. {-2109288600 7200 0 SAST}. {-860976000 10800 1 SAST}. {-845254800 7200 0 SAST}. {-829526400 10800 1 SAST}. {-813805200 7200 0 SAST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1059
                                                                                                                                                                                                                                  Entropy (8bit):3.9545766161038602
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQresZkn0Vb0iluy8pLXeKXhCvN9U0TlW50qCPR8jYJRFp0Q8SdAri/8+u8Wb2:5on010ilux1XeKXhCvN9U0TMGqCp8jYH
                                                                                                                                                                                                                                  MD5:79FCA072C6AABA65FB2DC83F33BFA17E
                                                                                                                                                                                                                                  SHA1:AC86AA9B0EAACAB1E4FDB14AECD8D884F8329A5A
                                                                                                                                                                                                                                  SHA-256:C084565CC6C217147C00DCA7D885AC917CFC8AF4A33CBA146F28586AD6F9832C
                                                                                                                                                                                                                                  SHA-512:9F19DEA8E21CE3D3DCA0AFC5588203DBB6F5A13BBE10CFDA0CEBE4A417384B85DB3BFFC48687EF7AD27268715FC154E235C106EC91875BA646C6759D285F1027
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Juba) {. {-9223372036854775808 7588 0 LMT}. {-1230775588 7200 0 CAT}. {10360800 10800 1 CAST}. {24786000 7200 0 CAT}. {41810400 10800 1 CAST}. {56322000 7200 0 CAT}. {73432800 10800 1 CAST}. {87944400 7200 0 CAT}. {104882400 10800 1 CAST}. {119480400 7200 0 CAT}. {136332000 10800 1 CAST}. {151016400 7200 0 CAT}. {167781600 10800 1 CAST}. {182552400 7200 0 CAT}. {199231200 10800 1 CAST}. {214174800 7200 0 CAT}. {230680800 10800 1 CAST}. {245710800 7200 0 CAT}. {262735200 10800 1 CAST}. {277246800 7200 0 CAT}. {294184800 10800 1 CAST}. {308782800 7200 0 CAT}. {325634400 10800 1 CAST}. {340405200 7200 0 CAT}. {357084000 10800 1 CAST}. {371941200 7200 0 CAT}. {388533600 10800 1 CAST}. {403477200 7200 0 CAT}. {419983200 10800 1 CAST}. {435013200 7200 0 CAT}. {452037600 10800 1 CAST}. {466635600 7200 0 CAT}. {483487200 10800 1 CAST
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):180
                                                                                                                                                                                                                                  Entropy (8bit):4.787605387034664
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt2DcJEl2DcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL2DIEl2Dkr
                                                                                                                                                                                                                                  MD5:8CF1CA04CD5FC03D3D96DC49E98D42D4
                                                                                                                                                                                                                                  SHA1:4D326475E9216089C872D5716C54DEB94590FCDE
                                                                                                                                                                                                                                  SHA-256:A166E17E3A4AB7C5B2425A17F905484EBFDBA971F88A221155BCA1EC5D28EA96
                                                                                                                                                                                                                                  SHA-512:1301B9469ED396198A2B87CBA254C66B148036C0117D7D4A8286CB8729296AD735DF16581AEF0715CEE24213E91970F181824F3A64BCF91435FDAD85DCD78C84
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Africa/Kampala) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1091
                                                                                                                                                                                                                                  Entropy (8bit):3.9616554773567083
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQWe9hXn0Vb0iluy8pLXeKXhCvN9U0TlW50qCPR8jYJRFp0Q8SdAri/8+u8WbVgM:5vn010ilux1XeKXhCvN9U0TMGqCp8jYs
                                                                                                                                                                                                                                  MD5:A00B0C499DE60158C9990CFE9628FEA4
                                                                                                                                                                                                                                  SHA1:44B768C63E170331396B4B81ABF0E3EDD8B0D864
                                                                                                                                                                                                                                  SHA-256:FCFF440D525F3493447C0ACFE32BB1E8BCDF3F1A20ADC3E0F5D2B245E2DB10E9
                                                                                                                                                                                                                                  SHA-512:30BF22857AA4C26FC6178C950AB6EAB472F2AC77D2D8EB3A209DCDEF2DDC8312B0AB6DA3428936CA16225ABE652DDB8536D870DB1905027AD7BD7FF245871556
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Khartoum) {. {-9223372036854775808 7808 0 LMT}. {-1230775808 7200 0 CAT}. {10360800 10800 1 CAST}. {24786000 7200 0 CAT}. {41810400 10800 1 CAST}. {56322000 7200 0 CAT}. {73432800 10800 1 CAST}. {87944400 7200 0 CAT}. {104882400 10800 1 CAST}. {119480400 7200 0 CAT}. {136332000 10800 1 CAST}. {151016400 7200 0 CAT}. {167781600 10800 1 CAST}. {182552400 7200 0 CAT}. {199231200 10800 1 CAST}. {214174800 7200 0 CAT}. {230680800 10800 1 CAST}. {245710800 7200 0 CAT}. {262735200 10800 1 CAST}. {277246800 7200 0 CAT}. {294184800 10800 1 CAST}. {308782800 7200 0 CAT}. {325634400 10800 1 CAST}. {340405200 7200 0 CAT}. {357084000 10800 1 CAST}. {371941200 7200 0 CAT}. {388533600 10800 1 CAST}. {403477200 7200 0 CAT}. {419983200 10800 1 CAST}. {435013200 7200 0 CAT}. {452037600 10800 1 CAST}. {466635600 7200 0 CAT}. {483487200 10800 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.8623059127375585
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsfKGyVAIgNGEjKKW62DcCJRx+DcfKu:SlSWB9IZaM3y7fYVAIgNTj5W62DRX+Da
                                                                                                                                                                                                                                  MD5:32AE0D7A7E7F0DF7AD0054E959A53B09
                                                                                                                                                                                                                                  SHA1:AE455C96401EBB1B2BDE5674A71A182D9E12D7BD
                                                                                                                                                                                                                                  SHA-256:7273FA039D250CABAE2ACCE926AB483B0BF16B0D77B9C2A7B499B9BDFB9E1CBB
                                                                                                                                                                                                                                  SHA-512:DC8E89A75D7212D398A253E6FF3D10AF72B7E14CBC07CA53C6CB01C8CE40FB12375E50AD4291C973C872566F8D875D1E1A2CF0A38F02C91355B957095004563E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Maputo)]} {. LoadTimeZoneFile Africa/Maputo.}.set TZData(:Africa/Kigali) $TZData(:Africa/Maputo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.816805447465336
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2DcqQFeDcGev:SlSWB9IZaM3y7V4FVAIgNT9L2DdD4v
                                                                                                                                                                                                                                  MD5:90EC372D6C8677249C8C2841432F0FB7
                                                                                                                                                                                                                                  SHA1:5D5E549496962420F56897BC01887B09EC863D78
                                                                                                                                                                                                                                  SHA-256:56F7CA006294049FA92704EDEAD78669C1E9EABE007C41F722E972BE2FD58A37
                                                                                                                                                                                                                                  SHA-512:93FD7C8F5C6527DCCFBF21043AB5EED21862A22DA1FDB3ED7635723060C9252D76541DAD3A76EBF8C581A82A6DBEF2766DD428ACE3A9D6A45954A787B686B1CA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Kinshasa) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):141
                                                                                                                                                                                                                                  Entropy (8bit):4.965079502032549
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52DcGemFFkXGm2OHWTdvUQDWTFWZRYvCn:SlSWB9X52D4mFJm2OHWTdRDWTGRLn
                                                                                                                                                                                                                                  MD5:51D7AC832AE95CFDE6098FFA6FA2B1C7
                                                                                                                                                                                                                                  SHA1:9DA61FDA03B4EFDA7ACC3F83E8AB9495706CCEF1
                                                                                                                                                                                                                                  SHA-256:EEDA5B96968552C12B916B39217005BF773A99CA17996893BC87BCC09966B954
                                                                                                                                                                                                                                  SHA-512:128C8D3A0AA7CF4DFAE326253F236058115028474BF122F14AB9461D910A03252FEEB420014CA91ACFBF94DF05FBFCADE98217FC59A86A2581BB68CDC83E88C8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Lagos) {. {-9223372036854775808 816 0 LMT}. {-1588464816 3600 0 WAT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.816649832558406
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2Dcr7bp4DcGev:SlSWB9IZaM3y7V4FVAIgNT9L2Dgfp4Di
                                                                                                                                                                                                                                  MD5:D1387B464CFCFE6CB2E10BA82D4EEE0E
                                                                                                                                                                                                                                  SHA1:F672B694551AB4228D4FC938D0CC2DA635EB8878
                                                                                                                                                                                                                                  SHA-256:BEE63E4DF9D03D2F5E4100D0FCF4E6D555173083A4470540D4ADC848B788A2FC
                                                                                                                                                                                                                                  SHA-512:DEB95AAB852772253B60F83DA9CE5E24144386DFBFB1F1E9A77905511181EC84FD13B00200602D6C276820527206EE0078DDE81CC0F1B1276B8BF4360C2CDB1E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Libreville) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.813464796454866
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2Dcih4DcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2DNh4DB
                                                                                                                                                                                                                                  MD5:D2AA823E78DD8E0A0C83508B6378DE5D
                                                                                                                                                                                                                                  SHA1:C26E03EF84C3C0B6001F0D4471907A94154E6850
                                                                                                                                                                                                                                  SHA-256:345F3F9422981CC1591FBC1B5B17A96F2F00F0C191DF23582328D44158041CF0
                                                                                                                                                                                                                                  SHA-512:908F8D096DA6A336703E7601D03477CECBCDC8D404C2410C7F419986379A14943BB61B0D92D87160D5F1EF5B229971B2B9D122D2B3F70746CED0D4D6B10D7412
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Africa/Lome) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.807298951345495
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2DccLtBQDcGev:SlSWB9IZaM3y7V4FVAIgNT9L2DXQD4v
                                                                                                                                                                                                                                  MD5:E851465BCA70F325B0B07E782D6A759E
                                                                                                                                                                                                                                  SHA1:3B3E0F3FD7AF99F941A3C70A2A2564C9301C8CFB
                                                                                                                                                                                                                                  SHA-256:F7E1DCBAE881B199F2E2BF18754E145DDED230518C691E7CB34DAE3C922A6063
                                                                                                                                                                                                                                  SHA-512:5F655B45D7A16213CE911EDAD935C1FEE7A947C0F5157CE20712A00B2A12A34AE51D5C05A392D2FF3A0B2DA7787D6C614FF100DDE7788CA01AAE21F10DD1CC3A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Luanda) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):180
                                                                                                                                                                                                                                  Entropy (8bit):4.893308860167744
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsfKGyVAIgNGEjKKW62DcfpT0DcfKu:SlSWB9IZaM3y7fYVAIgNTj5W62D8pT0G
                                                                                                                                                                                                                                  MD5:CD638B7929FB8C474293D5ECF1FE94D3
                                                                                                                                                                                                                                  SHA1:149AD0F3CF8AC1795E84B97CFF5CEB1FD26449C4
                                                                                                                                                                                                                                  SHA-256:41D32824F28AE235661EE0C959E0F555C44E3E78604D6D2809BBA2254FD47258
                                                                                                                                                                                                                                  SHA-512:D762C49B13961A01526C0DD9D7A55E202448E1B46BA64F701FB2E0ABE0F44B2C3DF743864B9E62DC07FD6CEA7197945CE246C89CDACB1FEC0F924F3ECC46B170
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Maputo)]} {. LoadTimeZoneFile Africa/Maputo.}.set TZData(:Africa/Lubumbashi) $TZData(:Africa/Maputo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.857012096036922
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsfKGyVAIgNGEjKKW62DcOf+DcfKu:SlSWB9IZaM3y7fYVAIgNTj5W62DkDE/
                                                                                                                                                                                                                                  MD5:3769866ADC24DA6F46996E43079C3545
                                                                                                                                                                                                                                  SHA1:546FA9C76A1AE5C6763B31FC7214B8A2B18C3C52
                                                                                                                                                                                                                                  SHA-256:5BAF390EA1CE95227F586423523377BABD141F0B5D4C31C6641E59C6E29FFAE0
                                                                                                                                                                                                                                  SHA-512:DEA8CAB330F6321AD9444DB9FEC58E2CBCC79404B9E5539EABB52DBC9C3AC01BA1E8A3E1EC32906F02E4E4744271D84B626A5C32A8CD8B22210C42DD0E774A9C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Maputo)]} {. LoadTimeZoneFile Africa/Maputo.}.set TZData(:Africa/Lusaka) $TZData(:Africa/Maputo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.807416212132411
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2Dcn2DcGev:SlSWB9IZaM3y7V4FVAIgNT9L2D42D4v
                                                                                                                                                                                                                                  MD5:37C13E1D11C817BA70DDC84E768F8891
                                                                                                                                                                                                                                  SHA1:0765A45CC37EB71F4A5D2B8D3359AEE554C647FF
                                                                                                                                                                                                                                  SHA-256:8F4F0E1C85A33E80BF7C04CF7E0574A1D829141CC949D2E38BDCC174337C5BAE
                                                                                                                                                                                                                                  SHA-512:1E31BBA68E85A8603FBDD27DA68382CBC6B0E1AB0763E86516D3EFD15CFF106DE02812756F504AEE799BF6742423DF5732352D488B3F05B889BE5E48594F558D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Malabo) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):143
                                                                                                                                                                                                                                  Entropy (8bit):4.906945970372021
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52DcfKUXGm2OHoVvXdSF2iv:SlSWB9X52DESm2OHoVPdM
                                                                                                                                                                                                                                  MD5:5497C01E507E7C392944946FCD984852
                                                                                                                                                                                                                                  SHA1:4C3FD215E931CE36FF095DD9D23165340D6EECFE
                                                                                                                                                                                                                                  SHA-256:C87A6E7B3B84CFFA4856C4B6C37C5C8BA5BBB339BDDCD9D2FD34CF17E5553F5D
                                                                                                                                                                                                                                  SHA-512:83A2AA0ED1EB22056FFD3A847FB63DD09302DA213FE3AB660C41229795012035B5EA64A3236D3871285A8E271458C2DA6FCD599E5747F2F842E742C11222671A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Maputo) {. {-9223372036854775808 7820 0 LMT}. {-2109291020 7200 0 CAT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):194
                                                                                                                                                                                                                                  Entropy (8bit):4.91873415322653
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7HbsvFVAIgNTzbDJL2DZQs+DWbBn:MBaIMaHw4NHnJL2DZiDWt
                                                                                                                                                                                                                                  MD5:71A4197C8062BBFCCC62DCEFA87A25F9
                                                                                                                                                                                                                                  SHA1:7490FAA5A0F5F20F456E71CBF51AA6DEB1F1ACC8
                                                                                                                                                                                                                                  SHA-256:4B33414E2B59E07028E9742FA4AE34D28C08FD074DDC6084EDB1DD179198B3C1
                                                                                                                                                                                                                                  SHA-512:A71CCB957FB5102D493320F48C94ADB642CCAA5F7F28BDDE05D1BB175C29BCBAC4D19DBC481AC0C80CE48F8E3840746C126CBC9CE511CA48D4E53DE22B3D66E7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Johannesburg)]} {. LoadTimeZoneFile Africa/Johannesburg.}.set TZData(:Africa/Maseru) $TZData(:Africa/Johannesburg).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):195
                                                                                                                                                                                                                                  Entropy (8bit):4.911369740193625
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7HbsvFVAIgNTzbDJL2DzjEHp4DWbBn:MBaIMaHw4NHnJL2DzjEJ4DWt
                                                                                                                                                                                                                                  MD5:8F4C02CE326FAEEBD926F94B693BFF9E
                                                                                                                                                                                                                                  SHA1:9E8ABB12E4CFE341F24F5B050C75DDE3D8D0CB53
                                                                                                                                                                                                                                  SHA-256:029AD8C75A779AED71FD233263643DADE6DF878530C47CF140FC8B7755DDA616
                                                                                                                                                                                                                                  SHA-512:4B7D2D1D8DA876ABCD1E44FD5E4C992287F2B62B7C7BC3D6FD353E6312053F6762DBD11C0F27056EF8E37C8A2AF8E5111CF09D4EB6BB32EC1FF77F4C0C37917B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Johannesburg)]} {. LoadTimeZoneFile Africa/Johannesburg.}.set TZData(:Africa/Mbabane) $TZData(:Africa/Johannesburg).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):182
                                                                                                                                                                                                                                  Entropy (8bit):4.828470940863702
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt2DcBEBXCEeDcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL2DFSVDkr
                                                                                                                                                                                                                                  MD5:B686E9408AB6EC58F3301D954A068C7E
                                                                                                                                                                                                                                  SHA1:C1259C31F93EB776F0F401920F076F162F3FFB2D
                                                                                                                                                                                                                                  SHA-256:79DB89294DAE09C215B9F71C61906E49AFAA5F5F27B4BC5B065992A45B2C183D
                                                                                                                                                                                                                                  SHA-512:CF96C687D33E68EB498A63EC262FC968858504410F670C6F492532F7C22F507BEACD41888B0A7527C30974DC545CCA9C015898E2D7C0C6D14C14C88F8BBED5C5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Africa/Mogadishu) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):200
                                                                                                                                                                                                                                  Entropy (8bit):4.81604007062907
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52D3NwTm2OHrFGxYPlHIgafTwG5B:MBp52D3NwTmdHhmYPdIgar5B
                                                                                                                                                                                                                                  MD5:8F9D1916FF86E2F8C5C9D4ABCC405D53
                                                                                                                                                                                                                                  SHA1:286BFEC8F7CE6729F84FD6CFEE6A40B7277A4DFF
                                                                                                                                                                                                                                  SHA-256:182F2608422FF14C53DC8AC1EDFFE054AE011275C1B5C2423E286AD95910F44C
                                                                                                                                                                                                                                  SHA-512:7EEF6840E54313EF1127694F550986BF97BB1C8BD51DED0AB6D5842B74B5BF0406C65B293F1106E69DDFA0B01AD46756492DEDD9ECCBD077BB75FDA95A9E1912
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Monrovia) {. {-9223372036854775808 -2588 0 LMT}. {-2776979812 -2588 0 MMT}. {-1604359012 -2670 0 MMT}. {63593070 0 0 GMT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):235
                                                                                                                                                                                                                                  Entropy (8bit):4.70181156382821
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52DkWJm2OHsvT5X26V/7VVpVCgekKB9TQ4U/w:MBp52DdJmdHsvVXHVVnmQ4U/w
                                                                                                                                                                                                                                  MD5:B6562D5A53E05FAAD80671C88A9E01D3
                                                                                                                                                                                                                                  SHA1:0014B14CFDDE47E603962935F8297C4C46533084
                                                                                                                                                                                                                                  SHA-256:726980DCC13E0596094E01B8377E17029A2FCCE6FE93538C61E61BA620DD0971
                                                                                                                                                                                                                                  SHA-512:D9C2838C89B0537C7F7A7319600D69D09AC004BD72358B452425A3B4861140246F71A94F004C2EF739620E81062F37ED9DA6D518F74956630006DD5674925A63
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Nairobi) {. {-9223372036854775808 8836 0 LMT}. {-1309746436 10800 0 EAT}. {-1262314800 9000 0 +0230}. {-946780200 9900 0 +0245}. {-315629100 10800 0 EAT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):200
                                                                                                                                                                                                                                  Entropy (8bit):4.8064239600480985
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52DjXm2OHNseVaxCXGFaS1HkFWTvLn:MBp52DjXmdHPVX8aS2yzn
                                                                                                                                                                                                                                  MD5:459DA3ECBE5C32019D1130DDEAB10BAA
                                                                                                                                                                                                                                  SHA1:DD1F6653A7B7B091A57EC59E271197CEC1892594
                                                                                                                                                                                                                                  SHA-256:F36F8581755E1B40084442C43C60CC904C908285C4D719708F2CF1EADB778E2E
                                                                                                                                                                                                                                  SHA-512:FF74D540157DE358E657E968C9C040B8FE5C806D22782D878575BFAC68779303E6071DC84D6773BC06D299AC971B0EB6B38CA50439161574B5A50FF6F1704046
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Ndjamena) {. {-9223372036854775808 3612 0 LMT}. {-1830387612 3600 0 WAT}. {308703600 7200 1 WAST}. {321314400 3600 0 WAT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.822255424633636
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2DcdhA9Ff2DcGev:SlSWB9IZaM3y7V4FVAIgNT9L2Dsh2f2e
                                                                                                                                                                                                                                  MD5:3142A6EAC3F36C872E7C32F8AF43A0F8
                                                                                                                                                                                                                                  SHA1:0EACF849944A55D4AB8198DDD0D3C5494D1986DA
                                                                                                                                                                                                                                  SHA-256:1704A1A82212E6DB71DA54E799D81EFA3279CD53A6BFA980625EE11126603B4C
                                                                                                                                                                                                                                  SHA-512:BB3DADC393D0CF87934629BBFAFAD3AD9149B80843FC5447670812357CC4DFBCAF71F7104EBF743C06517BB42111B0DB9028B22F401A50E17085431C9200DAB2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Niamey) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):183
                                                                                                                                                                                                                                  Entropy (8bit):4.862257004762335
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2DcboGb+DcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2Dqbb+V
                                                                                                                                                                                                                                  MD5:6849FA8FFC1228286B08CE0950FEB4DD
                                                                                                                                                                                                                                  SHA1:7F8E8069BA31E2E549566011053DA01DEC5444E9
                                                                                                                                                                                                                                  SHA-256:2071F744BC880E61B653E2D84CED96D0AD2485691DDE9FFD38D3063B91E4F41F
                                                                                                                                                                                                                                  SHA-512:30211297C2D8255D4B5195E9781931861A4DF55C431FFC6F83FE9C00A0089ED56179C07D33B1376C5DE8C0A9ABF2CFE473EF32AD14239DFD9599EA66BC286556
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Africa/Nouakchott) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.872638989714255
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2DcXCZDcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2D1DBP
                                                                                                                                                                                                                                  MD5:7FF39BAAF47859EE3CD60F3E2C6DFC7D
                                                                                                                                                                                                                                  SHA1:5CFC8B14222554156985031C7E9507CE3311F371
                                                                                                                                                                                                                                  SHA-256:47E40BDBAC36CDB847C2E533B9D58D09FE1DBA2BED49C49BC75DD9086A63C6EB
                                                                                                                                                                                                                                  SHA-512:DEEA0982593AE7757E70BD2E933B20B65CD9613891DC734AA4E6EC14D12AD119D2C69BA38E6FA4AE836C6CE14E57F35AE7F53345ACA4CF70AD67680E49BC6B7C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Africa/Ouagadougou) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.845403930433216
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsGe4FVAIgNGESIRL2DcyTKM0DcGev:SlSWB9IZaM3y7V4FVAIgNT9L2DQD4v
                                                                                                                                                                                                                                  MD5:9A4C8187E8AC86B1CF4177702A2D933A
                                                                                                                                                                                                                                  SHA1:6B54BBBE6D7ABC780EE11922F3AC50CDE3740A1F
                                                                                                                                                                                                                                  SHA-256:6292CC41FE34D465E3F38552BDE22F456E16ABCBAC0E0B813AE7566DF3725E83
                                                                                                                                                                                                                                  SHA-512:8008DB5E6F4F8144456021BB6B112B24ADB1194B1D544BBCB3E101E0684B63F4673F06A264C651A4BC0296CB81F7B4D73D47EAC7E1EC98468908E8B0086B2DDD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Lagos)]} {. LoadTimeZoneFile Africa/Lagos.}.set TZData(:Africa/Porto-Novo) $TZData(:Africa/Lagos).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):200
                                                                                                                                                                                                                                  Entropy (8bit):4.8463501042309645
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52DcOFwFkXGm2OHzT5vXbeaFnvUdSa5FF1IEvWZvZYvCn:SlSWB9X52DIJm2OHH5PzdVacbLn
                                                                                                                                                                                                                                  MD5:D28C0D0628DE3E5D9662A3376B20D5B4
                                                                                                                                                                                                                                  SHA1:464351F257655F10732CA9A1E59CF6587B33F8A1
                                                                                                                                                                                                                                  SHA-256:B9F317EAA504A195BD658BA7EE9EE22D816BF46A1FFDB8D8DA573D311A5FF78A
                                                                                                                                                                                                                                  SHA-512:B056E7A16CE8E5CC420F88AF26E893348117306D66ED2DF4C6A6C2CA9F48783714E08AACF94BC646A1B4A2B3FB2080A4E53EDF4633C9AE259BBBA3F8ABE4DEE3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Sao_Tome) {. {-9223372036854775808 1616 0 LMT}. {-2713912016 -2205 0 LMT}. {-1830384000 0 0 GMT}. {1514768400 3600 0 WAT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.85737401659099
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2DcHdDcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2DwdDBP
                                                                                                                                                                                                                                  MD5:AF295B9595965712D77952D692F02C6B
                                                                                                                                                                                                                                  SHA1:BC6737BD9BFD52FE538376A1441C59FB4FC1A038
                                                                                                                                                                                                                                  SHA-256:13A06D69AEB38D7A2D35DF3802CEE1A6E15FA1F5A6648328A9584DD55D11E58C
                                                                                                                                                                                                                                  SHA-512:E47C5EA2DFBC22CF9EAC865F67D01F5593D3CDDB51FDE24CDD13C8957B70F50111675D8E94CA859EC9B6FAA109B3EFA522C3985A69FE5334156FEE66B607006E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Africa/Timbuktu) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):920
                                                                                                                                                                                                                                  Entropy (8bit):4.074538534246205
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52D0mdHrjWC+fGZni8hRSUNvoTC3yJ/Z9vPdq8UwLVFoBZdEthEK7st5kS1R:cQIevhR5FNgTbJ3b3D0WeXR
                                                                                                                                                                                                                                  MD5:A53F5CD6FE7C2BDD8091E38F26EEA4D1
                                                                                                                                                                                                                                  SHA1:90FB5EE343FCC78173F88CA59B35126CC8C07447
                                                                                                                                                                                                                                  SHA-256:D2FCC1AD3BFE20954795F2CDFFFE96B483E1A82640B79ADAA6062B96D143E3C7
                                                                                                                                                                                                                                  SHA-512:965E42972994AE79C9144323F87C904F393BA0CDF75186C346DA77CFAA1A2868C68AF8F2F1D63D5F06C5D1D4B96BA724DD4BC0DF7F5C4BD77E379AA674AE12DA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Tripoli) {. {-9223372036854775808 3164 0 LMT}. {-1577926364 3600 0 CET}. {-574902000 7200 1 CEST}. {-512175600 7200 1 CEST}. {-449888400 7200 1 CEST}. {-347158800 7200 0 EET}. {378684000 3600 0 CET}. {386463600 7200 1 CEST}. {402271200 3600 0 CET}. {417999600 7200 1 CEST}. {433807200 3600 0 CET}. {449622000 7200 1 CEST}. {465429600 3600 0 CET}. {481590000 7200 1 CEST}. {496965600 3600 0 CET}. {512953200 7200 1 CEST}. {528674400 3600 0 CET}. {544230000 7200 1 CEST}. {560037600 3600 0 CET}. {575852400 7200 1 CEST}. {591660000 3600 0 CET}. {607388400 7200 1 CEST}. {623196000 3600 0 CET}. {641775600 7200 0 EET}. {844034400 3600 0 CET}. {860108400 7200 1 CEST}. {875919600 7200 0 EET}. {1352505600 3600 0 CET}. {1364515200 7200 1 CEST}. {1382662800 7200 0 EET}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1072
                                                                                                                                                                                                                                  Entropy (8bit):4.074604685883076
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52DgmdHjPbwSRjneMVyDKCNFWLFyBXS9/3S3K/CBmvyncSuZSqLS2C6oPwVFD:cQUejbwSRyS2Uyc+FcJLKgzmcx9b
                                                                                                                                                                                                                                  MD5:1899EDCB30CDDE3A13FB87C026CD5D87
                                                                                                                                                                                                                                  SHA1:4C7E25A36E0A62F3678BCD720FCB8911547BAC8D
                                                                                                                                                                                                                                  SHA-256:F0E01AA40BB39FE64A2EB2372E0E053D59AA65D64496792147FEFBAB476C4EC3
                                                                                                                                                                                                                                  SHA-512:FD22A2A7F9F8B66396152E27872CCBA6DA967F279BAF21BC91EF76E86B59505B3C21D198032B853427D9FFAB394FBB570F849B257D6F6821916C9AB29E7C37A1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Tunis) {. {-9223372036854775808 2444 0 LMT}. {-2797202444 561 0 PMT}. {-1855958961 3600 0 CET}. {-969242400 7200 1 CEST}. {-950493600 3600 0 CET}. {-941940000 7200 1 CEST}. {-891136800 3600 0 CET}. {-877827600 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-842918400 3600 0 CET}. {-842223600 7200 1 CEST}. {-828230400 3600 0 CET}. {-812502000 7200 1 CEST}. {-796269600 3600 0 CET}. {-781052400 7200 1 CEST}. {-766634400 3600 0 CET}. {231202800 7200 1 CEST}. {243903600 3600 0 CET}. {262825200 7200 1 CEST}. {276044400 3600 0 CET}. {581122800 7200 1 CEST}. {591145200 3600 0 CET}. {606870000 7200 1 CEST}. {622594800 3600 0 CET}. {641516400 7200 1 CEST}. {654649200 3600 0 CET}. {1114902000 7200 1 CEST}. {1128038400 3600 0 CET}. {1143334800 7200 1 CEST}. {1162083600 3600 0 CET}. {1174784400 7200 1 CEST}. {1193533200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1591
                                                                                                                                                                                                                                  Entropy (8bit):3.915421470240155
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5qtCmcMxTFD9nJivm/8ySy/tnwfn8OIxJJSV1AnNlKQmX0UTjJx2MgXgprKfks1/:QCj6tXww023zn/
                                                                                                                                                                                                                                  MD5:18BD78EB14E153DAAAAE70B0A6A2510C
                                                                                                                                                                                                                                  SHA1:A91BA216A2AB62B138B1F0247D75FBA14A5F05C0
                                                                                                                                                                                                                                  SHA-256:639A57650A4EA5B866EAAA2EEC0562233DC92CF9D6955AC387AD954391B850B1
                                                                                                                                                                                                                                  SHA-512:88F34732F843E95F2A2AD4FAA0B5F945DD69B65FDDB4BB7DD957B95283B7AE995F52050B45A6332864C1C5CC4611390F6827D82569D343B5E1B9DDFE0AE5A633
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Africa/Windhoek) {. {-9223372036854775808 4104 0 LMT}. {-2458170504 5400 0 +0130}. {-2109288600 7200 0 SAST}. {-860976000 10800 1 SAST}. {-845254800 7200 0 SAST}. {637970400 7200 0 CAT}. {764200800 3600 1 WAT}. {778640400 7200 0 CAT}. {796780800 3600 1 WAT}. {810090000 7200 0 CAT}. {828835200 3600 1 WAT}. {841539600 7200 0 CAT}. {860284800 3600 1 WAT}. {873594000 7200 0 CAT}. {891734400 3600 1 WAT}. {905043600 7200 0 CAT}. {923184000 3600 1 WAT}. {936493200 7200 0 CAT}. {954633600 3600 1 WAT}. {967942800 7200 0 CAT}. {986083200 3600 1 WAT}. {999392400 7200 0 CAT}. {1018137600 3600 1 WAT}. {1030842000 7200 0 CAT}. {1049587200 3600 1 WAT}. {1062896400 7200 0 CAT}. {1081036800 3600 1 WAT}. {1094346000 7200 0 CAT}. {1112486400 3600 1 WAT}. {1125795600 7200 0 CAT}. {1143936000 3600 1 WAT}. {1157245200 7200 0 CAT}. {1175385600 3600 1 WAT}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8171
                                                                                                                                                                                                                                  Entropy (8bit):3.783938143940452
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:DGWQm82ctfc/TVu7pAmKABmAlJD1NPaTsrEe50IC:DGWQm67pAmKABmiD1R2sG
                                                                                                                                                                                                                                  MD5:DD838D2C8CF84B775BBCBA7868E7FFB5
                                                                                                                                                                                                                                  SHA1:509CFC15E2CBFC2F183B4A3CDEC42C8427EBA825
                                                                                                                                                                                                                                  SHA-256:01A88ADE038DDD264B74ED921441642CAA93830CEF9594F70188CCF6D19C4664
                                                                                                                                                                                                                                  SHA-512:9D520CADC0134E7812B5643311246CED011A22D50240A03260478C90B69EC325AE5BD7548BA266E00253AC3288605A912C5DBB026EA1516CB2030F302BFCDF0E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Adak) {. {-9223372036854775808 44002 0 LMT}. {-3225223727 -42398 0 LMT}. {-2188944802 -39600 0 NST}. {-883573200 -39600 0 NST}. {-880196400 -36000 1 NWT}. {-769395600 -36000 1 NPT}. {-765374400 -39600 0 NST}. {-757342800 -39600 0 NST}. {-86878800 -39600 0 BST}. {-31496400 -39600 0 BST}. {-21466800 -36000 1 BDT}. {-5745600 -39600 0 BST}. {9982800 -36000 1 BDT}. {25704000 -39600 0 BST}. {41432400 -36000 1 BDT}. {57758400 -39600 0 BST}. {73486800 -36000 1 BDT}. {89208000 -39600 0 BST}. {104936400 -36000 1 BDT}. {120657600 -39600 0 BST}. {126709200 -36000 1 BDT}. {152107200 -39600 0 BST}. {162392400 -36000 1 BDT}. {183556800 -39600 0 BST}. {199285200 -36000 1 BDT}. {215611200 -39600 0 BST}. {230734800 -36000 1 BDT}. {247060800 -39600 0 BST}. {262789200 -36000 1 BDT}. {278510400 -39600 0 BST}. {294238800 -36000 1 BDT}. {309960000 -3
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8410
                                                                                                                                                                                                                                  Entropy (8bit):3.882284820226162
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:RWFxXw34N+YXSUKC8aaIqDPRs/Q7Ddh5sBPyNsSLFOMM/EowALVZVmWa86Eac8rQ:Rsd6M/4h5sBPy+CMt/ElALLVuAH
                                                                                                                                                                                                                                  MD5:30468928CFDD0B6AAC8EA5BF84956E21
                                                                                                                                                                                                                                  SHA1:0B146D4D789CD49F0A7FEDFFE85FFD31C0926D9C
                                                                                                                                                                                                                                  SHA-256:202A45DEBFD6E92EF21E2FFF37281C1DE5B4AF4C79DC59A642013EBB37FE5AF0
                                                                                                                                                                                                                                  SHA-512:721049A2C751BC3F90B0D757C85F59971B46C70942B2F8A20B0E0E0834B89BBE9A5F16D20AEB5F58C1B6268D71DD5F39F9135C60FDE692E3E472598E054C1D96
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Anchorage) {. {-9223372036854775808 50424 0 LMT}. {-3225223727 -35976 0 LMT}. {-2188951224 -36000 0 AST}. {-883576800 -36000 0 AST}. {-880200000 -32400 1 AWT}. {-769395600 -32400 1 APT}. {-765378000 -36000 0 AST}. {-86882400 -36000 0 AHST}. {-31500000 -36000 0 AHST}. {-21470400 -32400 1 AHDT}. {-5749200 -36000 0 AHST}. {9979200 -32400 1 AHDT}. {25700400 -36000 0 AHST}. {41428800 -32400 1 AHDT}. {57754800 -36000 0 AHST}. {73483200 -32400 1 AHDT}. {89204400 -36000 0 AHST}. {104932800 -32400 1 AHDT}. {120654000 -36000 0 AHST}. {126705600 -32400 1 AHDT}. {152103600 -36000 0 AHST}. {162388800 -32400 1 AHDT}. {183553200 -36000 0 AHST}. {199281600 -32400 1 AHDT}. {215607600 -36000 0 AHST}. {230731200 -32400 1 AHDT}. {247057200 -36000 0 AHST}. {262785600 -32400 1 AHDT}. {278506800 -36000 0 AHST}. {294235200 -32400 1 AHDT}. {309956400 -360
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):203
                                                                                                                                                                                                                                  Entropy (8bit):4.9101657646476164
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290/8J5290e/:MBaIMY9QpI290/8m90O
                                                                                                                                                                                                                                  MD5:F7D915076ABE4FF032E13F8769D38433
                                                                                                                                                                                                                                  SHA1:F930A8943E87105EE8523F640EA6F65BD4C9CE78
                                                                                                                                                                                                                                  SHA-256:9D368458140F29D95CAB9B5D0259DE27B52B1F2E987B4FA1C12F287082F4FE56
                                                                                                                                                                                                                                  SHA-512:63C99FFA65F749B7637D0DF5A73A21AC34DFEAD364479DE992E215258A82B9C15AB0D45AAF29BD2F259766346FDB901412413DD44C5D45BB8DF6B582C34F48B3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Anguilla) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):202
                                                                                                                                                                                                                                  Entropy (8bit):4.90033942341457
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290//MFe90e/:MBaIMY9QpI290//V90O
                                                                                                                                                                                                                                  MD5:25CA3996DDB8F1964D3008660338BA72
                                                                                                                                                                                                                                  SHA1:B66D73B5B38C2CCCA78232ADC3572BBBEB79365D
                                                                                                                                                                                                                                  SHA-256:A2ABBD9BCFCE1DB1D78C99F4993AC0D414A08DB4AC5CE915B81119E17C4DA76F
                                                                                                                                                                                                                                  SHA-512:A25AFE4FD981F458FE194A5D87C35BE5FC7D4426C1EEE8311AE655BB53364CD4AAC0710C0D7E6A91C0F248E2A6916902F4FD43A220CFF7A6474B77D93CF35C81
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Antigua) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1722
                                                                                                                                                                                                                                  Entropy (8bit):3.6435096006301833
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5s4h19U2dBUGrmO7XGtN3kh0VKnNIVkHZU7WWhKRWRN:Cm19U2zUGrpzGtVE0VKnyVkHZWWWhKRG
                                                                                                                                                                                                                                  MD5:6349567E3ED0FD11DD97056D2CFF11EE
                                                                                                                                                                                                                                  SHA1:404F1B311D7072A6372351366BA15BB94F3AC7D2
                                                                                                                                                                                                                                  SHA-256:41C816E9C0217A01D9288014013CD1D315B2CEB719F8BB310670D02B664A4462
                                                                                                                                                                                                                                  SHA-512:782910DFA0FF8FEDB94D622271FA0FF983BC50A4FEE95FFC8EC3E89FB123B82C26701D81A994A8248F1C1CA0B1EF49C2752C4D7B498A0A623D79E2B6753DA432
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Araguaina) {. {-9223372036854775808 -11568 0 LMT}. {-1767214032 -10800 0 -03}. {-1206957600 -7200 1 -03}. {-1191362400 -10800 0 -03}. {-1175374800 -7200 1 -03}. {-1159826400 -10800 0 -03}. {-633819600 -7200 1 -03}. {-622069200 -10800 0 -03}. {-602283600 -7200 1 -03}. {-591832800 -10800 0 -03}. {-570747600 -7200 1 -03}. {-560210400 -10800 0 -03}. {-539125200 -7200 1 -03}. {-531352800 -10800 0 -03}. {-191365200 -7200 1 -03}. {-184197600 -10800 0 -03}. {-155163600 -7200 1 -03}. {-150069600 -10800 0 -03}. {-128898000 -7200 1 -03}. {-121125600 -10800 0 -03}. {-99954000 -7200 1 -03}. {-89589600 -10800 0 -03}. {-68418000 -7200 1 -03}. {-57967200 -10800 0 -03}. {499748400 -7200 1 -03}. {511236000 -10800 0 -03}. {530593200 -7200 1 -03}. {540266400 -10800 0 -03}. {562129200 -7200 1 -03}. {571197600 -10800 0 -03}. {592974000 -7200 1 -03}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1981
                                                                                                                                                                                                                                  Entropy (8bit):3.6790048972731686
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5Wcap0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWvXydhSTP:vC0ZB9yRwhS+/po/lKENURMo8XvCWvX1
                                                                                                                                                                                                                                  MD5:93B8CF61EDC7378C39BE33A77A4222FC
                                                                                                                                                                                                                                  SHA1:8A01D2B22F8FC163B0FDCED4305C3FA08336AF7D
                                                                                                                                                                                                                                  SHA-256:35E05545A12E213DCBC0C2F7FDCA5C79CD522E7D2684EDF959E8A0A991BEF3C8
                                                                                                                                                                                                                                  SHA-512:68333AB0C9348AF0994DB26FB6D34FF67ABF56AF1FBABB77F2C9EFF20E9A2DB2B59C5B81DF0C42299DE459B03DF13E07071B84576E62597920D1848F1E1FC9E3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Buenos_Aires) {. {-9223372036854775808 -14028 0 LMT}. {-2372097972 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-73378
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2009
                                                                                                                                                                                                                                  Entropy (8bit):3.6543367491742913
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5f4p0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWg7ydhSTK+:No0ZB9yRwhS+/po/lKENURMo8XvCWg7r
                                                                                                                                                                                                                                  MD5:7FCA355F863158D180B3179782A6E8C8
                                                                                                                                                                                                                                  SHA1:CDFBC98923F7315388009F22F9C37626B677321F
                                                                                                                                                                                                                                  SHA-256:C3FE34E5BE68503D78D63A2AFB5C970584D0854C63648D7FE6E2412A4E5B008F
                                                                                                                                                                                                                                  SHA-512:6C2F9598C714BEBA7A538AAB7FA68C1962001C426C80B21F2A9560C72BCEA87B956821E68AF30B4576C1ECDB07E33D616934BD49943DA2E45841B10D483833C5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Catamarca) {. {-9223372036854775808 -15788 0 LMT}. {-2372096212 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-73378080
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):237
                                                                                                                                                                                                                                  Entropy (8bit):4.672788403288451
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/MMXAIVAIgp/MMXs290/MquQ90/MMXAv:MBaIMY/Mhp/MP290/MquQ90/MH
                                                                                                                                                                                                                                  MD5:42D568B6100D68F9E5698F301F4EC136
                                                                                                                                                                                                                                  SHA1:E0A5F43A80EB0FAAFBD45127DCAF793406A4CF3A
                                                                                                                                                                                                                                  SHA-256:D442E5BBB801C004A7903F6C217149FCDA521088705AC9FECB0BC3B3058981BF
                                                                                                                                                                                                                                  SHA-512:99580239B40247AF75FFAA44E930CDECB71F6769E3597AC85F19A8816F7D0859F6A0D5499AFAC2FA35C32BA05B75B27C77F36DE290DD0D442C0769D6F41E96DA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Argentina/Catamarca)]} {. LoadTimeZoneFile America/Argentina/Catamarca.}.set TZData(:America/Argentina/ComodRivadavia) $TZData(:America/Argentina/Catamarca).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1976
                                                                                                                                                                                                                                  Entropy (8bit):3.659938468164974
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5zxpp0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWg7ydhSTP:1xT0ZB9yRwhS+/po/lKENURMo8XvCWgJ
                                                                                                                                                                                                                                  MD5:C6A4EED52A2829671089F9E84D986BFB
                                                                                                                                                                                                                                  SHA1:F5BBDD0C3347C7519282249AA48543C01DA95B7A
                                                                                                                                                                                                                                  SHA-256:50541A1FBACAD2C93F08CD402A609C4984AF66E27DB9FAA7F64FDA93DDC57939
                                                                                                                                                                                                                                  SHA-512:52EA5BB27C91C753275EAC90E082EEBE98B5997B830D8DD579174558355E3FED0AAF4AA02679B0866591951F04F358AFB113423872D57820143E75FEB4415B60
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Cordoba) {. {-9223372036854775808 -15408 0 LMT}. {-2372096592 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1974
                                                                                                                                                                                                                                  Entropy (8bit):3.659895575974408
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5rCp0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCfSWnzydhSR:FK0ZB9yRwhS+/po/lKENURMo8XvCfbzD
                                                                                                                                                                                                                                  MD5:A7F2318729F0B4B04C9176CB5257691E
                                                                                                                                                                                                                                  SHA1:0EAD91CBDC640DB67F64A34209359674AC47062A
                                                                                                                                                                                                                                  SHA-256:E33962F99E6022ED1825898990B38C10F505DE6EC44DAFB00C75E3A7C1A61C8A
                                                                                                                                                                                                                                  SHA-512:CB80580383309CCA4837556ED0444F2B931E1B3B13582023BFB715393C94C4F1279D8EC18CACB06BB13E3D32A535495DF2D093E225DF7B6DFFD3571A3B3573B2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Jujuy) {. {-9223372036854775808 -15672 0 LMT}. {-2372096328 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800 -1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2037
                                                                                                                                                                                                                                  Entropy (8bit):3.655968476161033
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5J6p0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWXXydhSTK+:Hi0ZB9yRwhS+/po/lKENURMo8XvCWXXr
                                                                                                                                                                                                                                  MD5:49BB6DAD5560E7C6EAEA6F3CF9EB1F67
                                                                                                                                                                                                                                  SHA1:56E0D9DD4E6B12522A75F0ABFEBB6AE019614CB5
                                                                                                                                                                                                                                  SHA-256:13CBECD826DD5DE4D8576285FC6C4DE39F2E9CF03F4A61F75316776CAED9F878
                                                                                                                                                                                                                                  SHA-512:CA7EF1A94A6635EAB644C5EAAC2B890E7401745CFA97609BDA410D031B990C87EB2F97160731A45B5A8ADE48D883EAB529AE2379406852129102F0FDF92247D8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/La_Rioja) {. {-9223372036854775808 -16044 0 LMT}. {-2372095956 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2009
                                                                                                                                                                                                                                  Entropy (8bit):3.649537276151328
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5Yep0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCpSGSldhSTS:C+0ZB9yRwhS+/po/lKENURMo8XvCpVap
                                                                                                                                                                                                                                  MD5:69F8A1AC33BE03C008EC5FEBD1CE4CAA
                                                                                                                                                                                                                                  SHA1:858362EFEA0C68C1EC9295A9FCE647B41DBF429D
                                                                                                                                                                                                                                  SHA-256:B02DDE8DCF8E68B2B1DBF66ADF5B247E9833FEC347DFBC487C391FADA5706AD3
                                                                                                                                                                                                                                  SHA-512:8373EAEEBF5EA028CC0673B10E9DFE84F4DFC2F9E9E8320D59E6CE6125643B31F5E61FC894E420A8D7E9C2FF242617DF911ABF0884AF5B32316A098C8524772D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Mendoza) {. {-9223372036854775808 -16516 0 LMT}. {-2372095484 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2012
                                                                                                                                                                                                                                  Entropy (8bit):3.6703415662732746
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5mpp0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWvXydhSTK+:oT0ZB9yRwhS+/po/lKENURMo8XvCWvXr
                                                                                                                                                                                                                                  MD5:AC8E561F7573280594BDD898324E9442
                                                                                                                                                                                                                                  SHA1:7DC6248ED29719700189FF3A69D06AAC7B54EB6B
                                                                                                                                                                                                                                  SHA-256:0833962C0DE220BC601D764EE14442E98F83CB581816B74E5867540348227250
                                                                                                                                                                                                                                  SHA-512:2FDD23ABA891EBEF01944F3C8F1A9E6844C182B0EB2CBEC0F942F268BAE51F0D7775370E262B500FE7151210F8849DD54BA5CEB2160AE03A5747A48A10933F05
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Rio_Gallegos) {. {-9223372036854775808 -16612 0 LMT}. {-2372095388 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-73378
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1945
                                                                                                                                                                                                                                  Entropy (8bit):3.653135248071002
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5Vgp0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWg7ydhSTQO:7w0ZB9yRwhS+/po/lKENURMo8XvCWg7D
                                                                                                                                                                                                                                  MD5:70FB90E24FEEF5211C9488C938295F02
                                                                                                                                                                                                                                  SHA1:5C903A669B51A1635284AD80877E0C6789D8EB26
                                                                                                                                                                                                                                  SHA-256:FBDACFA5D82DC23ECDD9D9F8A4EF71F7DBB579BF4A621C545062A7AE0296141D
                                                                                                                                                                                                                                  SHA-512:4C36B34B2203F6D4C78CC6F0E061BF35C4B98121D50096C8015EBA6DBEFA989DD2F2E32436EEE3055F1CF466BC3D4FD787A89873EEE4914CB51B273E335C90C3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Salta) {. {-9223372036854775808 -15700 0 LMT}. {-2372096300 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800 -1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2037
                                                                                                                                                                                                                                  Entropy (8bit):3.6597750686514887
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5jXup0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWXXydhSTH:1+0ZB9yRwhS+/po/lKENURMo8XvCWXXh
                                                                                                                                                                                                                                  MD5:BBB4D4B341E7FEC2E5A937267AADCD0F
                                                                                                                                                                                                                                  SHA1:9AB509F97DCBAAE5ACA7F67853E86429438ED8DC
                                                                                                                                                                                                                                  SHA-256:BAC6CC41865DD3D4F042FE6106176279F3DEB9127BE0146AF75AE1E47098AF43
                                                                                                                                                                                                                                  SHA-512:49E32BD5BDBA773D99C883080660B431E8D4C806164C0354C848CF3AB0042797DBE7F6226BA234634A1DF254B0464ED5F714B054454520263536B0A77D7053D9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/San_Juan) {. {-9223372036854775808 -16444 0 LMT}. {-2372095556 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2013
                                                                                                                                                                                                                                  Entropy (8bit):3.6516068215670687
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:58kp0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCp1ESWn0SK4:K80ZB9yRwhS+/po/lKENURMo8XvCpmTr
                                                                                                                                                                                                                                  MD5:767F99822C382327A318EAC0779321F3
                                                                                                                                                                                                                                  SHA1:1352B21F20C7F742D57CB734013143C9B58DA221
                                                                                                                                                                                                                                  SHA-256:B4590DF5AC1993E10F508CC5183809775F5248B565400BA05AE5F87B69D4E26B
                                                                                                                                                                                                                                  SHA-512:C8FF21DC573DE5CB327DDA536391071012A038B8266C4E39922EC0F0EC975000E5D7AFBBE81D1C28DB8733E8B01E1E4D6BE0968D9EFCFC50DB102CC09BDABEA6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/San_Luis) {. {-9223372036854775808 -15924 0 LMT}. {-2372096076 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2036
                                                                                                                                                                                                                                  Entropy (8bit):3.653313944168433
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5yM9Ep0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWg7ydhSU:b9c0ZB9yRwhS+/po/lKENURMo8XvCWgi
                                                                                                                                                                                                                                  MD5:892E23EEB82C4EF52CB830C607E3DD6D
                                                                                                                                                                                                                                  SHA1:9A9334DC1F9FBA0152C1B5CAA954F2FF1775B78C
                                                                                                                                                                                                                                  SHA-256:F3D19E51463B4D04BE1CD4F36CD9DD5E3954B6186ADD6A176B78C3C4F399CCA1
                                                                                                                                                                                                                                  SHA-512:4FCC3F61E261D57788756921AE21E54D387AB533ACF56182579B9082EC0791CD655D50BEDDAF996233CDBDE549F743855C191BCB581EF3D7877C4CE26B14EEC2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Tucuman) {. {-9223372036854775808 -15652 0 LMT}. {-2372096348 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2007
                                                                                                                                                                                                                                  Entropy (8bit):3.6562927023582197
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:56Yp0SaS2SeSNS2S/SwS8gSvJ1/SKSHSRCSiS9SDS+SGwRShoSdXvCWvXydhSTHd:QI0ZB9yRwhS+/po/lKENURMo8XvCWvXz
                                                                                                                                                                                                                                  MD5:EA31C60D08FFE56504DEC62A539F51D9
                                                                                                                                                                                                                                  SHA1:79F31368AC9C141B5F0F5804A0D903C12B75A386
                                                                                                                                                                                                                                  SHA-256:4E3A4539FE0D8E0401C8304E5A79F40C420333C92BF1227BCBB5DB242444ECD6
                                                                                                                                                                                                                                  SHA-512:EB58A3122DE8FC7887622D3716E1D9D615625FC47C30BA0BD8112894B595263F04B37D43E142C43251C48D2CD703BB6F56966B965C5475DA83F2C290B6F564E8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Argentina/Ushuaia) {. {-9223372036854775808 -16392 0 LMT}. {-2372095608 -15408 0 CMT}. {-1567453392 -14400 0 -04}. {-1233432000 -10800 0 -04}. {-1222981200 -14400 0 -04}. {-1205956800 -10800 1 -04}. {-1194037200 -14400 0 -04}. {-1172865600 -10800 1 -04}. {-1162501200 -14400 0 -04}. {-1141329600 -10800 1 -04}. {-1130965200 -14400 0 -04}. {-1109793600 -10800 1 -04}. {-1099429200 -14400 0 -04}. {-1078257600 -10800 1 -04}. {-1067806800 -14400 0 -04}. {-1046635200 -10800 1 -04}. {-1036270800 -14400 0 -04}. {-1015099200 -10800 1 -04}. {-1004734800 -14400 0 -04}. {-983563200 -10800 1 -04}. {-973198800 -14400 0 -04}. {-952027200 -10800 1 -04}. {-941576400 -14400 0 -04}. {-931032000 -10800 1 -04}. {-900882000 -14400 0 -04}. {-890337600 -10800 1 -04}. {-833749200 -14400 0 -04}. {-827265600 -10800 1 -04}. {-752274000 -14400 0 -04}. {-733780800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):182
                                                                                                                                                                                                                                  Entropy (8bit):4.760006229014668
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx09CvjHVAIg209CvjvQ2IAcGE/nVIAcGE9Cvju:SlSWB9IZaM3y79CzVAIgp9CE290/V90J
                                                                                                                                                                                                                                  MD5:84605CB5AC93D51FF8C0C3D46B6A566F
                                                                                                                                                                                                                                  SHA1:8B56DBDAD33684743E5828EFBD638F082E9AA20D
                                                                                                                                                                                                                                  SHA-256:680651D932753C9F9E856018B7C1B6D944536111900CB56685ABA958DE9EC9C1
                                                                                                                                                                                                                                  SHA-512:A5FA747C4743130308A8D8832AD33CF10B2DA2F214DEE129CAC9543D6F88FF232B4387026976578D037DF7816D0F4177835866A35F497438DD2526FEBACA2AF6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Curacao)]} {. LoadTimeZoneFile America/Curacao.}.set TZData(:America/Aruba) $TZData(:America/Curacao).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7685
                                                                                                                                                                                                                                  Entropy (8bit):3.4198614734785875
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:57TOr5dwtvNJZWDQ2eBTVSZKnb0Yg6f5xgTK5IQPyP8D3rVPe9DptTkhXXkbCkCg:5P7J1A
                                                                                                                                                                                                                                  MD5:625A707182C6E0027D49F0FFD775AC51
                                                                                                                                                                                                                                  SHA1:6423A50DB875051656A1C3C5B6C6AF556F8FBE0A
                                                                                                                                                                                                                                  SHA-256:CD884C5C99949F5723DC94FBFF011B97AE0989EF2EDE089B30C2CD4893AFCE08
                                                                                                                                                                                                                                  SHA-512:C5787953997D7D1B583AEE7F68FCC255AC1FAC5C9A7025C8093F274206A0C8163DE221B4823F7750B5B30AF32D673F88D5956C0E510851EBA72CC2360AC35D18
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Asuncion) {. {-9223372036854775808 -13840 0 LMT}. {-2524507760 -13840 0 AMT}. {-1206389360 -14400 0 -04}. {86760000 -10800 0 -03}. {134017200 -14400 0 -04}. {162878400 -14400 0 -04}. {181368000 -10800 1 -04}. {194497200 -14400 0 -04}. {212990400 -10800 1 -04}. {226033200 -14400 0 -04}. {244526400 -10800 1 -04}. {257569200 -14400 0 -04}. {276062400 -10800 1 -04}. {291783600 -14400 0 -04}. {307598400 -10800 1 -04}. {323406000 -14400 0 -04}. {339220800 -10800 1 -04}. {354942000 -14400 0 -04}. {370756800 -10800 1 -04}. {386478000 -14400 0 -04}. {402292800 -10800 1 -04}. {418014000 -14400 0 -04}. {433828800 -10800 1 -04}. {449636400 -14400 0 -04}. {465451200 -10800 1 -04}. {481172400 -14400 0 -04}. {496987200 -10800 1 -04}. {512708400 -14400 0 -04}. {528523200 -10800 1 -04}. {544244400 -14400 0 -04}. {560059200 -10800 1 -04}. {57586
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):332
                                                                                                                                                                                                                                  Entropy (8bit):4.582750266902939
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5290/qlfbm2OHvcFGxYP329V/uFn/TUs/uFn/lHIs8/kRm5/uFb/C/iin:MBp5290/emdHLYP323/uFn/9/uFn/dBs
                                                                                                                                                                                                                                  MD5:66777BB05E04E030FABBC70649290851
                                                                                                                                                                                                                                  SHA1:97118A1C4561FC1CC9B7D18EE2C7D805778970B8
                                                                                                                                                                                                                                  SHA-256:2C6BBDE21C77163CD32465D773F6EBBA3332CA1EAEEF88BB95F1C98CBCA1562D
                                                                                                                                                                                                                                  SHA-512:B00F01A72A5306C71C30B1F0742E14E23202E03924887B2418CA6F5513AE59E12BC45F62B614716BBE50A7BEA8D62310E1B67BB39B84F7B1B40C5D2D19086B7C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Atikokan) {. {-9223372036854775808 -21988 0 LMT}. {-2366733212 -21600 0 CST}. {-1632067200 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-923248800 -18000 1 CDT}. {-880214400 -18000 0 CWT}. {-769395600 -18000 1 CPT}. {-765388800 -18000 0 EST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):172
                                                                                                                                                                                                                                  Entropy (8bit):4.761501750421919
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0/yO5pVAIg20/yOvYvt2IAcGE/ol7x+IAcGE/yOun:SlSWB9IZaM3y7/ykVAIgp/y9F290/ola
                                                                                                                                                                                                                                  MD5:E641C6615E1EF015427202803761AADD
                                                                                                                                                                                                                                  SHA1:E254129517335E60D82DFE00C6D5AF722D36565A
                                                                                                                                                                                                                                  SHA-256:9C546927B107BB4AB345F618A91C0F8C03D8A366028B2F0FCBF0A3CE29E6588E
                                                                                                                                                                                                                                  SHA-512:B7D34B1EA0D6722D7BFCD91F082D79EE009B97A2B5684D76A3F04CB59079637134275CF9A0306B9F4423A03CC0C2AB43994207D1B209161C893C2C6F3F3B6311
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Adak)]} {. LoadTimeZoneFile America/Adak.}.set TZData(:America/Atka) $TZData(:America/Adak).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1944
                                                                                                                                                                                                                                  Entropy (8bit):3.6123892296166242
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:534h19U2dBUGrmO7XGtN3kh0OjmimtnNIVkHZU7WWhw5N:Nm19U2zUGrpzGtVE0OjmicnyVkHZWWWK
                                                                                                                                                                                                                                  MD5:E52095DB1E77EC4553A0AF56665CDE51
                                                                                                                                                                                                                                  SHA1:CED0966E8D89443F2CCBBE9F44DA683F7D2D688B
                                                                                                                                                                                                                                  SHA-256:30A4658BD46F88A1585ACABB9EB6BA03DB929EAF7D2F430BC4864D194A6CC0DD
                                                                                                                                                                                                                                  SHA-512:D6F3D51393F9D8F6414023A8435213EC6BD4FCAA5084B664B828CCDE8D57821E3E284B3D5A27414B4C2AB0B71E31D775D1F924C926C849F591D361DAA8681D8A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Bahia) {. {-9223372036854775808 -9244 0 LMT}. {-1767216356 -10800 0 -03}. {-1206957600 -7200 1 -03}. {-1191362400 -10800 0 -03}. {-1175374800 -7200 1 -03}. {-1159826400 -10800 0 -03}. {-633819600 -7200 1 -03}. {-622069200 -10800 0 -03}. {-602283600 -7200 1 -03}. {-591832800 -10800 0 -03}. {-570747600 -7200 1 -03}. {-560210400 -10800 0 -03}. {-539125200 -7200 1 -03}. {-531352800 -10800 0 -03}. {-191365200 -7200 1 -03}. {-184197600 -10800 0 -03}. {-155163600 -7200 1 -03}. {-150069600 -10800 0 -03}. {-128898000 -7200 1 -03}. {-121125600 -10800 0 -03}. {-99954000 -7200 1 -03}. {-89589600 -10800 0 -03}. {-68418000 -7200 1 -03}. {-57967200 -10800 0 -03}. {499748400 -7200 1 -03}. {511236000 -10800 0 -03}. {530593200 -7200 1 -03}. {540266400 -10800 0 -03}. {562129200 -7200 1 -03}. {571197600 -10800 0 -03}. {592974000 -7200 1 -03}. {602
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6625
                                                                                                                                                                                                                                  Entropy (8bit):3.791871111929614
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:NqZL/1dCYDXEaXTuXMEXiH4RxGIJkYWXsWwav7jNf4sOVEmbwBlhcCLfYkNRfsNz:NqZL/1dCYDDCxyH4RxGIJkYWXsWwav7S
                                                                                                                                                                                                                                  MD5:6A18936EC3AA0FCEC8A230ADAF90FF1E
                                                                                                                                                                                                                                  SHA1:B13B8BF1FD2EEED44F63A0DC71F0BCE8AC15C783
                                                                                                                                                                                                                                  SHA-256:974481F867DEA51B6D8C6C21432F9F6F7D6A951EC1C34B49D5445305A6FB29B7
                                                                                                                                                                                                                                  SHA-512:75AA7A3AE63ED41AFF6CF0F6DC3CA649786A86A64293E715962B003383D31A8AD2B99C72CE6B788EC4DFF1AF7820F011B3F1FD353B37C326EF02289CE4A061BF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Bahia_Banderas) {. {-9223372036854775808 -25260 0 LMT}. {-1514739600 -25200 0 MST}. {-1343066400 -21600 0 CST}. {-1234807200 -25200 0 MST}. {-1220292000 -21600 0 CST}. {-1207159200 -25200 0 MST}. {-1191344400 -21600 0 CST}. {-873828000 -25200 0 MST}. {-661539600 -28800 0 PST}. {28800 -25200 0 MST}. {828867600 -21600 1 MDT}. {846403200 -25200 0 MST}. {860317200 -21600 1 MDT}. {877852800 -25200 0 MST}. {891766800 -21600 1 MDT}. {909302400 -25200 0 MST}. {923216400 -21600 1 MDT}. {941356800 -25200 0 MST}. {954666000 -21600 1 MDT}. {972806400 -25200 0 MST}. {989139600 -21600 1 MDT}. {1001836800 -25200 0 MST}. {1018170000 -21600 1 MDT}. {1035705600 -25200 0 MST}. {1049619600 -21600 1 MDT}. {1067155200 -25200 0 MST}. {1081069200 -21600 1 MDT}. {1099209600 -25200 0 MST}. {1112518800 -21600 1 MDT}. {1130659200 -25200 0 MST}. {1143968400 -
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):413
                                                                                                                                                                                                                                  Entropy (8bit):4.429320498710922
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5290eNJmdH9Gcvm/uFkCFP/K/uFkCFks/v/h/uFkCFFoI/qZ/uFkCF3dX/r:cQT7enmSkC9/KSkCT/BSkCLl/wSkCj/r
                                                                                                                                                                                                                                  MD5:49EED111AB16F289E7D2D145A2641720
                                                                                                                                                                                                                                  SHA1:2F0A37524209FC26421C2951F169B4352250ED9E
                                                                                                                                                                                                                                  SHA-256:E7415944397EF395DDBD8EACB6D68662908A25E2DB18E4A3411016CBB6B8AFC6
                                                                                                                                                                                                                                  SHA-512:3AD4511798BA763C4E4A549340C807FE2FDF6B107C74A977E425734BBADDFF44ADAA68B5AE1F96170902A10208BC4BBF551C596EB1A3E292071549B8F3012A35
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Barbados) {. {-9223372036854775808 -14309 0 LMT}. {-1451678491 -14309 0 BMT}. {-1199217691 -14400 0 AST}. {234943200 -10800 1 ADT}. {244616400 -14400 0 AST}. {261554400 -10800 1 ADT}. {276066000 -14400 0 AST}. {293004000 -10800 1 ADT}. {307515600 -14400 0 AST}. {325058400 -10800 1 ADT}. {338706000 -14400 0 AST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):996
                                                                                                                                                                                                                                  Entropy (8bit):3.799419505060255
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQYe3wc4h1u80V2dBUGphmC17ewGtN3kN:5VB4h19U2dBUGrmO7XGtN3kN
                                                                                                                                                                                                                                  MD5:2F3314B71810C1AC0280F292F09F37BE
                                                                                                                                                                                                                                  SHA1:B8702125A9768AE530354CE2A765BC07BABAEF34
                                                                                                                                                                                                                                  SHA-256:9ECA949D328915C6CB02A2E6084F3E0730D49F1C53C6D6AA12751F852C51BF02
                                                                                                                                                                                                                                  SHA-512:C4E1ADD2E580BFD4100EE776305530BCEA017D57A65205881536A1CDDA3A299816C133B5B1F4B40A99E47BB94AE2A7E727F3D24D06131705818CC0C1AA12E5BD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Belem) {. {-9223372036854775808 -11636 0 LMT}. {-1767213964 -10800 0 -03}. {-1206957600 -7200 1 -03}. {-1191362400 -10800 0 -03}. {-1175374800 -7200 1 -03}. {-1159826400 -10800 0 -03}. {-633819600 -7200 1 -03}. {-622069200 -10800 0 -03}. {-602283600 -7200 1 -03}. {-591832800 -10800 0 -03}. {-570747600 -7200 1 -03}. {-560210400 -10800 0 -03}. {-539125200 -7200 1 -03}. {-531352800 -10800 0 -03}. {-191365200 -7200 1 -03}. {-184197600 -10800 0 -03}. {-155163600 -7200 1 -03}. {-150069600 -10800 0 -03}. {-128898000 -7200 1 -03}. {-121125600 -10800 0 -03}. {-99954000 -7200 1 -03}. {-89589600 -10800 0 -03}. {-68418000 -7200 1 -03}. {-57967200 -10800 0 -03}. {499748400 -7200 1 -03}. {511236000 -10800 0 -03}. {530593200 -7200 1 -03}. {540266400 -10800 0 -03}. {562129200 -7200 1 -03}. {571197600 -10800 0 -03}. {590032800 -10800 0 -03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1854
                                                                                                                                                                                                                                  Entropy (8bit):3.8463726575443573
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQMeVyJOCSSVTSuWcLwX1QIXVlXco0bKdTu/pUHQGyUrROSTgltVJyODrUSn/mJO:5hxKj4jDMtVpIM/mjM/sQ
                                                                                                                                                                                                                                  MD5:1BFD01ECF77E031C23BDA5ED371E061F
                                                                                                                                                                                                                                  SHA1:7A38C5665A834B812613E4D10FE4D1E45F606407
                                                                                                                                                                                                                                  SHA-256:BDF09D97876E3A3C0422C655562252806B4EF914679FDCAB6DD78BD2B84DD932
                                                                                                                                                                                                                                  SHA-512:D7A2C2645129C4BAB1F0170A29A084396AD8CF07237DE339512C3A5C7227B017BF1D4B78EBD5A7274CAF1D172ECB2DB6F912887BFF1C6AC73E9D645E333A75A3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Belize) {. {-9223372036854775808 -21168 0 LMT}. {-1822500432 -21600 0 CST}. {-1616954400 -19800 1 -0530}. {-1606069800 -21600 0 CST}. {-1585504800 -19800 1 -0530}. {-1574015400 -21600 0 CST}. {-1554055200 -19800 1 -0530}. {-1542565800 -21600 0 CST}. {-1522605600 -19800 1 -0530}. {-1511116200 -21600 0 CST}. {-1490551200 -19800 1 -0530}. {-1479666600 -21600 0 CST}. {-1459101600 -19800 1 -0530}. {-1448217000 -21600 0 CST}. {-1427652000 -19800 1 -0530}. {-1416162600 -21600 0 CST}. {-1396202400 -19800 1 -0530}. {-1384713000 -21600 0 CST}. {-1364752800 -19800 1 -0530}. {-1353263400 -21600 0 CST}. {-1333303200 -19800 1 -0530}. {-1321813800 -21600 0 CST}. {-1301248800 -19800 1 -0530}. {-1290364200 -21600 0 CST}. {-1269799200 -19800 1 -0530}. {-1258914600 -21600 0 CST}. {-1238349600 -19800 1 -0530}. {-1226860200 -21600 0 CST}. {-1206900000 -1980
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):331
                                                                                                                                                                                                                                  Entropy (8bit):4.599775510303771
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5290Am2OHff4YPawmX/bVVFUFkCFVUP/GH6/XVVFUFkIZVVFUFkeF3k/g:MBp5290AmdHff4YPawY/b/uFkCFVUP/L
                                                                                                                                                                                                                                  MD5:5ACBD50E1CB87B4E7B735A8B5281917B
                                                                                                                                                                                                                                  SHA1:3E92C60B365C7E1F9BF5F312B007CBFD4175DB8F
                                                                                                                                                                                                                                  SHA-256:E61F3762B827971147772A01D51763A18CC5BED8F736000C64B4BDFF32973803
                                                                                                                                                                                                                                  SHA-512:9284FFDF115C7D7E548A06A6513E3591F88EE3E5197106B71B54CD82F27890D12773381218BCA69720F074A6762282F25830422DFA402FF19301D6834FD9FF7D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Blanc-Sablon) {. {-9223372036854775808 -13708 0 LMT}. {-2713896692 -14400 0 AST}. {-1632074400 -10800 1 ADT}. {-1615143600 -14400 0 AST}. {-880221600 -10800 1 AWT}. {-769395600 -10800 1 APT}. {-765399600 -14400 0 AST}. {14400 -14400 0 AST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1159
                                                                                                                                                                                                                                  Entropy (8bit):3.7116873200926586
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQETmex8Sos/USws/QSI/LHSD/vOSy/WS3o/aS2/vSh/TSSX/WcSp/ySZd/YlSjx:5EqSaSwXS4SqSbS3JSySxSxcSESAlSQE
                                                                                                                                                                                                                                  MD5:0858FCA5A59C9C6EE38B7E8A61307412
                                                                                                                                                                                                                                  SHA1:685597A5FD8BFEBF3EC558DB8ABF11903F63E05E
                                                                                                                                                                                                                                  SHA-256:825E89E4B35C9BA92CF53380475960C36307BF11FD87057891DF6EEBA984A88D
                                                                                                                                                                                                                                  SHA-512:7369EE42CD73CFD635505BF784E16A36C9BBDE0BDAAAB405CB8401EBC508F4CE0B0155206756C1905E915756F1D3CDC381C6B9C357A01EAE0ECC4C448978844A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Boa_Vista) {. {-9223372036854775808 -14560 0 LMT}. {-1767211040 -14400 0 -04}. {-1206954000 -10800 1 -04}. {-1191358800 -14400 0 -04}. {-1175371200 -10800 1 -04}. {-1159822800 -14400 0 -04}. {-633816000 -10800 1 -04}. {-622065600 -14400 0 -04}. {-602280000 -10800 1 -04}. {-591829200 -14400 0 -04}. {-570744000 -10800 1 -04}. {-560206800 -14400 0 -04}. {-539121600 -10800 1 -04}. {-531349200 -14400 0 -04}. {-191361600 -10800 1 -04}. {-184194000 -14400 0 -04}. {-155160000 -10800 1 -04}. {-150066000 -14400 0 -04}. {-128894400 -10800 1 -04}. {-121122000 -14400 0 -04}. {-99950400 -10800 1 -04}. {-89586000 -14400 0 -04}. {-68414400 -10800 1 -04}. {-57963600 -14400 0 -04}. {499752000 -10800 1 -04}. {511239600 -14400 0 -04}. {530596800 -10800 1 -04}. {540270000 -14400 0 -04}. {562132800 -10800 1 -04}. {571201200 -14400 0 -04}. {590036400 -1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):237
                                                                                                                                                                                                                                  Entropy (8bit):4.649012348678967
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5290bJqm2OHDgPcuknTEXPKV93kR/uFeEV/KV9C:MBp5290bUmdHDgPcukT8O93Y/uF7/O9C
                                                                                                                                                                                                                                  MD5:4B3B0F66FB3BC69A5AB5DA79D02F7E34
                                                                                                                                                                                                                                  SHA1:79B84C0578BBB0E4C07E99977D02EDE45F11CC8A
                                                                                                                                                                                                                                  SHA-256:E7C45CA67F1BA913E7DC1632C166973FDA8DA4734F8BCF3AB1157A45454C8D7B
                                                                                                                                                                                                                                  SHA-512:96289B4D179F146D6C5FB5DDAA4336CBCB60CF27BABCC20B9691387920897B293903DF41F5D9DE7237A689013A9266134B32AB4B4656796419B46E8378D84358
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Bogota) {. {-9223372036854775808 -17776 0 LMT}. {-2707671824 -17776 0 BMT}. {-1739041424 -18000 0 -05}. {704869200 -14400 1 -05}. {733896000 -18000 0 -05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8324
                                                                                                                                                                                                                                  Entropy (8bit):3.772029913040983
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:e45eG5cnWsGm+4I1zXN+C2mWBNQMsmNTxf6AeO+cblX:xGnWdVUC2mWBNwWTxyWR
                                                                                                                                                                                                                                  MD5:239425659E7345C757E6A44ABF258A22
                                                                                                                                                                                                                                  SHA1:9659217B4D55795333DFA5E08451B69D17F514AD
                                                                                                                                                                                                                                  SHA-256:6D6D377DDF237B1C5AB012DDDEB5F4FAA39D1D51240AA5C4C34EE96556D2D2F4
                                                                                                                                                                                                                                  SHA-512:3891D7BC1F84FF6B01B6C2DF6F0413C9E168E5B84CE445030F1B871766DD38B2FF7418501AB7C0DCEAB8381E538D65DF4E7708502EE924546A28DF1AC9BB7129
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Boise) {. {-9223372036854775808 -27889 0 LMT}. {-2717640000 -28800 0 PST}. {-1633269600 -25200 1 PDT}. {-1615129200 -28800 0 PST}. {-1601820000 -25200 1 PDT}. {-1583679600 -28800 0 PST}. {-1471788000 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-52930800 -21600 1 MDT}. {-37209600 -25200 0 MST}. {-21481200 -21600 1 MDT}. {-5760000 -25200 0 MST}. {9968400 -21600 1 MDT}. {25689600 -25200 0 MST}. {41418000 -21600 1 MDT}. {57744000 -25200 0 MST}. {73472400 -21600 1 MDT}. {89193600 -25200 0 MST}. {104922000 -21600 1 MDT}. {120643200 -25200 0 MST}. {126255600 -25200 0 MST}. {129114000 -21600 0 MDT}. {152092800 -25200 0 MST}. {162378000 -21600 1 MDT}. {183542400 -25200 0 MST}. {199270800 -21600 1 MDT}. {215596800 -25200 0 MST}. {2307
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):234
                                                                                                                                                                                                                                  Entropy (8bit):4.775296176809929
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/MQA+zJFVAIgp/MQA+z2L290BFzk5h490/MQA+zq:MBaIMY/MV+z6p/MV+z2L290rzy490/Mz
                                                                                                                                                                                                                                  MD5:861DAA3C2FFF1D3E9F81FB5C63EA71F1
                                                                                                                                                                                                                                  SHA1:8E219E63E6D7E702FD0644543E05778CE786601A
                                                                                                                                                                                                                                  SHA-256:1D32F22CF50C7586CB566E45988CA05538E61A05DF09FD8F824D870717832307
                                                                                                                                                                                                                                  SHA-512:71B47C369DF1958C560E71B114616B999FB4B091FAA6DD203B29D2555FFE419D6FC5EF82FA810DC56E6F00722E13B03BFBED2516B4C5C2321F21E03F0198B91B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Argentina/Buenos_Aires)]} {. LoadTimeZoneFile America/Argentina/Buenos_Aires.}.set TZData(:America/Buenos_Aires) $TZData(:America/Argentina/Buenos_Aires).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7487
                                                                                                                                                                                                                                  Entropy (8bit):3.787618233072156
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:OGoGm+4ILQzXN+C2mWBNQMsmNTxf6AeO+cblX:P7YUC2mWBNwWTxyWR
                                                                                                                                                                                                                                  MD5:839C797E403B4C102D466B1E759A6CC4
                                                                                                                                                                                                                                  SHA1:D95864FF269AD16B35CDAAC95AE03D8306B8DE1F
                                                                                                                                                                                                                                  SHA-256:37E219C4C7AEBCC8919293114280A247E8072F2760E69F083E9FDD6BE460B9BC
                                                                                                                                                                                                                                  SHA-512:A74F3B3C83815F62F6BDF4199EA471872AE539D6C0C595BA41E6D2DF033075D74CC00995C8F99C3ADD4B1E5E04A12D663BE9BED4CE600FC5F067D7CDDED4D7F5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Cambridge_Bay) {. {-9223372036854775808 0 0 -00}. {-1577923200 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-147891600 -18000 1 MDDT}. {-131562000 -25200 0 MST}. {325674000 -21600 1 MDT}. {341395200 -25200 0 MST}. {357123600 -21600 1 MDT}. {372844800 -25200 0 MST}. {388573200 -21600 1 MDT}. {404899200 -25200 0 MST}. {420022800 -21600 1 MDT}. {436348800 -25200 0 MST}. {452077200 -21600 1 MDT}. {467798400 -25200 0 MST}. {483526800 -21600 1 MDT}. {499248000 -25200 0 MST}. {514976400 -21600 1 MDT}. {530697600 -25200 0 MST}. {544611600 -21600 1 MDT}. {562147200 -25200 0 MST}. {576061200 -21600 1 MDT}. {594201600 -25200 0 MST}. {607510800 -21600 1 MDT}. {625651200 -25200 0 MST}. {638960400 -21600 1 MDT}. {657100800 -25200 0 MST}. {671014800 -21600 1 MDT}. {688550400 -25200 0 MST}. {
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7652
                                                                                                                                                                                                                                  Entropy (8bit):3.4267759764212906
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:ylD7ZYOtu7D/fVLF5H1RuSFuY66DCM/rDAWicDqRp5RepgK3i8kmmkniko1Kg+R7:n4jF17vArp
                                                                                                                                                                                                                                  MD5:87CB052D17717B696F3D9158B237E4FB
                                                                                                                                                                                                                                  SHA1:79B3947A50ED15C908CFC2D699D2B7F11468E7B2
                                                                                                                                                                                                                                  SHA-256:113E8ADCECE14A96261A59E0C26073EA5CFF864C4FF2DA6FAB5C61129A549043
                                                                                                                                                                                                                                  SHA-512:2BF788FD51E7268A1989F1C564E7B81B002B876381AEC561564D4BCE8D76C9D3F621A2F1AB26C1EAB5E5C64A3C41A536A1E21A5322D678CB11CB608333515144
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Campo_Grande) {. {-9223372036854775808 -13108 0 LMT}. {-1767212492 -14400 0 -04}. {-1206954000 -10800 1 -04}. {-1191358800 -14400 0 -04}. {-1175371200 -10800 1 -04}. {-1159822800 -14400 0 -04}. {-633816000 -10800 1 -04}. {-622065600 -14400 0 -04}. {-602280000 -10800 1 -04}. {-591829200 -14400 0 -04}. {-570744000 -10800 1 -04}. {-560206800 -14400 0 -04}. {-539121600 -10800 1 -04}. {-531349200 -14400 0 -04}. {-191361600 -10800 1 -04}. {-184194000 -14400 0 -04}. {-155160000 -10800 1 -04}. {-150066000 -14400 0 -04}. {-128894400 -10800 1 -04}. {-121122000 -14400 0 -04}. {-99950400 -10800 1 -04}. {-89586000 -14400 0 -04}. {-68414400 -10800 1 -04}. {-57963600 -14400 0 -04}. {499752000 -10800 1 -04}. {511239600 -14400 0 -04}. {530596800 -10800 1 -04}. {540270000 -14400 0 -04}. {562132800 -10800 1 -04}. {571201200 -14400 0 -04}. {592977600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1365
                                                                                                                                                                                                                                  Entropy (8bit):3.9551252054637245
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQseeRb/uyV3XVP/upG/u/yRXiSn/Q8Sn/mfSn/yISn/PSn/zI3Sn/RSn/lfSn/A:5i7XEaRyM/BM/mfM/1M/PM/zmM/RM/l/
                                                                                                                                                                                                                                  MD5:2EC91D30699B64FA8199004F97C63645
                                                                                                                                                                                                                                  SHA1:4C4E00857B1FB3970E7C16C4EFAA9347ED2C3629
                                                                                                                                                                                                                                  SHA-256:4EB4C729FF11E170D683310422D8F10BCE78992CF13DACCB06662308C76CCA3B
                                                                                                                                                                                                                                  SHA-512:D7811C32E4D2B3B9FAEE730D580BC813EC41B63765DE34BB3A30A0D9BBEF2F090E2DA59C6D9A4D8FC91885DDEA2B6E3B1FD3FD434E42D805AF66E578E66AE6FE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Cancun) {. {-9223372036854775808 -20824 0 LMT}. {-1514743200 -21600 0 CST}. {377935200 -18000 0 EST}. {828860400 -14400 1 EDT}. {846396000 -18000 0 EST}. {860310000 -14400 1 EDT}. {877845600 -18000 0 EST}. {891759600 -14400 1 EDT}. {902041200 -18000 0 CDT}. {909298800 -21600 0 CST}. {923212800 -18000 1 CDT}. {941353200 -21600 0 CST}. {954662400 -18000 1 CDT}. {972802800 -21600 0 CST}. {989136000 -18000 1 CDT}. {1001833200 -21600 0 CST}. {1018166400 -18000 1 CDT}. {1035702000 -21600 0 CST}. {1049616000 -18000 1 CDT}. {1067151600 -21600 0 CST}. {1081065600 -18000 1 CDT}. {1099206000 -21600 0 CST}. {1112515200 -18000 1 CDT}. {1130655600 -21600 0 CST}. {1143964800 -18000 1 CDT}. {1162105200 -21600 0 CST}. {1175414400 -18000 1 CDT}. {1193554800 -21600 0 CST}. {1207468800 -18000 1 CDT}. {1225004400 -21600 0 CST}. {1238918400 -18000 1 CD
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):274
                                                                                                                                                                                                                                  Entropy (8bit):4.527582804527589
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52909+ET2m2OHXP8Hk4lvFVFQVgIUF/R/OGWnVVFQVg2vR/O9:MBp5290QmdHXPy/ltvAYFZ/OGqVvA9/K
                                                                                                                                                                                                                                  MD5:D47486658B408AAF7F91569435B49D19
                                                                                                                                                                                                                                  SHA1:C69EDC17F2E77723A5C711342822BF21ECCB9C8E
                                                                                                                                                                                                                                  SHA-256:555A66624909220ACCCB35D852079D44944E188A81DF6A07CBA7433AC2478E5E
                                                                                                                                                                                                                                  SHA-512:35A4AF702405BD36F6EF7E42F1E1AEAD841A5710D04306C1C3390B3CC134E88F1221F284F489F6926C58E8FD50BD7E6BE0E5904AAE2ACBEA817EFCE0AAE61169
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Caracas) {. {-9223372036854775808 -16064 0 LMT}. {-2524505536 -16060 0 CMT}. {-1826739140 -16200 0 -0430}. {-157750200 -14400 0 -04}. {1197183600 -16200 0 -0430}. {1462086000 -14400 0 -04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):222
                                                                                                                                                                                                                                  Entropy (8bit):4.615632762186706
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/MMXAIVAIgp/MMXs29094SXAFB5290/MMXAv:MBaIMY/Mhp/MP290mh5290/MH
                                                                                                                                                                                                                                  MD5:359226FA8A7EAFCA0851F658B4EBBCDC
                                                                                                                                                                                                                                  SHA1:611A24C24462DF5994B5D043E65770B778A6443B
                                                                                                                                                                                                                                  SHA-256:F2782781F1FB7FD12FF85D36BB244887D1C2AD52746456B3C3FEAC2A63EC2157
                                                                                                                                                                                                                                  SHA-512:6F9DD2D1662103EC5A34A8858BDFA69AC9F74D3337052AB47EA61DC4D76216886A0644CF1284940E8862A09CBA3E0A87784DFDB6414434C92E45004AAF312614
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Argentina/Catamarca)]} {. LoadTimeZoneFile America/Argentina/Catamarca.}.set TZData(:America/Catamarca) $TZData(:America/Argentina/Catamarca).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.781235086647991
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52IAcGE91pkXGm2OHEFvpoevUdR4FIUPvGDUwXvp3VVFVGHC:SlSWB9X52909zm2OHEdGeG4vOIw/ZVVF
                                                                                                                                                                                                                                  MD5:1FFD7817EE1DC55EF72AD686749AE9CE
                                                                                                                                                                                                                                  SHA1:AE972D5395F3562F052780AD014BA2C0767943B6
                                                                                                                                                                                                                                  SHA-256:9CE77C0A01BFDA002EE3B2DCEF316DB7C9AC80B270DFC3A0D7769021E731D849
                                                                                                                                                                                                                                  SHA-512:480D8D56F7B8829F6E82D8AFF1A0A161C3C45402D85A588027E98F2FA20C6E6F35549FFC5F38F0EEA9C4190A70B334066FCD406D39FF06EE7B7855AF75CD0FC3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Cayenne) {. {-9223372036854775808 -12560 0 LMT}. {-1846269040 -14400 0 -04}. {-71092800 -10800 0 -03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):180
                                                                                                                                                                                                                                  Entropy (8bit):4.723325073771884
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0u55DdVAIg20u5AF2IAcGE91mr4IAcGEu5un:SlSWB9IZaM3y7oDdVAIgpX2909Yr490/
                                                                                                                                                                                                                                  MD5:E03755B574F4962030DB1E21D1317963
                                                                                                                                                                                                                                  SHA1:5B5FA4787DA7AE358EFEA81787EB2AB48E4D7247
                                                                                                                                                                                                                                  SHA-256:8E85F05135DB89CB304689081B22535002DBD184D5DCDBF6487CD0A2FBE4621E
                                                                                                                                                                                                                                  SHA-512:8B85E51BD8DC04AE768A4D42F8DF0E0D60F23FAB2607E3DCAD4E10695E50C2A3F2124DA7E3A87E97DB7AF090EF70C9A5B5C2D34F7D1B6F74FEFEA9148FEB15AB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Panama)]} {. LoadTimeZoneFile America/Panama.}.set TZData(:America/Cayman) $TZData(:America/Panama).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):11003
                                                                                                                                                                                                                                  Entropy (8bit):3.728817385585057
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:rXxbWziyUZB4ME9Hmp7EYQYMWUJ2eQzURWu3OabMQxXI6X8x3X3D2DgOMIOdXkqq:rXxbWziyUZB4ME9Hmp7EYQYMWUJ2eQzg
                                                                                                                                                                                                                                  MD5:6175956F3052F3BE172F6110EF6342EE
                                                                                                                                                                                                                                  SHA1:532E2600DFAFAACCD3A187A233956462383401A6
                                                                                                                                                                                                                                  SHA-256:FC172494A4943F8D1C3FC35362D96F3D12D6D352984B93BC1DE7BDCB7C85F15E
                                                                                                                                                                                                                                  SHA-512:36B47003183EB9D7886F9980538DB3BDDC231BB27D4F14006CDBE0CB9042215A02559D97085679F8320DED6109FC7745DC43859EBA99B87365B09C4526D28193
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Chicago) {. {-9223372036854775808 -21036 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-1577901600 -21600 0 CST}. {-1563724800 -18000 1 CDT}. {-1551632400 -21600 0 CST}. {-1538928000 -18000 1 CDT}. {-1520182800 -21600 0 CST}. {-1504454400 -18000 1 CDT}. {-1491757200 -21600 0 CST}. {-1473004800 -18000 1 CDT}. {-1459702800 -21600 0 CST}. {-1441555200 -18000 1 CDT}. {-1428253200 -21600 0 CST}. {-1410105600 -18000 1 CDT}. {-1396803600 -21600 0 CST}. {-1378656000 -18000 1 CDT}. {-1365354000 -21600 0 CST}. {-1347206400 -18000 1 CDT}. {-1333904400 -21600 0 CST}. {-1315152000 -18000 1 CDT}. {-1301850000 -21600 0 CST}. {-1283702400 -18000 1 CDT}. {-1270400400 -21600 0 CST}. {-1252252800 -18000 1 CDT}. {-1238950800 -21600 0 CST}. {-1220803200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6593
                                                                                                                                                                                                                                  Entropy (8bit):3.795313170000037
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:LJNfzBT8tRkfKxhzY720zaOXmlITHjLc1cb:dN18tRkfKv+2wB9h
                                                                                                                                                                                                                                  MD5:B0CA4CFF6571AFBFF25FAC72CDDB5B08
                                                                                                                                                                                                                                  SHA1:1BF3ACEC369AEA504AAA248459A115E61CF79C4B
                                                                                                                                                                                                                                  SHA-256:C689A3BEED80D26EAB96C95C85874428F80699F7E136A44377776E52B5855D00
                                                                                                                                                                                                                                  SHA-512:398496EBA4344EDF78AFBF51BD6024481D3A12546D0EE597B7C593A1CD1BF575AFDE62FFADE7A0DDFEDA79CF235612E6F4DA74D7305A6E48F5942EA10D8A4F8E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Chihuahua) {. {-9223372036854775808 -25460 0 LMT}. {-1514739600 -25200 0 MST}. {-1343066400 -21600 0 CST}. {-1234807200 -25200 0 MST}. {-1220292000 -21600 0 CST}. {-1207159200 -25200 0 MST}. {-1191344400 -21600 0 CST}. {820476000 -21600 0 CST}. {828864000 -18000 1 CDT}. {846399600 -21600 0 CST}. {860313600 -18000 1 CDT}. {877849200 -21600 0 CST}. {883634400 -21600 0 CST}. {891766800 -21600 0 MDT}. {909302400 -25200 0 MST}. {923216400 -21600 1 MDT}. {941356800 -25200 0 MST}. {954666000 -21600 1 MDT}. {972806400 -25200 0 MST}. {989139600 -21600 1 MDT}. {1001836800 -25200 0 MST}. {1018170000 -21600 1 MDT}. {1035705600 -25200 0 MST}. {1049619600 -21600 1 MDT}. {1067155200 -25200 0 MST}. {1081069200 -21600 1 MDT}. {1099209600 -25200 0 MST}. {1112518800 -21600 1 MDT}. {1130659200 -25200 0 MST}. {1143968400 -21600 1 MDT}. {1162108800 -25
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):193
                                                                                                                                                                                                                                  Entropy (8bit):4.822360211437507
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/qlfSwFVAIgp/qlfAvt2909qEac90/qlfu:MBaIMY/TwQp/tvt290Fac90/j
                                                                                                                                                                                                                                  MD5:2541EC94D1EA371AB1361118EEC98CC6
                                                                                                                                                                                                                                  SHA1:950E460C1BB680B591BA3ADA0CAA73EF07C229FE
                                                                                                                                                                                                                                  SHA-256:50E6EE06C0218FF19D5679D539983CEB2349E5D25F67FD05E142921431DC63D6
                                                                                                                                                                                                                                  SHA-512:2E6B66815565A9422015CAB8E972314055DC4141B5C21B302ABD671F30D0FBAE1A206F3474409826B65C30EDBEDD46E92A99251AB6316D59B09FC5A8095E7562
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Atikokan)]} {. LoadTimeZoneFile America/Atikokan.}.set TZData(:America/Coral_Harbour) $TZData(:America/Atikokan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):214
                                                                                                                                                                                                                                  Entropy (8bit):4.74004515366486
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/MdVAIgp/MOF29093+90/Msn:MBaIMY/M4p/MOF290c90/Ms
                                                                                                                                                                                                                                  MD5:89870B2001C2EE737755A692E7CA2F18
                                                                                                                                                                                                                                  SHA1:F67F6C22BF681C105068BEEB494A59B3809C5ED8
                                                                                                                                                                                                                                  SHA-256:38C3DD7DAF75DBF0179DBFC387CE7E64678232497AF0DACF35DC76050E9424F7
                                                                                                                                                                                                                                  SHA-512:EFA8A5A90BE6FAAA7C6F5F39CBBBA3C7D44C7943E1BB1B0F7E966FEE4F00F0E4BF1D999A377D4E5230271B120B059EB020BD93E7DA46CF1FFA54AB13D7EC3FFE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Argentina/Cordoba)]} {. LoadTimeZoneFile America/Argentina/Cordoba.}.set TZData(:America/Cordoba) $TZData(:America/Argentina/Cordoba).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):416
                                                                                                                                                                                                                                  Entropy (8bit):4.443696146912203
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5290l0TmdHd5PZ6kibvI8/uFn/mSU/uFn/i/uFn/4Y8/uFn//DVn:cQmAed9Z6n5Sn/mtSn/iSn/4JSn/bh
                                                                                                                                                                                                                                  MD5:D47A1FBA5AD701E1CA168A356D0DA0A9
                                                                                                                                                                                                                                  SHA1:6738EA6B4F54CC76B9723917AA373034F6865AF1
                                                                                                                                                                                                                                  SHA-256:51F08C1671F07D21D69E2B7868AA5B9BDBFA6C31D57EB84EB5FF37A06002C5CD
                                                                                                                                                                                                                                  SHA-512:DB6AD81466500F22820941DF3369155BA03CFA42FA9D267984A28A6D15F88E1A71625E3DC578370B5F97727355EBB7C338482FA33A7701ADB85A160C09BAD232
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Costa_Rica) {. {-9223372036854775808 -20173 0 LMT}. {-2524501427 -20173 0 SJMT}. {-1545071027 -21600 0 CST}. {288770400 -18000 1 CDT}. {297234000 -21600 0 CST}. {320220000 -18000 1 CDT}. {328683600 -21600 0 CST}. {664264800 -18000 1 CDT}. {678344400 -21600 0 CST}. {695714400 -18000 1 CDT}. {700635600 -21600 0 CST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):211
                                                                                                                                                                                                                                  Entropy (8bit):4.798554218839104
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52909ovTm2OHpcHvvPagcyEXC/vHcQCi:MBp52900mdHpcHPagPECvHl
                                                                                                                                                                                                                                  MD5:9E3726148A53940507998FA1A5EEE6DB
                                                                                                                                                                                                                                  SHA1:2493B72DF895ED2AE91D09D43BDDADDB41E4DEBC
                                                                                                                                                                                                                                  SHA-256:E809F227E92542C6FB4BAC82E6079661EEF7700964079AA4D7E289B5B400EC49
                                                                                                                                                                                                                                  SHA-512:F5ED4085160A06DE672DB93CEE700C420D0438DE9AC3548B291DA236AA8CCC84F97270DA3956E49432AE1E281CCECEB6DF92E71EB305106655B4DF231E04B558
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Creston) {. {-9223372036854775808 -27964 0 LMT}. {-2713882436 -25200 0 MST}. {-1680454800 -28800 0 PST}. {-1627833600 -25200 0 MST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7646
                                                                                                                                                                                                                                  Entropy (8bit):3.4194836403778353
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:+lD7ZYOtu7D/fVLF5H1RuSFuY66DCVDAWicDqRp5RepgK3i8kmmkniko1Kg+R4hu:3jF17vArp
                                                                                                                                                                                                                                  MD5:7309EBE8210C3C84C24D459289484EFA
                                                                                                                                                                                                                                  SHA1:31EFE19E3CA2DB512C7AC9CAFD72991EF0517FD3
                                                                                                                                                                                                                                  SHA-256:FE7543FF576D7EDC3A3FF82759E5C244DE8EB57A95744E20610CEDF6E29AB4C9
                                                                                                                                                                                                                                  SHA-512:41C94E4093F015B61ACEFCEA067C101AA1ECB855789CFDB8FA4D17589D20868FB7A1456D21C90B5261445D970E5E7F134CBAF17EA926278C9E6DFC471D29F896
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Cuiaba) {. {-9223372036854775808 -13460 0 LMT}. {-1767212140 -14400 0 -04}. {-1206954000 -10800 1 -04}. {-1191358800 -14400 0 -04}. {-1175371200 -10800 1 -04}. {-1159822800 -14400 0 -04}. {-633816000 -10800 1 -04}. {-622065600 -14400 0 -04}. {-602280000 -10800 1 -04}. {-591829200 -14400 0 -04}. {-570744000 -10800 1 -04}. {-560206800 -14400 0 -04}. {-539121600 -10800 1 -04}. {-531349200 -14400 0 -04}. {-191361600 -10800 1 -04}. {-184194000 -14400 0 -04}. {-155160000 -10800 1 -04}. {-150066000 -14400 0 -04}. {-128894400 -10800 1 -04}. {-121122000 -14400 0 -04}. {-99950400 -10800 1 -04}. {-89586000 -14400 0 -04}. {-68414400 -10800 1 -04}. {-57963600 -14400 0 -04}. {499752000 -10800 1 -04}. {511239600 -14400 0 -04}. {530596800 -10800 1 -04}. {540270000 -14400 0 -04}. {562132800 -10800 1 -04}. {571201200 -14400 0 -04}. {592977600 -1080
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.858195118945703
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52IAcGE9CvjEwcXGm2OHCevUd5xF9vFVFIVgYd/iQG3VFpRR/r:SlSWB9X52909C4wTm2OHjyxzFQVgIUFp
                                                                                                                                                                                                                                  MD5:CE0F18F27502E771B27236C5BF7D3317
                                                                                                                                                                                                                                  SHA1:D2E68415B8544A8BAC2A4F335854FC048BD4B34C
                                                                                                                                                                                                                                  SHA-256:118EC9D89937FDA05FCE45F694F8C3841664BBE9DFADB86347B375BF437F9BD6
                                                                                                                                                                                                                                  SHA-512:B04B5DAB30384FF05ABFC235DA4F9BFE96F400076DEB7CBBA0938F93E66BFF5E86B18E95E9BC0448D812722C8F2D4AFD78AC75180FD80D992F96DFA0CEC156AC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Curacao) {. {-9223372036854775808 -16547 0 LMT}. {-1826738653 -16200 0 -0430}. {-157750200 -14400 0 AST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1089
                                                                                                                                                                                                                                  Entropy (8bit):3.793747183330894
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQZefXQgiu2kPIw1Dtc7UXxH9vC0gdtiyW8RWK79ET7cSXKIuXvY:52XQgiu2kgw1DtuyxdvC0gdtiyW8RB7S
                                                                                                                                                                                                                                  MD5:E83072C1351121C5CFD74E110ECA9B4B
                                                                                                                                                                                                                                  SHA1:360B468851EBFF266E4A8F40FE5D196BC6809E65
                                                                                                                                                                                                                                  SHA-256:6A12AD52CBCF0B3F8BB449C7BC51A784BE560F4BD13545D04426E76B2511D8F9
                                                                                                                                                                                                                                  SHA-512:539C53AA1D02E3AABF65873CA830782697AC9D55EC6694B68B95C325608F8703882B1182215D2B4E2B6066784AC880BCF0F4EBC5A72B2E637BD9B2C3A61D2979
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Danmarkshavn) {. {-9223372036854775808 -4480 0 LMT}. {-1686091520 -10800 0 -03}. {323845200 -7200 0 -02}. {338950800 -10800 0 -03}. {354675600 -7200 1 -02}. {370400400 -10800 0 -03}. {386125200 -7200 1 -02}. {401850000 -10800 0 -03}. {417574800 -7200 1 -02}. {433299600 -10800 0 -03}. {449024400 -7200 1 -02}. {465354000 -10800 0 -03}. {481078800 -7200 1 -02}. {496803600 -10800 0 -03}. {512528400 -7200 1 -02}. {528253200 -10800 0 -03}. {543978000 -7200 1 -02}. {559702800 -10800 0 -03}. {575427600 -7200 1 -02}. {591152400 -10800 0 -03}. {606877200 -7200 1 -02}. {622602000 -10800 0 -03}. {638326800 -7200 1 -02}. {654656400 -10800 0 -03}. {670381200 -7200 1 -02}. {686106000 -10800 0 -03}. {701830800 -7200 1 -02}. {717555600 -10800 0 -03}. {733280400 -7200 1 -02}. {749005200 -10800 0 -03}. {764730000 -7200 1 -02}. {780454800 -10800 0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7609
                                                                                                                                                                                                                                  Entropy (8bit):3.785302701923574
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:nxr+C2ZCHtffWsBNwj/lpmlOxGcKcnRH31t+ucgge:nx/Nf+aNwj/lpmlOxnKcndIG
                                                                                                                                                                                                                                  MD5:4DBA9C83ECAD5B5A099CC1AA78D391B0
                                                                                                                                                                                                                                  SHA1:FFCC77D7964BD16BD8A554FB437BCF4F2FC8958E
                                                                                                                                                                                                                                  SHA-256:3A89A6834DDBE4A3A6A1CB8C1A1F9579259E7FD6C6C55DE21DCD4807753D8E48
                                                                                                                                                                                                                                  SHA-512:21212AFE8917C0F3BBED433B510C4FCE671B0DA887A1C7338A18CD5409B1A95E766510A9E636E5AA3AB0BA21D7D2C00A462FEBB10D4567A343B85AFE6A3E2394
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Dawson) {. {-9223372036854775808 -33460 0 LMT}. {-2188996940 -32400 0 YST}. {-1632056400 -28800 1 YDT}. {-1615125600 -32400 0 YST}. {-1596978000 -28800 1 YDT}. {-1583164800 -32400 0 YST}. {-880203600 -28800 1 YWT}. {-769395600 -28800 1 YPT}. {-765381600 -32400 0 YST}. {-147884400 -25200 1 YDDT}. {-131554800 -32400 0 YST}. {315561600 -28800 0 PST}. {325677600 -25200 1 PDT}. {341398800 -28800 0 PST}. {357127200 -25200 1 PDT}. {372848400 -28800 0 PST}. {388576800 -25200 1 PDT}. {404902800 -28800 0 PST}. {420026400 -25200 1 PDT}. {436352400 -28800 0 PST}. {452080800 -25200 1 PDT}. {467802000 -28800 0 PST}. {483530400 -25200 1 PDT}. {499251600 -28800 0 PST}. {514980000 -25200 1 PDT}. {530701200 -28800 0 PST}. {544615200 -25200 1 PDT}. {562150800 -28800 0 PST}. {576064800 -25200 1 PDT}. {594205200 -28800 0 PST}. {607514400 -25200 1 PDT}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1876
                                                                                                                                                                                                                                  Entropy (8bit):3.9458112723626755
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ4eJ58IlJ14RsT8X+km8VnynhBZ2c4Y+O4A5W5xDICW2n7oZA8QZFaIOvkty1H2:5DH0yIRkf12fZGJ5LB6xfZ89Y
                                                                                                                                                                                                                                  MD5:D7E4978775F290809B7C042674F46903
                                                                                                                                                                                                                                  SHA1:E94DB1EBB6A1594ED1A5AEA48B52395482D06085
                                                                                                                                                                                                                                  SHA-256:2E6CFFE8E0C1FE93F55B1BD01F96AA1F3CE645BC802C061CB4917318E30C4494
                                                                                                                                                                                                                                  SHA-512:1FF3CD58A4C4DEC7538F0816E93E6577C51B0045CF36190FF4D327E81FB8282ADDB0EF20BD78A838ABD507EBAD1C187F2A20CC7840E2325B9C326EC449897B45
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Dawson_Creek) {. {-9223372036854775808 -28856 0 LMT}. {-2713881544 -28800 0 PST}. {-1632060000 -25200 1 PDT}. {-1615129200 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-725817600 -28800 0 PST}. {-715788000 -25200 1 PDT}. {-702486000 -28800 0 PST}. {-684338400 -25200 1 PDT}. {-671036400 -28800 0 PST}. {-652888800 -25200 1 PDT}. {-639586800 -28800 0 PST}. {-620834400 -25200 1 PDT}. {-608137200 -28800 0 PST}. {-589384800 -25200 1 PDT}. {-576082800 -28800 0 PST}. {-557935200 -25200 1 PDT}. {-544633200 -28800 0 PST}. {-526485600 -25200 1 PDT}. {-513183600 -28800 0 PST}. {-495036000 -25200 1 PDT}. {-481734000 -28800 0 PST}. {-463586400 -25200 1 PDT}. {-450284400 -28800 0 PST}. {-431532000 -25200 1 PDT}. {-418230000 -28800 0 PST}. {-400082400 -25200 1 PDT}. {-386780400 -28800 0 PST}. {-
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8629
                                                                                                                                                                                                                                  Entropy (8bit):3.76966035849006
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:4cGbc2sGm+4I1zXN+C2mWBNQMsmNTxf6AeO+cblX:4c2dVUC2mWBNwWTxyWR
                                                                                                                                                                                                                                  MD5:F641A7F5DE8FCF4ADC1E5A1A2C9DEC53
                                                                                                                                                                                                                                  SHA1:B013EBBE8002C91C0C45A2D389245A1A9194077A
                                                                                                                                                                                                                                  SHA-256:DF5459068DB3C771E41BE8D62FB89A2822CB2A33CF9A5640C6C666AB20ECE608
                                                                                                                                                                                                                                  SHA-512:C2EA07FF21FD6D1A45A87C6AD85DD3929C2B56E66A52D23103DDFF7B2B3B6433EC5EBFC17BED0F9C0A9AF036F0DF965E12EA3D4463207A128AEF5F6BC12970D7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Denver) {. {-9223372036854775808 -25196 0 LMT}. {-2717643600 -25200 0 MST}. {-1633273200 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1601823600 -21600 1 MDT}. {-1583683200 -25200 0 MST}. {-1577898000 -25200 0 MST}. {-1570374000 -21600 1 MDT}. {-1551628800 -25200 0 MST}. {-1538924400 -21600 1 MDT}. {-1534089600 -25200 0 MST}. {-883587600 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-757357200 -25200 0 MST}. {-147884400 -21600 1 MDT}. {-131558400 -25200 0 MST}. {-116434800 -21600 1 MDT}. {-100108800 -25200 0 MST}. {-94669200 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-52930800 -21600 1 MDT}. {-37209600 -25200 0 MST}. {-21481200 -21600 1 MDT}. {-5760000 -25200 0 MST}. {9968400 -21600 1 MDT}. {25689600 -25200 0 MST}. {41418000 -21600 1 MDT}. {57744000 -25200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8010
                                                                                                                                                                                                                                  Entropy (8bit):3.742999180017181
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:FVzApQaC3Xm8sHRwvOTFhP5S+ijFnRaJeaX1eyDt:FVspQrn+qvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:177B0815E8BD6BFA6E62895FE12A61E5
                                                                                                                                                                                                                                  SHA1:EC2400FA644023D6B3100B52381DB65EAF2606F0
                                                                                                                                                                                                                                  SHA-256:402EC5AB0E99EF6EBB33F4D482EEA5198EC686C7EAE75FC4F7D9B4EF4AC0A9E9
                                                                                                                                                                                                                                  SHA-512:CFA4226A21FDB23C723335F7385EA15436D8A0752EE50C67DA4C1D839BFFD4792EE9AB6E408498CD06C6B8A99A96E95E0B591F7EA17B41C1895ED396438C6D5A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Detroit) {. {-9223372036854775808 -19931 0 LMT}. {-2051202469 -21600 0 CST}. {-1724083200 -18000 0 EST}. {-883594800 -18000 0 EST}. {-880218000 -14400 1 EWT}. {-769395600 -14400 1 EPT}. {-765396000 -18000 0 EST}. {-757364400 -18000 0 EST}. {-684349200 -14400 1 EDT}. {-671047200 -18000 0 EST}. {94712400 -18000 0 EST}. {104914800 -14400 1 EDT}. {120636000 -18000 0 EST}. {126687600 -14400 1 EDT}. {152085600 -18000 0 EST}. {157784400 -18000 0 EST}. {167814000 -14400 0 EDT}. {183535200 -18000 0 EST}. {199263600 -14400 1 EDT}. {215589600 -18000 0 EST}. {230713200 -14400 1 EDT}. {247039200 -18000 0 EST}. {262767600 -14400 1 EDT}. {278488800 -18000 0 EST}. {294217200 -14400 1 EDT}. {309938400 -18000 0 EST}. {325666800 -14400 1 EDT}. {341388000 -18000 0 EST}. {357116400 -14400 1 EDT}. {372837600 -18000 0 EST}. {388566000 -14400 1 EDT}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):203
                                                                                                                                                                                                                                  Entropy (8bit):4.856609165175433
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290TL3290e/:MBaIMY9QpI290Tr290O
                                                                                                                                                                                                                                  MD5:F85ADC16127A74C9B35D16C631E11F4F
                                                                                                                                                                                                                                  SHA1:F7716E20F546AA04697FB0F4993A14BAFDD1825E
                                                                                                                                                                                                                                  SHA-256:67ACF237962E3D12E0C746AEDC7CDBC8579DC7C0A7998AC6B6E169C58A687C17
                                                                                                                                                                                                                                  SHA-512:89E8F9DC6A306912B2DAEE77705E2DCD76E32F403352C23ED6BE34F8BEBB12C3604C20DA11DB921553D20E3FC43EC7984C7103D8D1396AB83B104E70BA6D13B1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Dominica) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8435
                                                                                                                                                                                                                                  Entropy (8bit):3.7724320820194475
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:7tGVgeb0Gm+qI1zXN+C2mWBNQMsmNTxf6AeO+cblX:7heJ/UC2mWBNwWTxyWR
                                                                                                                                                                                                                                  MD5:FECBDD64036247B2FBB723ADD8F798F6
                                                                                                                                                                                                                                  SHA1:60B1719958AD6151CDB174A319A396D5F48C7CF1
                                                                                                                                                                                                                                  SHA-256:EC95041E0A97B37A60EF16A6FA2B6BCB1EBEFABBC9468B828D0F467595132BC2
                                                                                                                                                                                                                                  SHA-512:7CF94EC5040F4C8FA3C6ED30CFDAB59A199C18AA0CDA9A66D1A477F15563D2B7CB872CEEF1E2295E0F3B9A85508A03AEC29E3ECEBE11D9B089A92794D510BA00
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Edmonton) {. {-9223372036854775808 -27232 0 LMT}. {-1998663968 -25200 0 MST}. {-1632063600 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1600614000 -21600 1 MDT}. {-1596816000 -25200 0 MST}. {-1567954800 -21600 1 MDT}. {-1551628800 -25200 0 MST}. {-1536505200 -21600 1 MDT}. {-1523203200 -25200 0 MST}. {-1504450800 -21600 1 MDT}. {-1491753600 -25200 0 MST}. {-1473001200 -21600 1 MDT}. {-1459699200 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-715791600 -21600 1 MDT}. {-702489600 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-21481200 -21600 1 MDT}. {-5760000 -25200 0 MST}. {73472400 -21600 1 MDT}. {89193600 -25200 0 MST}. {104922000 -21600 1 MDT}. {120643200 -25200 0 MST}. {136371600 -21600 1 MDT}. {152092800 -25200 0 MST}. {167821200 -21600 1 MDT}. {183542400
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1189
                                                                                                                                                                                                                                  Entropy (8bit):3.7118381376452767
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQOX9eptXyss/u/C5/ukCI/uiCk/u8CHe/uOCXs/um4Co/uN3Cc/ux8CL/uiFCyL:5OXUCs5IlTToo4mdGFtapG8dtedJ9fO2
                                                                                                                                                                                                                                  MD5:D6945DF73BA7E12D3B23889CC34F6CFB
                                                                                                                                                                                                                                  SHA1:8C1317F3EF82225A14751318DFDA8904F908C457
                                                                                                                                                                                                                                  SHA-256:71F15943EAD942224B8807CCBB21F9AE34F04619FD76176404633BDB49D9E88C
                                                                                                                                                                                                                                  SHA-512:088C2D7BE44650A044B7632337A1FF8C3CF8A6188F24507C846B9B648FE796466B22D4A322B602B75C2943653FC43C7B9A99AE0AACF9AB7BCC86388EC3953F8A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Eirunepe) {. {-9223372036854775808 -16768 0 LMT}. {-1767208832 -18000 0 -05}. {-1206950400 -14400 1 -05}. {-1191355200 -18000 0 -05}. {-1175367600 -14400 1 -05}. {-1159819200 -18000 0 -05}. {-633812400 -14400 1 -05}. {-622062000 -18000 0 -05}. {-602276400 -14400 1 -05}. {-591825600 -18000 0 -05}. {-570740400 -14400 1 -05}. {-560203200 -18000 0 -05}. {-539118000 -14400 1 -05}. {-531345600 -18000 0 -05}. {-191358000 -14400 1 -05}. {-184190400 -18000 0 -05}. {-155156400 -14400 1 -05}. {-150062400 -18000 0 -05}. {-128890800 -14400 1 -05}. {-121118400 -18000 0 -05}. {-99946800 -14400 1 -05}. {-89582400 -18000 0 -05}. {-68410800 -14400 1 -05}. {-57960000 -18000 0 -05}. {499755600 -14400 1 -05}. {511243200 -18000 0 -05}. {530600400 -14400 1 -05}. {540273600 -18000 0 -05}. {562136400 -14400 1 -05}. {571204800 -18000 0 -05}. {590040000 -18
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):269
                                                                                                                                                                                                                                  Entropy (8bit):4.7060952459188305
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X529078iwTm2OHvJ4YRIgdrV/uFn/acD3/uFn/sVn:MBp5290785mdHx4YlB/uFn/z/uFn/U
                                                                                                                                                                                                                                  MD5:77BE2E0759A3B7227B4DAC601A670D03
                                                                                                                                                                                                                                  SHA1:1FB09211F291E5B1C5CC9848EB53106AF48EE830
                                                                                                                                                                                                                                  SHA-256:40994535FE02326EA9E373F54CB60804BA7AE7162B52EA5F73497E7F72F2D482
                                                                                                                                                                                                                                  SHA-512:EB5E6A4A912053E399F6225A02DDC524A223D4A5724165CAD9009F1FA10B042F971E52CE17B395A86BC80FCC6897FD2CCC3B00708506FEF39E4D71812F5DF595
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/El_Salvador) {. {-9223372036854775808 -21408 0 LMT}. {-1546279392 -21600 0 CST}. {547020000 -18000 1 CDT}. {559717200 -21600 0 CST}. {578469600 -18000 1 CDT}. {591166800 -21600 0 CST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.786739478919165
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0qfSwVAIg20qfo2IAcGE7JM7QIAcGEqfu:SlSWB9IZaM3y7eHVAIgpeo2907390eu
                                                                                                                                                                                                                                  MD5:74AB4664E80A145D808CAB004A22859B
                                                                                                                                                                                                                                  SHA1:2AF7665C4E155A227B3F76D1C4BC87854C25A6CB
                                                                                                                                                                                                                                  SHA-256:BDD0893AA5D170F388B1E93CE5FE2EDF438866707E52033E49898AFC499F86C5
                                                                                                                                                                                                                                  SHA-512:CCC2E75E07BA1CAAFD1149A22D07668D191594272922AA2A1CE6DE628A8FF49AD90AA8BFE75C005328820C700B991AD87A6F40DEB5AD519B2708D8F7BF04E5A0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Tijuana)]} {. LoadTimeZoneFile America/Tijuana.}.set TZData(:America/Ensenada) $TZData(:America/Tijuana).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4427
                                                                                                                                                                                                                                  Entropy (8bit):3.8109873978594053
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5aIl06OIRkf12fZGJ5LB6xfZ89Cf5udCLA9ZClqs/K+ff0t9:sIlWf/5LB6xR89C8CgZCHtffW9
                                                                                                                                                                                                                                  MD5:90BBD338049233FAC5596CC63AA0D5B6
                                                                                                                                                                                                                                  SHA1:D96282F5B57CBF823D5A1C1FDDE7907B74DAD770
                                                                                                                                                                                                                                  SHA-256:DD21597BA97FD6591750E83CC00773864D658F32653017C4B52285670FFE52E3
                                                                                                                                                                                                                                  SHA-512:3B0F5801E55EBBB7B4C0F74DDBD3469B8F4C2BFC1B44CC80B0D36DA2152C837C8176695945F61FA75664C04F1266BCA0564815307A2C27E783CD3348C4451E4A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Fort_Nelson) {. {-9223372036854775808 -29447 0 LMT}. {-2713880953 -28800 0 PST}. {-1632060000 -25200 1 PDT}. {-1615129200 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-757353600 -28800 0 PST}. {-725817600 -28800 0 PST}. {-715788000 -25200 1 PDT}. {-702486000 -28800 0 PST}. {-684338400 -25200 1 PDT}. {-671036400 -28800 0 PST}. {-652888800 -25200 1 PDT}. {-639586800 -28800 0 PST}. {-620834400 -25200 1 PDT}. {-608137200 -28800 0 PST}. {-589384800 -25200 1 PDT}. {-576082800 -28800 0 PST}. {-557935200 -25200 1 PDT}. {-544633200 -28800 0 PST}. {-526485600 -25200 1 PDT}. {-513183600 -28800 0 PST}. {-495036000 -25200 1 PDT}. {-481734000 -28800 0 PST}. {-463586400 -25200 1 PDT}. {-450284400 -28800 0 PST}. {-431532000 -25200 1 PDT}. {-418230000 -28800 0 PST}. {-400082400 -25200 1 PDT}. {-3
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):226
                                                                                                                                                                                                                                  Entropy (8bit):4.730673843485836
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y73GK7mFVAIgp3GKBL290HXYAp4903GK1:MBaIMY3GK7Hp3GKBL290Hz4903GK1
                                                                                                                                                                                                                                  MD5:4685E4E850E0B6669F72B8E1B4314A0A
                                                                                                                                                                                                                                  SHA1:BC6CCD58A2977A1E125B21D7B8FD57E800E624E1
                                                                                                                                                                                                                                  SHA-256:D35F335D6F575F95CEA4FF53382C0BE0BE94BE7EB8B1E0CA3B7C50E8F7614E4E
                                                                                                                                                                                                                                  SHA-512:867003B33A5FC6E42D546FBFC7A8AB351DE72232B89BA1BEC6DB566F6DCE135E65C08DE9112837190EB21D677E2F83E7E0F6049EC70CB9E36F223DE3A68E000A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Indiana/Indianapolis)]} {. LoadTimeZoneFile America/Indiana/Indianapolis.}.set TZData(:America/Fort_Wayne) $TZData(:America/Indiana/Indianapolis).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1375
                                                                                                                                                                                                                                  Entropy (8bit):3.695923796037783
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQVeVc4h1u80V2dBUGphmC17ewGtN3rvIh0VBHZDIOXqWoN:5b4h19U2dBUGrmO7XGtN3kh0VBHZUwqX
                                                                                                                                                                                                                                  MD5:2BCCE3C71898F3D7F2327419950C5838
                                                                                                                                                                                                                                  SHA1:CE45568E951C227CB3D88D20B337E5E1E1D4B1EF
                                                                                                                                                                                                                                  SHA-256:AA2CF8DA8D63FC4DE912A4F220CF7E49379021F5E51ABA1AFCFC7C9164D5A381
                                                                                                                                                                                                                                  SHA-512:420066E5D39446AA53547CBF1A015A4745F02D1059B2530B7735AC4C28BD2BFC431AEB7531C2C49C2BDF8E31405F15717D88DE0DE3F5F42BAA96A8289A014D06
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Fortaleza) {. {-9223372036854775808 -9240 0 LMT}. {-1767216360 -10800 0 -03}. {-1206957600 -7200 1 -03}. {-1191362400 -10800 0 -03}. {-1175374800 -7200 1 -03}. {-1159826400 -10800 0 -03}. {-633819600 -7200 1 -03}. {-622069200 -10800 0 -03}. {-602283600 -7200 1 -03}. {-591832800 -10800 0 -03}. {-570747600 -7200 1 -03}. {-560210400 -10800 0 -03}. {-539125200 -7200 1 -03}. {-531352800 -10800 0 -03}. {-191365200 -7200 1 -03}. {-184197600 -10800 0 -03}. {-155163600 -7200 1 -03}. {-150069600 -10800 0 -03}. {-128898000 -7200 1 -03}. {-121125600 -10800 0 -03}. {-99954000 -7200 1 -03}. {-89589600 -10800 0 -03}. {-68418000 -7200 1 -03}. {-57967200 -10800 0 -03}. {499748400 -7200 1 -03}. {511236000 -10800 0 -03}. {530593200 -7200 1 -03}. {540266400 -10800 0 -03}. {562129200 -7200 1 -03}. {571197600 -10800 0 -03}. {592974000 -7200 1 -03}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8099
                                                                                                                                                                                                                                  Entropy (8bit):3.737123408653655
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:C1V2eXXnqvlrPGgFEUlpde9pXbO53oVmM7IEc2fVGYu2yeB/T/eleWmBk81kS/kQ:CDJv
                                                                                                                                                                                                                                  MD5:3A839112950BFDFD3B5FBD440A2981E4
                                                                                                                                                                                                                                  SHA1:FFDF034F7E26647D1C18C1F6C49C776AD5BA93ED
                                                                                                                                                                                                                                  SHA-256:3D0325012AB7076FB31A68E33EE0EABC8556DFA78FBA16A3E41F986D523858FF
                                                                                                                                                                                                                                  SHA-512:1E06F4F607252C235D2D69E027D7E0510027D8DB0EE49CF291C39D6FD010868EF6899437057DA489DD30981949243DDFA6599FD07CE80E05A1994147B78A76CE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Glace_Bay) {. {-9223372036854775808 -14388 0 LMT}. {-2131646412 -14400 0 AST}. {-1632074400 -10800 1 ADT}. {-1615143600 -14400 0 AST}. {-880221600 -10800 1 AWT}. {-769395600 -10800 1 APT}. {-765399600 -14400 0 AST}. {-536443200 -14400 0 AST}. {-526500000 -10800 1 ADT}. {-513198000 -14400 0 AST}. {-504907200 -14400 0 AST}. {63086400 -14400 0 AST}. {73461600 -10800 1 ADT}. {89182800 -14400 0 AST}. {104911200 -10800 1 ADT}. {120632400 -14400 0 AST}. {126244800 -14400 0 AST}. {136360800 -10800 1 ADT}. {152082000 -14400 0 AST}. {167810400 -10800 1 ADT}. {183531600 -14400 0 AST}. {199260000 -10800 1 ADT}. {215586000 -14400 0 AST}. {230709600 -10800 1 ADT}. {247035600 -14400 0 AST}. {262764000 -10800 1 ADT}. {278485200 -14400 0 AST}. {294213600 -10800 1 ADT}. {309934800 -14400 0 AST}. {325663200 -10800 1 ADT}. {341384400 -14400 0 AST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7186
                                                                                                                                                                                                                                  Entropy (8bit):3.4539479411234977
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:HzC1RFbvHQbnRJ2N+f4hQAa3/paCxwPQg07VvN/W5ylGiGJ3G5cGKQWaT7dZV4gF:t5lfDARzJXC
                                                                                                                                                                                                                                  MD5:F7C502D77495455080AC3125CE2B42EA
                                                                                                                                                                                                                                  SHA1:B4883AF71068903AFA372DBFA9E73A39B658A8FF
                                                                                                                                                                                                                                  SHA-256:058FBB47D5CD3001C0E5A0B5D92ACE1F8A720527A673A78AB71925198AC0ACA1
                                                                                                                                                                                                                                  SHA-512:B0361D7FB7B02C996B9E608F9B8B1D8DB76FC7D298FA9AC841C4C51A0469FF05A06E0F7829E6C7D810D13BDF3B792A9547B70F6721CA9D7544CBD94028364CAB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Godthab) {. {-9223372036854775808 -12416 0 LMT}. {-1686083584 -10800 0 -03}. {323845200 -7200 0 -02}. {338950800 -10800 0 -03}. {354675600 -7200 1 -02}. {370400400 -10800 0 -03}. {386125200 -7200 1 -02}. {401850000 -10800 0 -03}. {417574800 -7200 1 -02}. {433299600 -10800 0 -03}. {449024400 -7200 1 -02}. {465354000 -10800 0 -03}. {481078800 -7200 1 -02}. {496803600 -10800 0 -03}. {512528400 -7200 1 -02}. {528253200 -10800 0 -03}. {543978000 -7200 1 -02}. {559702800 -10800 0 -03}. {575427600 -7200 1 -02}. {591152400 -10800 0 -03}. {606877200 -7200 1 -02}. {622602000 -10800 0 -03}. {638326800 -7200 1 -02}. {654656400 -10800 0 -03}. {670381200 -7200 1 -02}. {686106000 -10800 0 -03}. {701830800 -7200 1 -02}. {717555600 -10800 0 -03}. {733280400 -7200 1 -02}. {749005200 -10800 0 -03}. {764730000 -7200 1 -02}. {780454800 -10800 0 -03
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10015
                                                                                                                                                                                                                                  Entropy (8bit):3.780383775128893
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:z9zdvd8mSGDcfnrpbXXMqvlrPGgFEUlpd8ESeYPiVFuT/eleWmBk81kS/kV6kefD:z9zdvd7SGgcESeYPiV2Jv
                                                                                                                                                                                                                                  MD5:77DEEF08876F92042F71E1DEFA666857
                                                                                                                                                                                                                                  SHA1:7E21B51B3ED8EBEB85193374174C6E2BCA7FEB7F
                                                                                                                                                                                                                                  SHA-256:87E9C6E265BFA58885FBEC128263D5E5D86CC32B8FFEDECAFE96F773192C18BE
                                                                                                                                                                                                                                  SHA-512:C9AB8C9147354A388AEC5FE04C6C5317481478A07893461706CDC9FD5B42E31733EAC01C95C357F3C5DC3556C49F20374F58A6E0A120755D5E96744DE3A95A81
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Goose_Bay) {. {-9223372036854775808 -14500 0 LMT}. {-2713895900 -12652 0 NST}. {-1640982548 -12652 0 NST}. {-1632076148 -9052 1 NDT}. {-1615145348 -12652 0 NST}. {-1609446548 -12652 0 NST}. {-1096921748 -12600 0 NST}. {-1072989000 -12600 0 NST}. {-1061670600 -9000 1 NDT}. {-1048973400 -12600 0 NST}. {-1030221000 -9000 1 NDT}. {-1017523800 -12600 0 NST}. {-998771400 -9000 1 NDT}. {-986074200 -12600 0 NST}. {-966717000 -9000 1 NDT}. {-954624600 -12600 0 NST}. {-935267400 -9000 1 NDT}. {-922570200 -12600 0 NST}. {-903817800 -9000 1 NDT}. {-891120600 -12600 0 NST}. {-872368200 -9000 0 NWT}. {-769395600 -9000 1 NPT}. {-765401400 -12600 0 NST}. {-757369800 -12600 0 NST}. {-746044200 -9000 1 NDT}. {-733347000 -12600 0 NST}. {-714594600 -9000 1 NDT}. {-701897400 -12600 0 NST}. {-683145000 -9000 1 NDT}. {-670447800 -12600 0 NST}. {-6516954
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7307
                                                                                                                                                                                                                                  Entropy (8bit):3.755018614919114
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:hrZaC3Xm8sHRyvOTFhP5S+ijFnRaJeaX1eyDt:htrn+cvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:8582299C1262010B6843306D65DB436C
                                                                                                                                                                                                                                  SHA1:70DB6B507D7F51B1E2C96E087CD7987EB69E9A1D
                                                                                                                                                                                                                                  SHA-256:7CFBA4D1B1E6106A0EC6D6B5600791D6A33AD527B7D47325C3AB9524B17B1829
                                                                                                                                                                                                                                  SHA-512:CC12912C38D85B23242C69211BA2B58167C55836D51DB02E6D820CDBD6368F835893AF656FC81F73EA745FD786E9134EC4A3E8D325D1515A01540E8A7EBEF03B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Grand_Turk) {. {-9223372036854775808 -17072 0 LMT}. {-2524504528 -18430 0 KMT}. {-1827687170 -18000 0 EST}. {284014800 -18000 0 EST}. {294217200 -14400 1 EDT}. {309938400 -18000 0 EST}. {325666800 -14400 1 EDT}. {341388000 -18000 0 EST}. {357116400 -14400 1 EDT}. {372837600 -18000 0 EST}. {388566000 -14400 1 EDT}. {404892000 -18000 0 EST}. {420015600 -14400 1 EDT}. {436341600 -18000 0 EST}. {452070000 -14400 1 EDT}. {467791200 -18000 0 EST}. {483519600 -14400 1 EDT}. {499240800 -18000 0 EST}. {514969200 -14400 1 EDT}. {530690400 -18000 0 EST}. {544604400 -14400 1 EDT}. {562140000 -18000 0 EST}. {576054000 -14400 1 EDT}. {594194400 -18000 0 EST}. {607503600 -14400 1 EDT}. {625644000 -18000 0 EST}. {638953200 -14400 1 EDT}. {657093600 -18000 0 EST}. {671007600 -14400 1 EDT}. {688543200 -18000 0 EST}. {702457200 -14400 1 EDT}. {71
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):202
                                                                                                                                                                                                                                  Entropy (8bit):4.877543794488217
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX2905Qb90e/:MBaIMY9QpI290Ob90O
                                                                                                                                                                                                                                  MD5:C62E81B423F5BA10709D331FEBAB1839
                                                                                                                                                                                                                                  SHA1:F7BC5E7055E472DE33DED5077045F680843B1AA7
                                                                                                                                                                                                                                  SHA-256:0806C0E907DB13687BBAD2D22CEF5974D37A407D00E0A97847EC12AF972BCFF3
                                                                                                                                                                                                                                  SHA-512:7D7090C3A6FEBE67203EB18E06717B39EC62830757BAD5A40E0A7F97572ABB81E81CAB614AA4CD3089C3787DAA6293D6FED0137BB57EF3AE358A92FCDDCF52A8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Grenada) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):205
                                                                                                                                                                                                                                  Entropy (8bit):4.914669229343752
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX2905AJLr490e/:MBaIMY9QpI290qJLr490O
                                                                                                                                                                                                                                  MD5:026A098D231C9BE8557A7F4A673C1BE2
                                                                                                                                                                                                                                  SHA1:192EECA778E1E713053D37353AF6D3C168D2BFF5
                                                                                                                                                                                                                                  SHA-256:FFE0E204D43000121944C57D2B2A846E792DDC73405C02FC5E8017136CD55BCB
                                                                                                                                                                                                                                  SHA-512:B49BD0FC12CC8D475E7E5116B8BDEA1584912BFA433734451F4338E42B5E042F3EC259E81C009E85798030E21F658158FA9F4EFC60078972351F706F852425E3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Guadeloupe) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):385
                                                                                                                                                                                                                                  Entropy (8bit):4.450029420195016
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52906GdJmdHKznI2f/uFn/z/uFn/w67Rd3/uFn/4Bx/uFn/xAQ:cQ8JeQXfSn/zSn/w67Rd3Sn/4HSn/j
                                                                                                                                                                                                                                  MD5:6E3FD9D19E0CD26275B0F95412F13F4C
                                                                                                                                                                                                                                  SHA1:A1B6D6219DEBDBC9B5FFF5848E5DF14F8F4B1158
                                                                                                                                                                                                                                  SHA-256:1DC103227CA0EDEEBA8EE8A41AE54B3E11459E4239DC051B0694CF7DF3636F1A
                                                                                                                                                                                                                                  SHA-512:BF615D16BB55186AFC7216B47250EE84B7834FD08077E29E0A8F49C65AACAAD8D27539EA751202EBFF5E0B00702EC59B0A7D95F5FB585BFED68AC6206416110D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Guatemala) {. {-9223372036854775808 -21724 0 LMT}. {-1617040676 -21600 0 CST}. {123055200 -18000 1 CDT}. {130914000 -21600 0 CST}. {422344800 -18000 1 CDT}. {433054800 -21600 0 CST}. {669708000 -18000 1 CDT}. {684219600 -21600 0 CST}. {1146376800 -18000 1 CDT}. {1159678800 -21600 0 CST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):240
                                                                                                                                                                                                                                  Entropy (8bit):4.690879495223713
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X529056m2OHHjGeP5lahicKpKV91EX/uFkfF/KV9C:MBp5290smdHHLP5C/gO9U/uFEF/O9C
                                                                                                                                                                                                                                  MD5:58E0902DC63F2F584AD72E6855A68BB8
                                                                                                                                                                                                                                  SHA1:C8ED225C95DB512CB860D798E6AF648A321B82E7
                                                                                                                                                                                                                                  SHA-256:D940627FFCBE6D690E34406B62EE4A032F116DF1AB81631E27A61E16BD4051E2
                                                                                                                                                                                                                                  SHA-512:EF2523F2C55890BE4CE78DA2274833647587CF6F48B144C8261EB69B24BA73946B63244F03FEDF37A990FCAFECB2D88F4ECE302993F115C06323721E570EDD99
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Guayaquil) {. {-9223372036854775808 -19160 0 LMT}. {-2524502440 -18840 0 QMT}. {-1230749160 -18000 0 -05}. {722926800 -14400 1 -05}. {728884800 -18000 0 -05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):208
                                                                                                                                                                                                                                  Entropy (8bit):4.687194013851928
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52905R3Lm2OHRjGeTShVy4yViUKcVVFAH/MIB/O9:MBp5290LLmdHVTiy4yVi7c/OH/MG/O9
                                                                                                                                                                                                                                  MD5:CF5AD3AFBD735A42E3F7D85064C16AFC
                                                                                                                                                                                                                                  SHA1:B8160F8D5E677836051643622262F13E3AE1B0BE
                                                                                                                                                                                                                                  SHA-256:AF2EC2151402DF377E011618512BBC25A5A6AC64165E2C42212E2C2EC182E8F1
                                                                                                                                                                                                                                  SHA-512:F69F10822AB115D25C0B5F705D294332FAAA66EB0BA2D98A6610A35E1FA5ED05F02B3DDBB4E37B9B4A77946C05E28C98113DBF11EDF8DB2661A2D8ED40711182
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Guyana) {. {-9223372036854775808 -13960 0 LMT}. {-1730578040 -13500 0 -0345}. {176010300 -10800 0 -03}. {662698800 -14400 0 -04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10763
                                                                                                                                                                                                                                  Entropy (8bit):3.724988391778253
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Y7Z1hubfVmv0SqJXDiFHrbm96qddObEn/RDzWRfQFQ4XL8vG+81VcfnrpbXXnqvo:823ZLYvuOZJv
                                                                                                                                                                                                                                  MD5:7DE8E355A725B3D9B3FD06A838B9715F
                                                                                                                                                                                                                                  SHA1:41C6AAEA03FC7FEED50CFFFC4DFF7F35E2B1C23D
                                                                                                                                                                                                                                  SHA-256:5F65F38FFA6B05C59B21DB98672EB2124E4283530ACB01B22093EAEFB256D116
                                                                                                                                                                                                                                  SHA-512:4C61A15DDF28124343C1E6EFE068D15E48F0662534486EC38A4E2731BE085CDA5856F884521EF32A6E0EDD610A8A491A722220BDD1BAF2A9652D8457778AF696
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Halifax) {. {-9223372036854775808 -15264 0 LMT}. {-2131645536 -14400 0 AST}. {-1696276800 -10800 1 ADT}. {-1680469200 -14400 0 AST}. {-1640980800 -14400 0 AST}. {-1632074400 -10800 1 ADT}. {-1615143600 -14400 0 AST}. {-1609444800 -14400 0 AST}. {-1566763200 -10800 1 ADT}. {-1557090000 -14400 0 AST}. {-1535486400 -10800 1 ADT}. {-1524949200 -14400 0 AST}. {-1504468800 -10800 1 ADT}. {-1493413200 -14400 0 AST}. {-1472414400 -10800 1 ADT}. {-1461963600 -14400 0 AST}. {-1440964800 -10800 1 ADT}. {-1429390800 -14400 0 AST}. {-1409515200 -10800 1 ADT}. {-1396731600 -14400 0 AST}. {-1376856000 -10800 1 ADT}. {-1366491600 -14400 0 AST}. {-1346616000 -10800 1 ADT}. {-1333832400 -14400 0 AST}. {-1313956800 -10800 1 ADT}. {-1303678800 -14400 0 AST}. {-1282507200 -10800 1 ADT}. {-1272661200 -14400 0 AST}. {-1251057600 -10800 1 ADT}. {-1240088400
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8444
                                                                                                                                                                                                                                  Entropy (8bit):3.7372403334059547
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:VXA0Bc0tTJtNliQ4sxgpuG4c2JPTxUw9Or2ocrPGSyM9Gk4LK46MCf7VkXgySCWv:VXA0Bc0tTJtNliQ4sxSuG4c2JPTxUw9F
                                                                                                                                                                                                                                  MD5:C436FDCDBA98987601FEFC2DBFD5947B
                                                                                                                                                                                                                                  SHA1:A04CF2A5C9468C634AED324CB79F9EE3544514B7
                                                                                                                                                                                                                                  SHA-256:32F8B4D03E4ACB466353D72DAA2AA9E1E42D454DBBA001D0B880667E6346B8A1
                                                                                                                                                                                                                                  SHA-512:56C25003685582AF2B8BA4E32EFF03EF10F4360D1A12E0F1294355000161ADDF7024CBD047D1830AB884BE2C385FD8ABE8DA5C30E9A0671C22E84EE3BF957D85
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Havana) {. {-9223372036854775808 -19768 0 LMT}. {-2524501832 -19776 0 HMT}. {-1402813824 -18000 0 CST}. {-1311534000 -14400 1 CDT}. {-1300996800 -18000 0 CST}. {-933534000 -14400 1 CDT}. {-925675200 -18000 0 CST}. {-902084400 -14400 1 CDT}. {-893620800 -18000 0 CST}. {-870030000 -14400 1 CDT}. {-862171200 -18000 0 CST}. {-775681200 -14400 1 CDT}. {-767822400 -18000 0 CST}. {-744231600 -14400 1 CDT}. {-736372800 -18000 0 CST}. {-144702000 -14400 1 CDT}. {-134251200 -18000 0 CST}. {-113425200 -14400 1 CDT}. {-102542400 -18000 0 CST}. {-86295600 -14400 1 CDT}. {-72907200 -18000 0 CST}. {-54154800 -14400 1 CDT}. {-41457600 -18000 0 CST}. {-21495600 -14400 1 CDT}. {-5774400 -18000 0 CST}. {9954000 -14400 1 CDT}. {25675200 -18000 0 CST}. {41403600 -14400 1 CDT}. {57729600 -18000 0 CST}. {73458000 -14400 1 CDT}. {87364800 -18000 0 CST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):595
                                                                                                                                                                                                                                  Entropy (8bit):4.2803367804689785
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5290ebmdH5NWw+Ux++vTQtFlvm0tFXtFjV5a:cQBe5gfUT7UFltF9FjV5a
                                                                                                                                                                                                                                  MD5:9D1A1746614CE2CEE26D066182938CDC
                                                                                                                                                                                                                                  SHA1:967590403A84E80ED299B8D548A2B37C8EEB21CE
                                                                                                                                                                                                                                  SHA-256:493DB3E7B56B2E6B266A5C212CD1F75F1E5CF57533DA03BB1C1F2449543B9F48
                                                                                                                                                                                                                                  SHA-512:DFAE6BC48F2E4B75DD6744AEE57D31D6A6E764D02DCA5731C7B516AD87B9BAB2FEB355A012EC38BDD53008B501B0744953EB7E0677F02B9EAF083D2E66042B37
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Hermosillo) {. {-9223372036854775808 -26632 0 LMT}. {-1514739600 -25200 0 MST}. {-1343066400 -21600 0 CST}. {-1234807200 -25200 0 MST}. {-1220292000 -21600 0 CST}. {-1207159200 -25200 0 MST}. {-1191344400 -21600 0 CST}. {-873828000 -25200 0 MST}. {-661539600 -28800 0 PST}. {28800 -25200 0 MST}. {828867600 -21600 1 MDT}. {846403200 -25200 0 MST}. {860317200 -21600 1 MDT}. {877852800 -25200 0 MST}. {891766800 -21600 1 MDT}. {909302400 -25200 0 MST}. {915174000 -25200 0 MST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6996
                                                                                                                                                                                                                                  Entropy (8bit):3.799188069575817
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:uRXxWMzJ2eQzURWu3N7sHRwvOTFhP5S+ijFnRaJeaX1eyDt:uRXxWUJ2eQzURWu3NOqvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:154A332C3ACF6D6F358B07D96B91EBD1
                                                                                                                                                                                                                                  SHA1:FC16E7CBE179B3AB4E0C2A61AB5E0E8C23E50D50
                                                                                                                                                                                                                                  SHA-256:C0C7964EBF9EA332B46D8B928B52FDE2ED15ED2B25EC664ACD33DA7BF3F987AE
                                                                                                                                                                                                                                  SHA-512:5831905E1E6C6FA9DD309104B3A2EE476941D6FF159764123A477E2690C697B0F19EDEA0AD0CD3BBBECF96D64DC4B981027439E7865FCB1632661C8539B3BD6C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Indianapolis) {. {-9223372036854775808 -20678 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-1577901600 -21600 0 CST}. {-900259200 -18000 1 CDT}. {-891795600 -21600 0 CST}. {-883591200 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-757360800 -21600 0 CST}. {-747244800 -18000 1 CDT}. {-733942800 -21600 0 CST}. {-715795200 -18000 1 CDT}. {-702493200 -21600 0 CST}. {-684345600 -18000 1 CDT}. {-671043600 -21600 0 CST}. {-652896000 -18000 1 CDT}. {-639594000 -21600 0 CST}. {-620841600 -18000 1 CDT}. {-608144400 -21600 0 CST}. {-589392000 -18000 1 CDT}. {-576090000 -21600 0 CST}. {-557942400 -18000 1 CDT}. {-544640400 -21600 0 CST}. {-526492800 -18000 1 CDT}. {-513190800 -21600 0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8470
                                                                                                                                                                                                                                  Entropy (8bit):3.7546412701514034
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:AXxr2eQzURWu3Oab9BxXI6X8xYIIOdXkqbfkeTzZSJw5/9/yuvQ+hcr8bYkzbXw6:AXxr2eQzUwu3Oab9BxXI6XUYIIOdXkqv
                                                                                                                                                                                                                                  MD5:E8AFD9E320A7F4310B413F8086462F31
                                                                                                                                                                                                                                  SHA1:7BEE624AAC096E9C280B4FC84B0671381C657F6C
                                                                                                                                                                                                                                  SHA-256:BE74C1765317898834A18617352DF3B2952D69DE4E294616F1554AB95824DAF0
                                                                                                                                                                                                                                  SHA-512:C76620999A293FA3A93CA4615AB78F19395F12CC08C242F56BFD4C4CAF8BC769DDEBF33FF10F7DA5A3EFD8ED18792362780188636075419014A8C099A897C43C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Knox) {. {-9223372036854775808 -20790 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-725824800 -21600 0 CST}. {-715795200 -18000 1 CDT}. {-702493200 -21600 0 CST}. {-684345600 -18000 1 CDT}. {-671043600 -21600 0 CST}. {-652896000 -18000 1 CDT}. {-639594000 -21600 0 CST}. {-620841600 -18000 1 CDT}. {-608144400 -21600 0 CST}. {-589392000 -18000 1 CDT}. {-576090000 -21600 0 CST}. {-557942400 -18000 1 CDT}. {-544640400 -21600 0 CST}. {-526492800 -18000 1 CDT}. {-513190800 -21600 0 CST}. {-495043200 -18000 1 CDT}. {-481741200 -21600 0 CST}. {-463593600 -18000 1 CDT}. {-447267600 -21600 0 CST}. {-431539200 -18000 1 CDT}. {-415818000 -21600 0 CST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7037
                                                                                                                                                                                                                                  Entropy (8bit):3.786429098558221
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:FXx3knO559B18XWRh0ksHRwvOTFhP5S+ijFnRaJeaX1eyDt:FXxUnO559B2XWRh0pqvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:456422A0D5BE8FBF5DBD0E75D8650894
                                                                                                                                                                                                                                  SHA1:737AC21F019A7E89689B9C8B465C8482FF4F403E
                                                                                                                                                                                                                                  SHA-256:C92D86CACFF85344453E1AFBC124CE11085DE7F6DC52CB4CBE6B89B01D5FE2F3
                                                                                                                                                                                                                                  SHA-512:372AEBB2F13A50536C36A025881874E5EE3162F0168B71B2083965BECBBFCA3DAC726117D205D708CC2B4F7ABE65CCC2B3FE6625F1403D97001950524D545470
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Marengo) {. {-9223372036854775808 -20723 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-599594400 -21600 0 CST}. {-589392000 -18000 1 CDT}. {-576090000 -21600 0 CST}. {-495043200 -18000 1 CDT}. {-481741200 -21600 0 CST}. {-463593600 -18000 1 CDT}. {-450291600 -21600 0 CST}. {-431539200 -18000 1 CDT}. {-418237200 -21600 0 CST}. {-400089600 -18000 1 CDT}. {-386787600 -21600 0 CST}. {-368640000 -18000 1 CDT}. {-355338000 -21600 0 CST}. {-337190400 -18000 1 CDT}. {-323888400 -21600 0 CST}. {-305740800 -18000 1 CDT}. {-292438800 -21600 0 CST}. {-273686400 -18000 0 EST}. {-31518000 -18000 0 EST}. {-21488400 -14400 1 EDT}. {-5767200 -18000 0 EST}. {
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7364
                                                                                                                                                                                                                                  Entropy (8bit):3.79636789874872
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:pXxS559B2XW6X8x3X3D2D8IOdXkqbfkeTzlbaqvOTFhPI1jFIL:pXxS559B2XW6XU3X3D2D8IOdXkqbfNT2
                                                                                                                                                                                                                                  MD5:9614153F9471187A2F92B674733369A0
                                                                                                                                                                                                                                  SHA1:199E8D5018A374EDB9592483CE4DDB30712006E3
                                                                                                                                                                                                                                  SHA-256:5323EBC8D450CC1B53AED18AD209ADEB3A6EEB5A00A80D63E26DB1C85B6476ED
                                                                                                                                                                                                                                  SHA-512:2A1E26D711F62C51A5EE7014584FAF41C1780BD62573247D45D467500C6AB9A9EAD5A382A1986A9D768D7BB927E4D391EA1B7A4AD9A54D3B05D8AD2385156C33
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Petersburg) {. {-9223372036854775808 -20947 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-473364000 -21600 0 CST}. {-462996000 -18000 1 CDT}. {-450291600 -21600 0 CST}. {-431539200 -18000 1 CDT}. {-418237200 -21600 0 CST}. {-400089600 -18000 1 CDT}. {-386787600 -21600 0 CST}. {-368640000 -18000 1 CDT}. {-355338000 -21600 0 CST}. {-337190400 -18000 1 CDT}. {-323888400 -21600 0 CST}. {-305740800 -18000 1 CDT}. {-292438800 -21600 0 CST}. {-273686400 -18000 1 CDT}. {-257965200 -21600 0 CST}. {-242236800 -18000 1 CDT}. {-226515600 -21600 0 CST}. {-210787200 -18000 1 CDT}. {-195066000 -21600 0 CST}. {-179337600 -18000 1 CDT}. {-163616400 -21600 0 CST
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6992
                                                                                                                                                                                                                                  Entropy (8bit):3.7768650637181533
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:CXxjL36559B2XI6XE3X3D2E0bYkzbXwDTIRqfhXbdXvDXpVXVto//q7u379zlq3g:CXxjL36559B2XI6XE3X3D2E0bYkzbXw6
                                                                                                                                                                                                                                  MD5:D0F40504B578D996E93DAE6DA583116A
                                                                                                                                                                                                                                  SHA1:4D4D24021B826BFED2735D42A46EEC1C9EBEA8E3
                                                                                                                                                                                                                                  SHA-256:F4A0572288D2073D093A256984A2EFEC6DF585642EA1C4A2860B38341D376BD8
                                                                                                                                                                                                                                  SHA-512:BA9D994147318FF5A53D45EC432E118B5F349207D58448D568E0DB316452EF9FD620EE4623FD4EAD123BC2A6724E1BAE2809919C58223E6FD4C7A20F004155E0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Tell_City) {. {-9223372036854775808 -20823 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-757360800 -21600 0 CST}. {-747244800 -18000 1 CDT}. {-733942800 -21600 0 CST}. {-526492800 -18000 1 CDT}. {-513190800 -21600 0 CST}. {-495043200 -18000 1 CDT}. {-481741200 -21600 0 CST}. {-462996000 -18000 1 CDT}. {-450291600 -21600 0 CST}. {-431539200 -18000 1 CDT}. {-418237200 -21600 0 CST}. {-400089600 -18000 1 CDT}. {-386787600 -21600 0 CST}. {-368640000 -18000 1 CDT}. {-355338000 -21600 0 CST}. {-337190400 -18000 1 CDT}. {-323888400 -21600 0 CST}. {-305740800 -18000 1 CDT}. {-289414800 -21600 0 CST}. {-273686400 -18000 1 CDT}. {-260989200 -21600 0 CST}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6350
                                                                                                                                                                                                                                  Entropy (8bit):3.782861360101505
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:K9Xx3+lsHRwvOTFhP5S+ijFnRaJeaX1eyDt:6XxuoqvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:35A64C161E0083DCE8CD1E8E1D6EBE85
                                                                                                                                                                                                                                  SHA1:9BC295C23783C07587D82DA2CC25C1A4586284B2
                                                                                                                                                                                                                                  SHA-256:75E89796C6FB41D75D4DDA6D94E4D27979B0572487582DC980575AF6656A7822
                                                                                                                                                                                                                                  SHA-512:7BAF735DA0DE899653F60EED6EEF53DD8A1ABC6F61F052B8E37B404BC9B37355E94563827BC296D8E980C4247864A57A117B7B1CB58A2C242991BBDC8FE7174E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Vevay) {. {-9223372036854775808 -20416 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-495043200 -18000 0 EST}. {-31518000 -18000 0 EST}. {-21488400 -14400 1 EDT}. {-5767200 -18000 0 EST}. {9961200 -14400 1 EDT}. {25682400 -18000 0 EST}. {41410800 -14400 1 EDT}. {57736800 -18000 0 EST}. {73465200 -14400 1 EDT}. {89186400 -18000 0 EST}. {94712400 -18000 0 EST}. {1136091600 -18000 0 EST}. {1143961200 -14400 1 EDT}. {1162101600 -18000 0 EST}. {1173596400 -14400 1 EDT}. {1194156000 -18000 0 EST}. {1205046000 -14400 1 EDT}. {1225605600 -18000 0 EST}. {1236495600 -14400 1 EDT}. {1257055200 -18000 0 EST}. {1268550000 -14400 1 EDT}. {1289109600 -18000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6992
                                                                                                                                                                                                                                  Entropy (8bit):3.795913753683276
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:TXxjL36559B2XI6XE3X3D2E0baqvOTFhPI1jFIL:TXxjL36559B2XI6XE3X3D2E0bZ3+
                                                                                                                                                                                                                                  MD5:AD8B44BD0DBBEB06786B2B281736A82B
                                                                                                                                                                                                                                  SHA1:7480D3916F0ED66379FC534F20DC31001A3F14AF
                                                                                                                                                                                                                                  SHA-256:18F35F24AEF9A937CD9E91E723F611BC5D802567A03C5484FAB7AEEC1F2A0ED0
                                                                                                                                                                                                                                  SHA-512:7911EC3F1FD564C50DEAF074ED99A502A9B5262B63E3E0D2901E21F27E90FBD5656A53831E61B43A096BA1FF18BB4183CCCE2B903782C2189DAAFDD7A90B3083
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Vincennes) {. {-9223372036854775808 -21007 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-757360800 -21600 0 CST}. {-747244800 -18000 1 CDT}. {-733942800 -21600 0 CST}. {-526492800 -18000 1 CDT}. {-513190800 -21600 0 CST}. {-495043200 -18000 1 CDT}. {-481741200 -21600 0 CST}. {-462996000 -18000 1 CDT}. {-450291600 -21600 0 CST}. {-431539200 -18000 1 CDT}. {-418237200 -21600 0 CST}. {-400089600 -18000 1 CDT}. {-386787600 -21600 0 CST}. {-368640000 -18000 1 CDT}. {-355338000 -21600 0 CST}. {-337190400 -18000 1 CDT}. {-323888400 -21600 0 CST}. {-305740800 -18000 1 CDT}. {-289414800 -21600 0 CST}. {-273686400 -18000 1 CDT}. {-260989200 -21600 0 CST}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7170
                                                                                                                                                                                                                                  Entropy (8bit):3.7942292979267767
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:YXxjJ2eQzURWu3Oab9B2XWR0/qvOTFhPI1jFIL:YXxjJ2eQzUwu3Oab9B2XWR0M3+
                                                                                                                                                                                                                                  MD5:40D8E05D8794C9D11DF018E3C8B8D7C0
                                                                                                                                                                                                                                  SHA1:58161F320CB46EC72B9AA6BAD9086F18B2E0141B
                                                                                                                                                                                                                                  SHA-256:A13D6158CCD4283FE94389FD341853AD90EA4EC505D37CE23BD7A6E7740F03F6
                                                                                                                                                                                                                                  SHA-512:BC45B6EFF1B879B01F517D4A4012D0AFBA0F6A9D92E862EF9A960FE07CBE216C8C929FE790044C566DC95981EC4BEAB3DCBD45A1FE597606CF601214A78AEA08
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Indiana/Winamac) {. {-9223372036854775808 -20785 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-757360800 -21600 0 CST}. {-747244800 -18000 1 CDT}. {-733942800 -21600 0 CST}. {-715795200 -18000 1 CDT}. {-702493200 -21600 0 CST}. {-684345600 -18000 1 CDT}. {-671043600 -21600 0 CST}. {-652896000 -18000 1 CDT}. {-639594000 -21600 0 CST}. {-620841600 -18000 1 CDT}. {-608144400 -21600 0 CST}. {-589392000 -18000 1 CDT}. {-576090000 -21600 0 CST}. {-557942400 -18000 1 CDT}. {-544640400 -21600 0 CST}. {-526492800 -18000 1 CDT}. {-513190800 -21600 0 CST}. {-495043200 -18000 1 CDT}. {-481741200 -21600 0 CST}. {-463593600 -18000 1 CDT}. {-447267600 -21600 0 CST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):228
                                                                                                                                                                                                                                  Entropy (8bit):4.655121947675421
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y73GK7mFVAIgp3GKBL2903GfJ4903GK1:MBaIMY3GK7Hp3GKBL2903GfJ4903GK1
                                                                                                                                                                                                                                  MD5:CB79BE371FAB0B0A5EBEB1BA101AA8BA
                                                                                                                                                                                                                                  SHA1:6A24348AB24D6D55A8ABDEE1500ED03D5D1357F3
                                                                                                                                                                                                                                  SHA-256:6AABF28AC5A766828DD91F2EE2783F50E9C6C6307D8942FCD4DFAE21DB2F1855
                                                                                                                                                                                                                                  SHA-512:156E1E7046D7A0938FE4BF40BC586F0A7BEF1B0ED7B887665E9C6041980B511F079AA739B7BD42A89794CB9E82DB6629E81DD39D2F8161DFABDED539E272FB6E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Indiana/Indianapolis)]} {. LoadTimeZoneFile America/Indiana/Indianapolis.}.set TZData(:America/Indianapolis) $TZData(:America/Indiana/Indianapolis).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7389
                                                                                                                                                                                                                                  Entropy (8bit):3.778898781146325
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:/ZGm+4I1zXN+C2mWBNQMsmNTxf6AeO+cblX:/EVUC2mWBNwWTxyWR
                                                                                                                                                                                                                                  MD5:EFEFB694C4F54583C0ED45A955E823AF
                                                                                                                                                                                                                                  SHA1:6FF35D151E8E1DED0DC362671FFF904B3CFF59B4
                                                                                                                                                                                                                                  SHA-256:72C48C0CCC1B8C1BD80E5BB5B8879A07A2DBE82317667568523BBE1F855E4883
                                                                                                                                                                                                                                  SHA-512:52BDACF02C5A595927FF9B7DC0151367C81B259C8831A91F66A0C10D5271DCDF834763F44868CCF7EDA497295D9D55C49C8F8FD43EEC383C29BC3CABAA4B6B0F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Inuvik) {. {-9223372036854775808 0 0 -00}. {-536457600 -28800 0 PST}. {-147888000 -21600 1 PDDT}. {-131558400 -28800 0 PST}. {315558000 -25200 0 MST}. {325674000 -21600 1 MDT}. {341395200 -25200 0 MST}. {357123600 -21600 1 MDT}. {372844800 -25200 0 MST}. {388573200 -21600 1 MDT}. {404899200 -25200 0 MST}. {420022800 -21600 1 MDT}. {436348800 -25200 0 MST}. {452077200 -21600 1 MDT}. {467798400 -25200 0 MST}. {483526800 -21600 1 MDT}. {499248000 -25200 0 MST}. {514976400 -21600 1 MDT}. {530697600 -25200 0 MST}. {544611600 -21600 1 MDT}. {562147200 -25200 0 MST}. {576061200 -21600 1 MDT}. {594201600 -25200 0 MST}. {607510800 -21600 1 MDT}. {625651200 -25200 0 MST}. {638960400 -21600 1 MDT}. {657100800 -25200 0 MST}. {671014800 -21600 1 MDT}. {688550400 -25200 0 MST}. {702464400 -21600 1 MDT}. {720000000 -25200 0 MST}. {733914000 -
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7421
                                                                                                                                                                                                                                  Entropy (8bit):3.7475594770809835
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:0/GC3XmzdsHRwvOTFhP5S+ijFnRaJeaX1eyDt:0/Pn0gqvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:67B9C859DCD38D60EB892500D7287387
                                                                                                                                                                                                                                  SHA1:E91BE702B1D97039528A3F540D1FFFF553683CE9
                                                                                                                                                                                                                                  SHA-256:34D907D9F2B36DC562DCD4E972170011B4DA98F9F6EDA819C50C130A51F1DBED
                                                                                                                                                                                                                                  SHA-512:239B0BA842C1432DB5A6DE4E0A63CDE4B4800FC76AE237B0E723116426F0700FFF418634FB1B5641B87E7792709E16A9ED679E37A570E9D723E3561C2B6B45B5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Iqaluit) {. {-9223372036854775808 0 0 -00}. {-865296000 -14400 0 EWT}. {-769395600 -14400 1 EPT}. {-765396000 -18000 0 EST}. {-147898800 -10800 1 EDDT}. {-131569200 -18000 0 EST}. {325666800 -14400 1 EDT}. {341388000 -18000 0 EST}. {357116400 -14400 1 EDT}. {372837600 -18000 0 EST}. {388566000 -14400 1 EDT}. {404892000 -18000 0 EST}. {420015600 -14400 1 EDT}. {436341600 -18000 0 EST}. {452070000 -14400 1 EDT}. {467791200 -18000 0 EST}. {483519600 -14400 1 EDT}. {499240800 -18000 0 EST}. {514969200 -14400 1 EDT}. {530690400 -18000 0 EST}. {544604400 -14400 1 EDT}. {562140000 -18000 0 EST}. {576054000 -14400 1 EDT}. {594194400 -18000 0 EST}. {607503600 -14400 1 EDT}. {625644000 -18000 0 EST}. {638953200 -14400 1 EDT}. {657093600 -18000 0 EST}. {671007600 -14400 1 EDT}. {688543200 -18000 0 EST}. {702457200 -14400 1 EDT}. {71999280
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):818
                                                                                                                                                                                                                                  Entropy (8bit):4.132568007446054
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ1ewtWFD/u/Ip/uJD/u2lR/utzN54i/uhU/ufUF5/uDBq/u63gU/u3Zh/u4u8H:5htWFYIgxmzfwuFqBG3g/k8H
                                                                                                                                                                                                                                  MD5:5C35FFB7D73B7F46DB4A508CF7AB1C54
                                                                                                                                                                                                                                  SHA1:5C631104044E9413C86F95E072A630C2AD9EA56D
                                                                                                                                                                                                                                  SHA-256:7FDD008C250308942D0D1DE485B05670A6A4276CB61F5F052385769B7E1906C1
                                                                                                                                                                                                                                  SHA-512:7B3FF2C945598DDBF43B0BD0650192D6C70B333BF89916013C35F56DC1489CB65A72BA70FB0AE7341C71A71D4B73805F9D597A5B5FA525F4BFB1DF0F582641AE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Jamaica) {. {-9223372036854775808 -18430 0 LMT}. {-2524503170 -18430 0 KMT}. {-1827687170 -18000 0 EST}. {126248400 -18000 0 EST}. {126687600 -14400 1 EDT}. {152085600 -18000 0 EST}. {162370800 -14400 1 EDT}. {183535200 -18000 0 EST}. {199263600 -14400 1 EDT}. {215589600 -18000 0 EST}. {230713200 -14400 1 EDT}. {247039200 -18000 0 EST}. {262767600 -14400 1 EDT}. {278488800 -18000 0 EST}. {294217200 -14400 1 EDT}. {309938400 -18000 0 EST}. {325666800 -14400 1 EDT}. {341388000 -18000 0 EST}. {357116400 -14400 1 EDT}. {372837600 -18000 0 EST}. {388566000 -14400 1 EDT}. {404892000 -18000 0 EST}. {420015600 -14400 1 EDT}. {436341600 -18000 0 EST}. {441781200 -18000 0 EST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):206
                                                                                                                                                                                                                                  Entropy (8bit):4.89710274358395
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/MI1VAIgp/MI+290pPGe90/MIE:MBaIMY/Mvp/Mh290h390/MB
                                                                                                                                                                                                                                  MD5:320C83EFE59FD60EB9F5D4CF0845B948
                                                                                                                                                                                                                                  SHA1:5A71DFAE7DF9E3D8724DFA533A37744B9A34FFEC
                                                                                                                                                                                                                                  SHA-256:67740B2D5427CFCA70FB53ABD2356B62E01B782A51A805A324C4DFAD9ACA0CFA
                                                                                                                                                                                                                                  SHA-512:D7A6378372386C45C907D3CB48B923511A719794B0C0BFA3694DBCE094A46A48249720653836C2F10CBB2178DD8EEEEA6B5019E4CC6C6B650FD7BE256BE1CA99
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Argentina/Jujuy)]} {. LoadTimeZoneFile America/Argentina/Jujuy.}.set TZData(:America/Jujuy) $TZData(:America/Argentina/Jujuy).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8406
                                                                                                                                                                                                                                  Entropy (8bit):3.8821515247187883
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:sL19jPaps/Q7Ddh5sBPyNsSLFOMM/EowALVZVmWa86Eac8rQ:sB9jPP/4h5sBPy+CMt/ElALLVuAH
                                                                                                                                                                                                                                  MD5:7D338E0224E7DDC690766CDC3E436805
                                                                                                                                                                                                                                  SHA1:89BB26B7731AC40DE75FFCD854BA4D30A0F1B716
                                                                                                                                                                                                                                  SHA-256:B703FC5AA56667A5F27FD80E5042AFE0F22F5A7EF7C5174646B2C10297E16810
                                                                                                                                                                                                                                  SHA-512:7B52EDD2FE3ECAB682138EC867B4D654A08BEA9C4A3BB20E1ED69F03DD9EF91A3B707C78D25CA5A32938152157E98188A253AD2D2D283EF24ECE7352BCB88B67
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Juneau) {. {-9223372036854775808 54139 0 LMT}. {-3225223727 -32261 0 LMT}. {-2188954939 -28800 0 PST}. {-883584000 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-757353600 -28800 0 PST}. {-31507200 -28800 0 PST}. {-21477600 -25200 1 PDT}. {-5756400 -28800 0 PST}. {9972000 -25200 1 PDT}. {25693200 -28800 0 PST}. {41421600 -25200 1 PDT}. {57747600 -28800 0 PST}. {73476000 -25200 1 PDT}. {89197200 -28800 0 PST}. {104925600 -25200 1 PDT}. {120646800 -28800 0 PST}. {126698400 -25200 1 PDT}. {152096400 -28800 0 PST}. {162381600 -25200 1 PDT}. {183546000 -28800 0 PST}. {199274400 -25200 1 PDT}. {215600400 -28800 0 PST}. {230724000 -25200 1 PDT}. {247050000 -28800 0 PST}. {262778400 -25200 1 PDT}. {278499600 -28800 0 PST}. {294228000 -25200 1 PDT}. {309949200 -28800 0 PST}. {325677600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9332
                                                                                                                                                                                                                                  Entropy (8bit):3.769996646995791
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:wmXxSkUArUfxLURWu3O5bMQxXI6Xah0drn+qvOTFhPI1jFIL:wmXxSkUArUfxLUwu3O5bMQxXI6Xah2n8
                                                                                                                                                                                                                                  MD5:D9BC20AFD7DA8643A2091EB1A4B48CB3
                                                                                                                                                                                                                                  SHA1:9B567ABF6630E7AB231CAD867AD541C82D9599FF
                                                                                                                                                                                                                                  SHA-256:B4CC987A6582494779799A32A9FB3B4A0D0298425E71377EB80E2FB4AAAEB873
                                                                                                                                                                                                                                  SHA-512:0BC769A53E63B41341C25A0E2093B127064B589F86483962BD24DB4082C4466E12F4CD889B82AD0134C992E984EF0897113F28321522B57BA45A98C15FF7E172
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Kentucky/Louisville) {. {-9223372036854775808 -20582 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-1546279200 -21600 0 CST}. {-1535904000 -18000 1 CDT}. {-1525280400 -21600 0 CST}. {-905097600 -18000 1 CDT}. {-891795600 -21600 0 CST}. {-883591200 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-757360800 -21600 0 CST}. {-747244800 -18000 1 CDT}. {-744224400 -21600 0 CST}. {-715795200 -18000 1 CDT}. {-684349200 -18000 1 CDT}. {-652899600 -18000 1 CDT}. {-620845200 -18000 1 CDT}. {-608144400 -21600 0 CST}. {-589392000 -18000 1 CDT}. {-576090000 -21600 0 CST}. {-557942400 -18000 1 CDT}. {-544640400 -21600 0 CST}. {-526492800 -18000 1 CDT}. {-513190800 -21600 0 CST}. {-495043200 -18000 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8279
                                                                                                                                                                                                                                  Entropy (8bit):3.785637200740036
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:jFPXxEOdXkqbfkeTzZSJw5/9/yuvQ+hcrD57X0N41+gqvOTFhPI1jFIL:5PXxEOdXkqbfNTzZSJw5/9/yuvQ6crD9
                                                                                                                                                                                                                                  MD5:0C6F5C9D1514DF2D0F8044BE27080EE2
                                                                                                                                                                                                                                  SHA1:70CBA0561E4319027C60FB0DCF29C9783BFE8A75
                                                                                                                                                                                                                                  SHA-256:1515460FBA496FE8C09C87C51406F4DA5D77C11D1FF2A2C8351DF5030001450F
                                                                                                                                                                                                                                  SHA-512:17B519BCC044FE6ED2F16F2DFBCB6CCE7FA83CF17B9FC4A40FDA21DEFBA9DE7F022A50CF5A264F3090D57D51362662E01C3C60BD125430AEECA0887BB8520DB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Kentucky/Monticello) {. {-9223372036854775808 -20364 0 LMT}. {-2717647200 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-757360800 -21600 0 CST}. {-63136800 -21600 0 CST}. {-52934400 -18000 1 CDT}. {-37213200 -21600 0 CST}. {-21484800 -18000 1 CDT}. {-5763600 -21600 0 CST}. {9964800 -18000 1 CDT}. {25686000 -21600 0 CST}. {41414400 -18000 1 CDT}. {57740400 -21600 0 CST}. {73468800 -18000 1 CDT}. {89190000 -21600 0 CST}. {104918400 -18000 1 CDT}. {120639600 -21600 0 CST}. {126691200 -18000 1 CDT}. {152089200 -21600 0 CST}. {162374400 -18000 1 CDT}. {183538800 -21600 0 CST}. {199267200 -18000 1 CDT}. {215593200 -21600 0 CST}. {230716800 -18000 1 CDT}. {247042800 -21600 0 C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):199
                                                                                                                                                                                                                                  Entropy (8bit):4.8191308888643345
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y73GKXFVAIgp3GK4N2901iZ903GKk:MBaIMY3GKXQp3GKe290Q903GKk
                                                                                                                                                                                                                                  MD5:465D405C9720EB7EC4BB007A279E88ED
                                                                                                                                                                                                                                  SHA1:7D80B8746816ECF4AF45166AED24C731B60CCFC6
                                                                                                                                                                                                                                  SHA-256:BE85C86FBD7D396D2307E7DCC945214977829E1314D1D71EFAE509E98AC15CF7
                                                                                                                                                                                                                                  SHA-512:C476022D2CC840793BF7B5841051F707A30CCAB1022E30FB1E45B420077417F517BEDA5564EFB154283C7C018A9CA09D10845C6A1BFE2A2DE7C939E307BDCE6F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Indiana/Knox)]} {. LoadTimeZoneFile America/Indiana/Knox.}.set TZData(:America/Knox_IN) $TZData(:America/Indiana/Knox).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):187
                                                                                                                                                                                                                                  Entropy (8bit):4.810917109656368
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx09CvjHVAIg209CvjvQ2IAcGE1QOa0IAcGE9Cvju:SlSWB9IZaM3y79CzVAIgp9CE2901Qv0k
                                                                                                                                                                                                                                  MD5:4763D6524D2D8FC62720BCD020469FF6
                                                                                                                                                                                                                                  SHA1:EE567965467E4F3BDFE4094604E526A49305FDD8
                                                                                                                                                                                                                                  SHA-256:A794B43E498484FFD83702CFB9250932058C01627F6F6F4EE1432C80A9B37CD6
                                                                                                                                                                                                                                  SHA-512:37462E0A3C24D5BAEBDD1ADCF8EE94EA07682960D710D57D5FD05AF9C5F09FF30312528D79516A16A0A84A2D351019DBB33308FC39EC468033B18FB0AC872C13
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Curacao)]} {. LoadTimeZoneFile America/Curacao.}.set TZData(:America/Kralendijk) $TZData(:America/Curacao).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):210
                                                                                                                                                                                                                                  Entropy (8bit):4.853705210019575
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52IAcGEyUMWkXGm2OHpJvvvX+nFp1vZSsXxyFYMUmBXlVvG9:SlSWB9X5290Xm2OHphvPKZpyFMmBVVO9
                                                                                                                                                                                                                                  MD5:FE113AA98220A177DA9DD5BF588EB317
                                                                                                                                                                                                                                  SHA1:083F2C36FF97185E2078B389F6DB2B3B04E95672
                                                                                                                                                                                                                                  SHA-256:AF2A931C2CC39EED49710B9AFDBB3E56F1E4A1A5B9B1C813565BE43D6668493A
                                                                                                                                                                                                                                  SHA-512:B6A34966F4150E3E3785563DFEB543726868923DB3980F693B4F2504B773A6CFD4102225C24897C81F1B3D22F35D1BE92D5ECE19F03028AC485A6B975896BB8F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/La_Paz) {. {-9223372036854775808 -16356 0 LMT}. {-2524505244 -16356 0 CMT}. {-1205954844 -12756 1 BST}. {-1192307244 -14400 0 -04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):444
                                                                                                                                                                                                                                  Entropy (8bit):4.171707948838632
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5290BbmdH4VPvut/O9F/O9BQXR/uFEC3/O9Ge/uFAs/O92/O9PF/O9R8/O9Tu:cQye8mV6FC4R/u1Cp/u2sC2CdC6CTSPV
                                                                                                                                                                                                                                  MD5:D20722EC3E24AA65C23DB94006246684
                                                                                                                                                                                                                                  SHA1:3E9D446FFA6163ED658D947BB582C9F566374777
                                                                                                                                                                                                                                  SHA-256:593FEBC924D0DE7DA5FC482952282F1B1E3432D7509798F475B13743047286DA
                                                                                                                                                                                                                                  SHA-512:326E300C837981DEFC497B5E467EA70DC2F6F10765FAB39977A2F03F3BEF0A0917EFD0524E2B66CBCFE0EE424273594437E098C6503EFC73002673678016C605
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Lima) {. {-9223372036854775808 -18492 0 LMT}. {-2524503108 -18516 0 LMT}. {-1938538284 -14400 0 -05}. {-1002052800 -18000 0 -05}. {-986756400 -14400 1 -05}. {-971035200 -18000 0 -05}. {-955306800 -14400 1 -05}. {-939585600 -18000 0 -05}. {512712000 -18000 0 -05}. {544248000 -18000 0 -05}. {638942400 -18000 0 -05}. {765172800 -18000 0 -05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9409
                                                                                                                                                                                                                                  Entropy (8bit):3.767062784666229
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:lBY5PBFx/9jgNf+aNwj/lpmlOxnKcndIG:lBY5PBFx/9wfefnK6
                                                                                                                                                                                                                                  MD5:A661407CC08E68459018A636C8EF0EC1
                                                                                                                                                                                                                                  SHA1:5524A613B07C4B4CA7404504EAD917E5B0A00112
                                                                                                                                                                                                                                  SHA-256:C39E5A4C1482B13E862B4D36F4F4590BDF230BE44BAC30BDAB015CDBE02BE9C9
                                                                                                                                                                                                                                  SHA-512:F5BD08D99E0B54911AC3ABFD413A1D98A0EB7F39A41E348E17D38EA9226A9320BA0CFE9CEB0954D158AB9B8761F0A9ECFB6F82DF033CD9B2234BC71A2D163B3A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Los_Angeles) {. {-9223372036854775808 -28378 0 LMT}. {-2717640000 -28800 0 PST}. {-1633269600 -25200 1 PDT}. {-1615129200 -28800 0 PST}. {-1601820000 -25200 1 PDT}. {-1583679600 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-757353600 -28800 0 PST}. {-687967140 -25200 1 PDT}. {-662655600 -28800 0 PST}. {-620838000 -25200 1 PDT}. {-608137200 -28800 0 PST}. {-589388400 -25200 1 PDT}. {-576082800 -28800 0 PST}. {-557938800 -25200 1 PDT}. {-544633200 -28800 0 PST}. {-526489200 -25200 1 PDT}. {-513183600 -28800 0 PST}. {-495039600 -25200 1 PDT}. {-481734000 -28800 0 PST}. {-463590000 -25200 1 PDT}. {-450284400 -28800 0 PST}. {-431535600 -25200 1 PDT}. {-418230000 -28800 0 PST}. {-400086000 -25200 1 PDT}. {-386780400 -28800 0 PST}. {-368636400 -25200 1 PDT}. {-355330800 -28800 0 PST}. {
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):223
                                                                                                                                                                                                                                  Entropy (8bit):4.866250035215905
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y71PiKp4ozFVAIgp1PiKp4zL290hp4901PiKp4/:MBaIMYPyJpPyzL290P490Py/
                                                                                                                                                                                                                                  MD5:3BAD2D8B6F2ECB3EC0BFA16DEAEBADC3
                                                                                                                                                                                                                                  SHA1:2E8D7A5A29733F94FF247E7E62A7D99D5073AFDC
                                                                                                                                                                                                                                  SHA-256:242870CE8998D1B4E756FB4CD7097FF1B41DF8AA6645E0B0F8EB64AEDC46C13C
                                                                                                                                                                                                                                  SHA-512:533A6A22A11C34BCE3772BD85B6A5819CCCD98BF7ECED9E751191E5D1AD3B84F34D70F30936CFE501C2FA3F6AAC7ABB9F8843B7EB742C6F9C2AD4C22D5C73740
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Kentucky/Louisville)]} {. LoadTimeZoneFile America/Kentucky/Louisville.}.set TZData(:America/Louisville) $TZData(:America/Kentucky/Louisville).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                  Entropy (8bit):4.81236985301262
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx09CvjHVAIg209CvjvQ2IAcGEyOqdVM1h4IAcGE9Cva:SlSWB9IZaM3y79CzVAIgp9CE290h48hf
                                                                                                                                                                                                                                  MD5:EBB062CC0AA5C21F7C4278B79B9EAE6C
                                                                                                                                                                                                                                  SHA1:6DFC8303BBE1FB990D7CB258E7DBC6270A5CFE64
                                                                                                                                                                                                                                  SHA-256:4842420076033349DD9560879505326FFAB91BED75D6C133143FFBBFB8725975
                                                                                                                                                                                                                                  SHA-512:5087C6257CA797317D049424324F5DC31BBD938436DCEB4CF4FE3D2520F7745F1C023E3EC48689957E389900EF2AACB3F5E9E49FD154DF51FF89F9A7173818CD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Curacao)]} {. LoadTimeZoneFile America/Curacao.}.set TZData(:America/Lower_Princes) $TZData(:America/Curacao).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1487
                                                                                                                                                                                                                                  Entropy (8bit):3.655866753080831
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQGEecc4h1u80V2dBUGphmC17ewGtN3rvIh0VKngBHZDIOXqWoN:5K4h19U2dBUGrmO7XGtN3kh0VKngBHZy
                                                                                                                                                                                                                                  MD5:3BC7560FE4E357A36D53F6DCC1E6F176
                                                                                                                                                                                                                                  SHA1:F9F647E5021344A3A350CD895A26B049331E7CF1
                                                                                                                                                                                                                                  SHA-256:184EC961CA5D1233A96A030D75D0D47A4111717B793EE25C82C0540E25168BDD
                                                                                                                                                                                                                                  SHA-512:0805146230F55E12D7524F3F4EDB53D9C6C41C6926FA0603B3958AA82E85C9531D8CBDF4DFF085189908F293A2B29FDFA1BAEFB0FDADF34134D6C4D2FCF19397
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Maceio) {. {-9223372036854775808 -8572 0 LMT}. {-1767217028 -10800 0 -03}. {-1206957600 -7200 1 -03}. {-1191362400 -10800 0 -03}. {-1175374800 -7200 1 -03}. {-1159826400 -10800 0 -03}. {-633819600 -7200 1 -03}. {-622069200 -10800 0 -03}. {-602283600 -7200 1 -03}. {-591832800 -10800 0 -03}. {-570747600 -7200 1 -03}. {-560210400 -10800 0 -03}. {-539125200 -7200 1 -03}. {-531352800 -10800 0 -03}. {-191365200 -7200 1 -03}. {-184197600 -10800 0 -03}. {-155163600 -7200 1 -03}. {-150069600 -10800 0 -03}. {-128898000 -7200 1 -03}. {-121125600 -10800 0 -03}. {-99954000 -7200 1 -03}. {-89589600 -10800 0 -03}. {-68418000 -7200 1 -03}. {-57967200 -10800 0 -03}. {499748400 -7200 1 -03}. {511236000 -10800 0 -03}. {530593200 -7200 1 -03}. {540266400 -10800 0 -03}. {562129200 -7200 1 -03}. {571197600 -10800 0 -03}. {592974000 -7200 1 -03}. {60
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):590
                                                                                                                                                                                                                                  Entropy (8bit):4.233264210289004
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5290znTsmdHOYPprva6/wLAyM/uFn/V8/uFn/3Y/oA2P/RASx/uFn/G/uFn/M:cQGnoeOshRIpMSn/V8Sn/3YVgJvxSn/6
                                                                                                                                                                                                                                  MD5:6BF9AB156020E7AC62F93F561B314CB8
                                                                                                                                                                                                                                  SHA1:7484A57EADCFD870490395BB4D6865A2E024B791
                                                                                                                                                                                                                                  SHA-256:D45B4690B43C46A7CD8001F8AE950CD6C0FF7B01CD5B3623E3DD92C62FD5E473
                                                                                                                                                                                                                                  SHA-512:CF02E62650679D8E2D58D0D70DE2322CAAA6508AF4FF7A60E415AA8AA3A9D26D1A191CFAE986ACAF0AEF1DFC4C2E34F9A5B6EDC2018E0B7E9000917D429FB587
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Managua) {. {-9223372036854775808 -20708 0 LMT}. {-2524500892 -20712 0 MMT}. {-1121105688 -21600 0 CST}. {105084000 -18000 0 EST}. {161758800 -21600 0 CST}. {290584800 -18000 1 CDT}. {299134800 -21600 0 CST}. {322034400 -18000 1 CDT}. {330584400 -21600 0 CST}. {694260000 -18000 0 EST}. {717310800 -21600 0 CST}. {725868000 -18000 0 EST}. {852094800 -21600 0 CST}. {1113112800 -18000 1 CDT}. {1128229200 -21600 0 CST}. {1146384000 -18000 1 CDT}. {1159682400 -21600 0 CST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1127
                                                                                                                                                                                                                                  Entropy (8bit):3.6965365214193797
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQGnveI8Sos/USws/QSI/LHSD/vOSy/WS3o/aS2/vSh/TSSX/WcSp/ySZd/YlSjc:5rSaSwXS4SqSbS3JSySxSxcSESAlSQSk
                                                                                                                                                                                                                                  MD5:BFCC0D7639AE2D973CDBD504E99A58B8
                                                                                                                                                                                                                                  SHA1:E8C43C5B026891D3E9B291446ABC050E7A100C71
                                                                                                                                                                                                                                  SHA-256:1237FF765AA4C5530E5250F928DFAB5BB687C72C990A37B87E9DB8135C5D9CBD
                                                                                                                                                                                                                                  SHA-512:DAD87E612161A136606E50944C50401AFD4C11D51A016704BDD070E52ED3BAC56E0E7BCFD83E7DA392FC8D2278E5F9EF6C0C466372F58AFA1005C4156CDA189D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Manaus) {. {-9223372036854775808 -14404 0 LMT}. {-1767211196 -14400 0 -04}. {-1206954000 -10800 1 -04}. {-1191358800 -14400 0 -04}. {-1175371200 -10800 1 -04}. {-1159822800 -14400 0 -04}. {-633816000 -10800 1 -04}. {-622065600 -14400 0 -04}. {-602280000 -10800 1 -04}. {-591829200 -14400 0 -04}. {-570744000 -10800 1 -04}. {-560206800 -14400 0 -04}. {-539121600 -10800 1 -04}. {-531349200 -14400 0 -04}. {-191361600 -10800 1 -04}. {-184194000 -14400 0 -04}. {-155160000 -10800 1 -04}. {-150066000 -14400 0 -04}. {-128894400 -10800 1 -04}. {-121122000 -14400 0 -04}. {-99950400 -10800 1 -04}. {-89586000 -14400 0 -04}. {-68414400 -10800 1 -04}. {-57963600 -14400 0 -04}. {499752000 -10800 1 -04}. {511239600 -14400 0 -04}. {530596800 -10800 1 -04}. {540270000 -14400 0 -04}. {562132800 -10800 1 -04}. {571201200 -14400 0 -04}. {590036400 -1440
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):202
                                                                                                                                                                                                                                  Entropy (8bit):4.890561068654966
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290zzJ/90e/:MBaIMY9QpI290zzN90O
                                                                                                                                                                                                                                  MD5:3340CD9706ECBB2C6BCB16F1D75C5428
                                                                                                                                                                                                                                  SHA1:FE230B53F0DCCE15C14C91F43796E46DA5C1A2CE
                                                                                                                                                                                                                                  SHA-256:BC2F908758F074D593C033F7B1C7D7B4F81618A4ED46E7907CD434E0CCFEE9F4
                                                                                                                                                                                                                                  SHA-512:016AB54B9E99600A296D99A036A555BB79E3C5FDB0F1BEB516AFFE17B7763D864CB076B9C2D95547ED44BA2F6FC372CDFF25708C5423E1CF643AB6F0AA78E0E3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Marigot) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):242
                                                                                                                                                                                                                                  Entropy (8bit):4.7982301339896285
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5290zlJm2OHfueP9dMQR5OfT/VVFUFkCFeR/r:MBp5290znmdHfnP9dMQR5Gb/uFkCFO/r
                                                                                                                                                                                                                                  MD5:2F7A1415403071E5D2E545C1DAA96A15
                                                                                                                                                                                                                                  SHA1:6A8FB2ABAD2B2D25AF569624C6C9AAE9821EF70B
                                                                                                                                                                                                                                  SHA-256:40F3C68A518F294062AC3DD5361BB9884308E1C490EF11D2CFDC93CB219C3D26
                                                                                                                                                                                                                                  SHA-512:3E4D94AB6A46E6C3BB97304F3A5596A06041C0E0935CC840F4A6EB56D0892778F853959A742C5B832CD8F07AB9B74539C45599F22C080577503B2E34B6CE28C5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Martinique) {. {-9223372036854775808 -14660 0 LMT}. {-2524506940 -14660 0 FFMT}. {-1851537340 -14400 0 AST}. {323841600 -10800 1 ADT}. {338958000 -14400 0 AST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6526
                                                                                                                                                                                                                                  Entropy (8bit):3.7582526108760064
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:t+vN41+z6stuNEsRZLbXwDTIRqfhXbdXvDXpVXVto//q7u379zlq3LtVBaANIsr2:taN41+z6stuNEsRZLbXwDTIRqfh57TlE
                                                                                                                                                                                                                                  MD5:2BBAA150389EAAE284D905A159A61167
                                                                                                                                                                                                                                  SHA1:0001B50C25FC0CDF015A60150963AAF895EEDEEF
                                                                                                                                                                                                                                  SHA-256:A7966B95DBE643291FB68E228B60E2DC780F8155E064D96B670C8290F104E4AB
                                                                                                                                                                                                                                  SHA-512:87CE18E7E4C2C59A953CD47005EF406F4923730459996B1BF09B04FFD9CD5F963A9E50299ECCDBF4B24C565412B706B1ABC39890D659E6F409F1BA50308E57F9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Matamoros) {. {-9223372036854775808 -24000 0 LMT}. {-1514743200 -21600 0 CST}. {568015200 -21600 0 CST}. {576057600 -18000 1 CDT}. {594198000 -21600 0 CST}. {599637600 -21600 0 CST}. {828864000 -18000 1 CDT}. {846399600 -21600 0 CST}. {860313600 -18000 1 CDT}. {877849200 -21600 0 CST}. {891763200 -18000 1 CDT}. {909298800 -21600 0 CST}. {923212800 -18000 1 CDT}. {941353200 -21600 0 CST}. {954662400 -18000 1 CDT}. {972802800 -21600 0 CST}. {989136000 -18000 1 CDT}. {1001833200 -21600 0 CST}. {1018166400 -18000 1 CDT}. {1035702000 -21600 0 CST}. {1049616000 -18000 1 CDT}. {1067151600 -21600 0 CST}. {1081065600 -18000 1 CDT}. {1099206000 -21600 0 CST}. {1112515200 -18000 1 CDT}. {1130655600 -21600 0 CST}. {1143964800 -18000 1 CDT}. {1162105200 -21600 0 CST}. {1175414400 -18000 1 CDT}. {1193554800 -21600 0 CST}. {1207468800 -18000 1 C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6619
                                                                                                                                                                                                                                  Entropy (8bit):3.788952004807415
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:W7ezBT8tRkfKxhzY720zaOXmlITHjLc1cb:X8tRkfKv+2wB9h
                                                                                                                                                                                                                                  MD5:4D63766E65BF3E772CCEC2D6DB3E2D3E
                                                                                                                                                                                                                                  SHA1:DB541D2908159C7EF98F912D8DBC36755FFD13F3
                                                                                                                                                                                                                                  SHA-256:81CEA4A397AF6190FD250325CF513976B3508209AE3A88FDFD55490A5016A36D
                                                                                                                                                                                                                                  SHA-512:DFAF1B3547B1B1B78B33F1F0F5E9624C693492687EC5D060FC4C6CBE2AFBB61B2E9B618133636DD62364D28B2450F741561AADFDE7B811F579BBC7247343A041
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Mazatlan) {. {-9223372036854775808 -25540 0 LMT}. {-1514739600 -25200 0 MST}. {-1343066400 -21600 0 CST}. {-1234807200 -25200 0 MST}. {-1220292000 -21600 0 CST}. {-1207159200 -25200 0 MST}. {-1191344400 -21600 0 CST}. {-873828000 -25200 0 MST}. {-661539600 -28800 0 PST}. {28800 -25200 0 MST}. {828867600 -21600 1 MDT}. {846403200 -25200 0 MST}. {860317200 -21600 1 MDT}. {877852800 -25200 0 MST}. {891766800 -21600 1 MDT}. {909302400 -25200 0 MST}. {923216400 -21600 1 MDT}. {941356800 -25200 0 MST}. {954666000 -21600 1 MDT}. {972806400 -25200 0 MST}. {989139600 -21600 1 MDT}. {1001836800 -25200 0 MST}. {1018170000 -21600 1 MDT}. {1035705600 -25200 0 MST}. {1049619600 -21600 1 MDT}. {1067155200 -25200 0 MST}. {1081069200 -21600 1 MDT}. {1099209600 -25200 0 MST}. {1112518800 -21600 1 MDT}. {1130659200 -25200 0 MST}. {1143968400 -21600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):214
                                                                                                                                                                                                                                  Entropy (8bit):4.76389929825594
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/MBVAIgp/Ma290zpH+90/MI:MBaIMY/Mcp/Ma290zpe90/MI
                                                                                                                                                                                                                                  MD5:A6EFD8F443D4CB54A5FB238D4D975808
                                                                                                                                                                                                                                  SHA1:8F25C6C0EA9D73DC8D1964C4A28A4E2E783880CC
                                                                                                                                                                                                                                  SHA-256:39B34B406339F06A8D187F8CCC1B6BF2550E49329F7DCE223619190F560E75F8
                                                                                                                                                                                                                                  SHA-512:4B5D48472D56AF19B29AD2377573CC8CB3ED9EF1AF53C00C907B6576FA852EA3D1E9F9B3A78A280DC44F8ADBE5B81D6AEC2609BE08FFA08507CD0F4139878F46
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Argentina/Mendoza)]} {. LoadTimeZoneFile America/Argentina/Mendoza.}.set TZData(:America/Mendoza) $TZData(:America/Argentina/Mendoza).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8136
                                                                                                                                                                                                                                  Entropy (8bit):3.7460641906933345
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:oXxj07ffkeTzZSJw5/9/yuvQ+hcrD57X0N41+IestuNEbYkzbXwDTIRqfhXbdXvC:oXxj07ffNTzZSJw5/9/yuvQ6crD57X0w
                                                                                                                                                                                                                                  MD5:0D0DC4A816CDAE4707CDF4DF51A18D30
                                                                                                                                                                                                                                  SHA1:7ED2835AA8F723B958A6631092019A779554CADE
                                                                                                                                                                                                                                  SHA-256:3C659C1EAC7848BBE8DF00F857F8F81D2F64B56BD1CEF3495641C53C007434FA
                                                                                                                                                                                                                                  SHA-512:930F2FDC2C1EAE4106F9B37A16BCBBAF618A2CCBBA98C712E8215555CF09B9303D71842DEC38EFAF930DB71E14E8208B14E41E10B54EF98335E01435D0FC3518
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Menominee) {. {-9223372036854775808 -21027 0 LMT}. {-2659759773 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-757360800 -21600 0 CST}. {-747244800 -18000 1 CDT}. {-733942800 -21600 0 CST}. {-116438400 -18000 1 CDT}. {-100112400 -21600 0 CST}. {-21484800 -18000 0 EST}. {104914800 -21600 0 CST}. {104918400 -18000 1 CDT}. {120639600 -21600 0 CST}. {126691200 -18000 1 CDT}. {152089200 -21600 0 CST}. {162374400 -18000 1 CDT}. {183538800 -21600 0 CST}. {199267200 -18000 1 CDT}. {215593200 -21600 0 CST}. {230716800 -18000 1 CDT}. {247042800 -21600 0 CST}. {262771200 -18000 1 CDT}. {278492400 -21600 0 CST}. {294220800 -18000 1 CDT}. {309942000 -21600 0 CST}. {325670400 -18000 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6435
                                                                                                                                                                                                                                  Entropy (8bit):3.757504464563519
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:gN41+z6stuNEsRZjWqZL/1dCYDXEaXTuXMEXiH4RxGIJkYWXsWwav7jNf4sOVEmR:gN41+z6stuNEsRZjWqZL/1dCYDDCxyHo
                                                                                                                                                                                                                                  MD5:A7C5CFE3FA08D4CEDF6324457EA5766E
                                                                                                                                                                                                                                  SHA1:83BB96398C0B1B34771940C8F7A19CB78C5EF72F
                                                                                                                                                                                                                                  SHA-256:A1D7DE7285DC78ADDE1B0A04E05DA44D0D46D4696F67A682D0D28313A53825FE
                                                                                                                                                                                                                                  SHA-512:092DD7CEF6A5861472965E082171937EEDCFB3AE1821E3C88AA1BDFAB1EC48F765CAC497E3E5C78C19653C78B087C7CE28A8AB76F9073558963234901EF4B4A4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Merida) {. {-9223372036854775808 -21508 0 LMT}. {-1514743200 -21600 0 CST}. {377935200 -18000 0 EST}. {407653200 -21600 0 CST}. {828864000 -18000 1 CDT}. {846399600 -21600 0 CST}. {860313600 -18000 1 CDT}. {877849200 -21600 0 CST}. {891763200 -18000 1 CDT}. {909298800 -21600 0 CST}. {923212800 -18000 1 CDT}. {941353200 -21600 0 CST}. {954662400 -18000 1 CDT}. {972802800 -21600 0 CST}. {989136000 -18000 1 CDT}. {1001833200 -21600 0 CST}. {1018166400 -18000 1 CDT}. {1035702000 -21600 0 CST}. {1049616000 -18000 1 CDT}. {1067151600 -21600 0 CST}. {1081065600 -18000 1 CDT}. {1099206000 -21600 0 CST}. {1112515200 -18000 1 CDT}. {1130655600 -21600 0 CST}. {1143964800 -18000 1 CDT}. {1162105200 -21600 0 CST}. {1175414400 -18000 1 CDT}. {1193554800 -21600 0 CST}. {1207468800 -18000 1 CDT}. {1225004400 -21600 0 CST}. {1238918400 -18000 1 CD
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6462
                                                                                                                                                                                                                                  Entropy (8bit):3.906655458013535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:XP19jJ+h5sBPyNsSLFOMM/EowALVZVmWa86Eac8rQ:X99jIh5sBPy+CMt/ElALLVuAH
                                                                                                                                                                                                                                  MD5:897140EE4C46A300FBA4B66692A77D2B
                                                                                                                                                                                                                                  SHA1:D5F2F3C8561A19EA0C5DAF0236696D5DB98D4220
                                                                                                                                                                                                                                  SHA-256:8B48C28A0AB6728CEDBCC82197355A5F9DD7D73E270EE949D996BB788777623B
                                                                                                                                                                                                                                  SHA-512:17E52B3C00C4EDE3B2FA10A4BE0601889B12581D31936D075E85118F37329716C4083D2B16F7081F7AA73EC9774ED7B4CF67615BE6090F8A506BF77AADE0CAFD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Metlakatla) {. {-9223372036854775808 54822 0 LMT}. {-3225223727 -31578 0 LMT}. {-2188955622 -28800 0 PST}. {-883584000 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-757353600 -28800 0 PST}. {-31507200 -28800 0 PST}. {-21477600 -25200 1 PDT}. {-5756400 -28800 0 PST}. {9972000 -25200 1 PDT}. {25693200 -28800 0 PST}. {41421600 -25200 1 PDT}. {57747600 -28800 0 PST}. {73476000 -25200 1 PDT}. {89197200 -28800 0 PST}. {104925600 -25200 1 PDT}. {120646800 -28800 0 PST}. {126698400 -25200 1 PDT}. {152096400 -28800 0 PST}. {162381600 -25200 1 PDT}. {183546000 -28800 0 PST}. {199274400 -25200 1 PDT}. {215600400 -28800 0 PST}. {230724000 -25200 1 PDT}. {247050000 -28800 0 PST}. {262778400 -25200 1 PDT}. {278499600 -28800 0 PST}. {294228000 -25200 1 PDT}. {309949200 -28800 0 PST}. {325677
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6807
                                                                                                                                                                                                                                  Entropy (8bit):3.761365047166545
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:VeE7nN41+zKstuNEsRZjWqZL/1dCYDXEaXTuXMEXiH4RxGIJkYWXsWwav7jNf4sQ:VeE7nN41+zKstuNEsRZjWqZL/1dCYDDK
                                                                                                                                                                                                                                  MD5:C675DA8A44A9841C417C585C2661EF13
                                                                                                                                                                                                                                  SHA1:147DDE5DD00E520DA889AC9931088E6232CE6FEA
                                                                                                                                                                                                                                  SHA-256:82B9AAD03408A9DFC0B6361EC923FEAEF97DBB4B3129B772B902B9DAE345D63E
                                                                                                                                                                                                                                  SHA-512:00615A5EC0D08BABF009C3CAAF3D631B1F4E2E4324E91B0F29ADD7E61B51C80D5D495D20BD131A9370C3005B2E510C8A4E4869A5032D82BC33C875E909CDE086
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Mexico_City) {. {-9223372036854775808 -23796 0 LMT}. {-1514739600 -25200 0 MST}. {-1343066400 -21600 0 CST}. {-1234807200 -25200 0 MST}. {-1220292000 -21600 0 CST}. {-1207159200 -25200 0 MST}. {-1191344400 -21600 0 CST}. {-975261600 -18000 1 CDT}. {-963169200 -21600 0 CST}. {-917114400 -18000 1 CDT}. {-907354800 -21600 0 CST}. {-821901600 -18000 1 CWT}. {-810068400 -21600 0 CST}. {-627501600 -18000 1 CDT}. {-612990000 -21600 0 CST}. {828864000 -18000 1 CDT}. {846399600 -21600 0 CST}. {860313600 -18000 1 CDT}. {877849200 -21600 0 CST}. {891763200 -18000 1 CDT}. {909298800 -21600 0 CST}. {923212800 -18000 1 CDT}. {941353200 -21600 0 CST}. {954662400 -18000 1 CDT}. {972802800 -21600 0 CST}. {989136000 -18000 1 CDT}. {1001836800 -21600 0 CST}. {1014184800 -21600 0 CST}. {1018166400 -18000 1 CDT}. {1035702000 -21600 0 CST}. {1049616000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6846
                                                                                                                                                                                                                                  Entropy (8bit):3.44227328239419
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:FxfUaXYEn/wGm3eADKja4PcCYCJ7j7Ub0ZixJpF8pnmpRipo1kay2DfhJ+Nwz/ad:DeTntbDs
                                                                                                                                                                                                                                  MD5:0C7122725D98CDE5CB9B22624D24A26C
                                                                                                                                                                                                                                  SHA1:1889279EBE1377DB3460B706CAA4ECF803651517
                                                                                                                                                                                                                                  SHA-256:86BB088047FB5A6041C7B0792D15F9CB453F49A54F78529CC415B7FF2C41265A
                                                                                                                                                                                                                                  SHA-512:C23D3AE8D579FAC56521A0C06178550C4976E906A4CD149554821A2550B0EAB43344C6536166271EAA22EC77AF8529D9164696D7A5A740B02FA34C4272D43F26
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Miquelon) {. {-9223372036854775808 -13480 0 LMT}. {-1850328920 -14400 0 AST}. {326001600 -10800 0 -03}. {536468400 -10800 0 -02}. {544597200 -7200 1 -02}. {562132800 -10800 0 -02}. {576046800 -7200 1 -02}. {594187200 -10800 0 -02}. {607496400 -7200 1 -02}. {625636800 -10800 0 -02}. {638946000 -7200 1 -02}. {657086400 -10800 0 -02}. {671000400 -7200 1 -02}. {688536000 -10800 0 -02}. {702450000 -7200 1 -02}. {719985600 -10800 0 -02}. {733899600 -7200 1 -02}. {752040000 -10800 0 -02}. {765349200 -7200 1 -02}. {783489600 -10800 0 -02}. {796798800 -7200 1 -02}. {814939200 -10800 0 -02}. {828853200 -7200 1 -02}. {846388800 -10800 0 -02}. {860302800 -7200 1 -02}. {877838400 -10800 0 -02}. {891752400 -7200 1 -02}. {909288000 -10800 0 -02}. {923202000 -7200 1 -02}. {941342400 -10800 0 -02}. {954651600 -7200 1 -02}. {972792000 -10800 0 -
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10165
                                                                                                                                                                                                                                  Entropy (8bit):3.73501024949866
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:XYtQYUKXZRMavqQS8L2En/RDmzTWRf2oFnoF8l988fL8vG+81VcfnrpbX+qvlrPf:gQYzCO4alKqYvuOdeYP/Jv
                                                                                                                                                                                                                                  MD5:C1F34BD1FB4402481FFA5ABEE1573085
                                                                                                                                                                                                                                  SHA1:46B9AD38086417554549C36A40487140256BED57
                                                                                                                                                                                                                                  SHA-256:A4C2F586D7F59A192D6D326AD892C8BE20753FB4D315D506F4C2ED9E3F657B9A
                                                                                                                                                                                                                                  SHA-512:115D3E65A6A3834E748ED1917CF03A835F74EC0F8DB789C2B99EB78879EA3A5A2AFEB35981BA221D868E6A5B579374CFB3F865ACF6D4271B918EBCC2C3C69579
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Moncton) {. {-9223372036854775808 -15548 0 LMT}. {-2715882052 -18000 0 EST}. {-2131642800 -14400 0 AST}. {-1632074400 -10800 1 ADT}. {-1615143600 -14400 0 AST}. {-1167595200 -14400 0 AST}. {-1153681200 -10800 1 ADT}. {-1145822400 -14400 0 AST}. {-1122231600 -10800 1 ADT}. {-1114372800 -14400 0 AST}. {-1090782000 -10800 1 ADT}. {-1082923200 -14400 0 AST}. {-1059332400 -10800 1 ADT}. {-1051473600 -14400 0 AST}. {-1027882800 -10800 1 ADT}. {-1020024000 -14400 0 AST}. {-996433200 -10800 1 ADT}. {-988574400 -14400 0 AST}. {-965674800 -10800 1 ADT}. {-955396800 -14400 0 AST}. {-934743600 -10800 1 ADT}. {-923947200 -14400 0 AST}. {-904503600 -10800 1 ADT}. {-891892800 -14400 0 AST}. {-883598400 -14400 0 AST}. {-880221600 -10800 1 AWT}. {-769395600 -10800 1 APT}. {-765399600 -14400 0 AST}. {-757368000 -14400 0 AST}. {-747252000 -10800 1 ADT}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6496
                                                                                                                                                                                                                                  Entropy (8bit):3.75909042772931
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Xc+vN41+z6stuNEsRZjWqZL/1dCYDXEaXTuXMEXiH4RxGIJkYWXsWwav7jNf4sOt:saN41+z6stuNEsRZjWqZL/1dCYDDCxyI
                                                                                                                                                                                                                                  MD5:255A5A8E27CA1F0127D71E09033C6D9B
                                                                                                                                                                                                                                  SHA1:4F1C5E6D3F9E5BC9F8958FA50C195FDADD0F4022
                                                                                                                                                                                                                                  SHA-256:C753DEF7056E26D882DCD842729816890D42B6C7E31522111467C0C39A24B2F2
                                                                                                                                                                                                                                  SHA-512:96A67C3CC54EC39086D4DF681DDA39B4167FE80F0C45600045480F28C282071915F793BD672146119A22E0C15339F162DFF9DF326E7132E723684EF079666F58
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Monterrey) {. {-9223372036854775808 -24076 0 LMT}. {-1514743200 -21600 0 CST}. {568015200 -21600 0 CST}. {576057600 -18000 1 CDT}. {594198000 -21600 0 CST}. {599637600 -21600 0 CST}. {828864000 -18000 1 CDT}. {846399600 -21600 0 CST}. {860313600 -18000 1 CDT}. {877849200 -21600 0 CST}. {891763200 -18000 1 CDT}. {909298800 -21600 0 CST}. {923212800 -18000 1 CDT}. {941353200 -21600 0 CST}. {954662400 -18000 1 CDT}. {972802800 -21600 0 CST}. {989136000 -18000 1 CDT}. {1001833200 -21600 0 CST}. {1018166400 -18000 1 CDT}. {1035702000 -21600 0 CST}. {1049616000 -18000 1 CDT}. {1067151600 -21600 0 CST}. {1081065600 -18000 1 CDT}. {1099206000 -21600 0 CST}. {1112515200 -18000 1 CDT}. {1130655600 -21600 0 CST}. {1143964800 -18000 1 CDT}. {1162105200 -21600 0 CST}. {1175414400 -18000 1 CDT}. {1193554800 -21600 0 CST}. {1207468800 -18000 1 C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2840
                                                                                                                                                                                                                                  Entropy (8bit):3.549378422404712
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5JJjQSSSGEcS2SrPZSMSEkS/StSneSOSnx7EXnF9XXGGLgvA/Sa8h1liqZovoJqP:X9QV0cduTSe+J1ix7inFBXGGUvA/Sa8A
                                                                                                                                                                                                                                  MD5:87A9F18CE5E5EE97D943316EE93DC664
                                                                                                                                                                                                                                  SHA1:C221C82FA644943AF05C5737B4A68418BEFE66D7
                                                                                                                                                                                                                                  SHA-256:E8DB201FDAF1FD43BE39422062CEB2A25F25764934C481A95CD7BB3F93949495
                                                                                                                                                                                                                                  SHA-512:AC7D6BA85A37585BEC2101AAF0F46B04BF49F56B449A2BEC4E32D009576CA4D0CB687981EFA96DA8DAB00453F0020925E5FB9681BF8071AC6EFFC4F938E0D891
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Montevideo) {. {-9223372036854775808 -13491 0 LMT}. {-1942690509 -13491 0 MMT}. {-1567455309 -14400 0 -04}. {-1459627200 -10800 0 -0330}. {-1443819600 -12600 0 -0330}. {-1428006600 -10800 1 -0330}. {-1412283600 -12600 0 -0330}. {-1396470600 -10800 1 -0330}. {-1380747600 -12600 0 -0330}. {-1141590600 -10800 1 -0330}. {-1128286800 -12600 0 -0330}. {-1110141000 -10800 1 -0330}. {-1096837200 -12600 0 -0330}. {-1078691400 -10800 1 -0330}. {-1065387600 -12600 0 -0330}. {-1047241800 -10800 1 -0330}. {-1033938000 -12600 0 -0330}. {-1015187400 -10800 1 -0330}. {-1002488400 -12600 0 -0330}. {-983737800 -10800 1 -0330}. {-971038800 -12600 0 -0330}. {-954707400 -10800 1 -0330}. {-938984400 -12600 0 -0330}. {-920838600 -10800 1 -0330}. {-907534800 -12600 0 -0330}. {-896819400 -10800 1 -0330}. {-853621200 -9000 0 -03}. {-845847000 -10800 0 -03}. {-33
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.696915330047381
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0qMKLRXIVAIg20qMKLRI62IAcGEzQ21h4IAcGEqMKR:SlSWB9IZaM3y7RQ+VAIgpRQ+6290zQg2
                                                                                                                                                                                                                                  MD5:F4631583229AD8B12C548E624AAF4A9F
                                                                                                                                                                                                                                  SHA1:C56022CEACBD910C9CBF8C39C974021294AEE9DA
                                                                                                                                                                                                                                  SHA-256:884575BE85D1276A1AE3426F33153B3D4787AC5238FDBE0991C6608E7EB0DF07
                                                                                                                                                                                                                                  SHA-512:48FB9910D8A75AD9451C860716746D38B29319CA04DF9E8690D62FB875A5BEBCC7A8C546A60878821BD68A83271C69671D483C3133E4F807F2C3AC899CEBF065
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Toronto)]} {. LoadTimeZoneFile America/Toronto.}.set TZData(:America/Montreal) $TZData(:America/Toronto).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):205
                                                                                                                                                                                                                                  Entropy (8bit):4.865859395466201
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290zQ1HK90e/:MBaIMY9QpI290zQ490O
                                                                                                                                                                                                                                  MD5:705E51A8FB38AA8F9714256AFB55DA8A
                                                                                                                                                                                                                                  SHA1:97D96BE4C08F128E739D541A43057F08D24DDDCF
                                                                                                                                                                                                                                  SHA-256:0FED15D7D58E8A732110FF6765D0D148D15ACBB0251EE867CE7596933E999865
                                                                                                                                                                                                                                  SHA-512:4D7E42ECDB16F7A8A62D9EDA1E365325F3CBFAA1EF0E9FEE2790E24BA8DEAAA716D41F9389B849C69DC3973DA61D575146932FB2C8AC81579C65C18E45AE386E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Montserrat) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8260
                                                                                                                                                                                                                                  Entropy (8bit):3.7353311910027376
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:JUzoaC3Xm8sHRwvOTFhP5S+ijFnRaJeaX1eyDt:Gzorn+qvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:6F9F530A792FC34E2B0CEE4BC3DB3809
                                                                                                                                                                                                                                  SHA1:4DF8A4A6993E47DD5A710BEE921D88FEF44858E7
                                                                                                                                                                                                                                  SHA-256:9F62117DDA0A21D37B63C9083B3C50572399B22D640262F427D68123078B32F9
                                                                                                                                                                                                                                  SHA-512:C2BF93FDBE8430113FA63561D1A08145DCF31CD679AB7230098993C7A19EF0F29F486C962656F8A62505CB1BFE993FBD3BB5FB0BAE7B6E7E190DE2865C445408
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Nassau) {. {-9223372036854775808 -18570 0 LMT}. {-1825095030 -18000 0 EST}. {-179341200 -14400 1 EDT}. {-163620000 -18000 0 EST}. {-147891600 -14400 1 EDT}. {-131565600 -18000 0 EST}. {-116442000 -14400 1 EDT}. {-100116000 -18000 0 EST}. {-84387600 -14400 1 EDT}. {-68666400 -18000 0 EST}. {-52938000 -14400 1 EDT}. {-37216800 -18000 0 EST}. {-21488400 -14400 1 EDT}. {-5767200 -18000 0 EST}. {9961200 -14400 1 EDT}. {25682400 -18000 0 EST}. {41410800 -14400 1 EDT}. {57736800 -18000 0 EST}. {73465200 -14400 1 EDT}. {89186400 -18000 0 EST}. {104914800 -14400 1 EDT}. {120636000 -18000 0 EST}. {136364400 -14400 1 EDT}. {152085600 -18000 0 EST}. {167814000 -14400 1 EDT}. {183535200 -18000 0 EST}. {189320400 -18000 0 EST}. {199263600 -14400 1 EDT}. {215589600 -18000 0 EST}. {230713200 -14400 1 EDT}. {247039200 -18000 0 EST}. {262767600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):11004
                                                                                                                                                                                                                                  Entropy (8bit):3.725417189649631
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:iNXYUiZrbgZ8UMr5UwdaC3Xm8sHRwvOTFhP5S+ijFnRaJeaX1eyDt:23iZrbgZ8UMr2wdrn+qvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:C9D78AB6CF796A9D504BE2903F00B49C
                                                                                                                                                                                                                                  SHA1:A6C0E4135986A1A6F36B62276BFAB396DA1A4A9B
                                                                                                                                                                                                                                  SHA-256:1AB6E47D96BC34F57D56B936233F58B5C748B65E06AFF6449C3E3C317E411EFE
                                                                                                                                                                                                                                  SHA-512:6D20B13F337734CB58198396477B7C0E9CB89ED4D7AB328C22A4A528CAF187D10F42540DBB4514A0C139E6F4AE9A1A71AED02E3735D1D4F12C5314014C0C1EB6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/New_York) {. {-9223372036854775808 -17762 0 LMT}. {-2717650800 -18000 0 EST}. {-1633280400 -14400 1 EDT}. {-1615140000 -18000 0 EST}. {-1601830800 -14400 1 EDT}. {-1583690400 -18000 0 EST}. {-1577905200 -18000 0 EST}. {-1570381200 -14400 1 EDT}. {-1551636000 -18000 0 EST}. {-1536512400 -14400 1 EDT}. {-1523210400 -18000 0 EST}. {-1504458000 -14400 1 EDT}. {-1491760800 -18000 0 EST}. {-1473008400 -14400 1 EDT}. {-1459706400 -18000 0 EST}. {-1441558800 -14400 1 EDT}. {-1428256800 -18000 0 EST}. {-1410109200 -14400 1 EDT}. {-1396807200 -18000 0 EST}. {-1378659600 -14400 1 EDT}. {-1365357600 -18000 0 EST}. {-1347210000 -14400 1 EDT}. {-1333908000 -18000 0 EST}. {-1315155600 -14400 1 EDT}. {-1301853600 -18000 0 EST}. {-1283706000 -14400 1 EDT}. {-1270404000 -18000 0 EST}. {-1252256400 -14400 1 EDT}. {-1238954400 -18000 0 EST}. {-122080680
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7836
                                                                                                                                                                                                                                  Entropy (8bit):3.7462966187089535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:rEa2raC3Xm8sHRwvOTFhP5S+ijFnRaJeaX1eyDt:rYrrn+qvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:3D389AA51D3E29E8A1E8ED07646AA0DD
                                                                                                                                                                                                                                  SHA1:2E3DF9406B14662ADEDDC0F891CD81DF23D98157
                                                                                                                                                                                                                                  SHA-256:3A0FB897E5CCB31B139E009B909053DCE36BB5791ACF23529D874AFA9F0BB405
                                                                                                                                                                                                                                  SHA-512:AFF7B30355ECB6EBD43D1E6C943C250AB98CC82BDC8DDC7595769E4CE188A23591AEFCF18A028CC6479CF6AA20F65980E37C74F6CEE907537366136FAF29B66E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Nipigon) {. {-9223372036854775808 -21184 0 LMT}. {-2366734016 -18000 0 EST}. {-1632070800 -14400 1 EDT}. {-1615140000 -18000 0 EST}. {-923252400 -14400 1 EDT}. {-880218000 -14400 0 EWT}. {-769395600 -14400 1 EPT}. {-765396000 -18000 0 EST}. {136364400 -14400 1 EDT}. {152085600 -18000 0 EST}. {167814000 -14400 1 EDT}. {183535200 -18000 0 EST}. {199263600 -14400 1 EDT}. {215589600 -18000 0 EST}. {230713200 -14400 1 EDT}. {247039200 -18000 0 EST}. {262767600 -14400 1 EDT}. {278488800 -18000 0 EST}. {294217200 -14400 1 EDT}. {309938400 -18000 0 EST}. {325666800 -14400 1 EDT}. {341388000 -18000 0 EST}. {357116400 -14400 1 EDT}. {372837600 -18000 0 EST}. {388566000 -14400 1 EDT}. {404892000 -18000 0 EST}. {420015600 -14400 1 EDT}. {436341600 -18000 0 EST}. {452070000 -14400 1 EDT}. {467791200 -18000 0 EST}. {483519600 -14400 1 EDT}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8404
                                                                                                                                                                                                                                  Entropy (8bit):3.88589736733708
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:OWmWQm825s/Q7Ddh5sBPyNsSLFOMM/EowALVZVmWa86Eac8rQ:OWmWQmI/4h5sBPy+CMt/ElALLVuAH
                                                                                                                                                                                                                                  MD5:F5E89780553D3D30A32CF65746CA9A69
                                                                                                                                                                                                                                  SHA1:43D8B6E3C5D719599A680E1E6D4FF913D2700D7E
                                                                                                                                                                                                                                  SHA-256:5BDA4867EC7707E9D5E07AD3E558DA7C1E44EC1135E85A8F1809441A54B22BE5
                                                                                                                                                                                                                                  SHA-512:D1239FF5277055DD8787BF58ED14DBDC229FC46EDDF21E034CA77DEA439631974F44FCE63EF12483520ADB83AD235642AE480230544A7284A8BDAA5296486563
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Nome) {. {-9223372036854775808 46702 0 LMT}. {-3225223727 -39698 0 LMT}. {-2188947502 -39600 0 NST}. {-883573200 -39600 0 NST}. {-880196400 -36000 1 NWT}. {-769395600 -36000 1 NPT}. {-765374400 -39600 0 NST}. {-757342800 -39600 0 NST}. {-86878800 -39600 0 BST}. {-31496400 -39600 0 BST}. {-21466800 -36000 1 BDT}. {-5745600 -39600 0 BST}. {9982800 -36000 1 BDT}. {25704000 -39600 0 BST}. {41432400 -36000 1 BDT}. {57758400 -39600 0 BST}. {73486800 -36000 1 BDT}. {89208000 -39600 0 BST}. {104936400 -36000 1 BDT}. {120657600 -39600 0 BST}. {126709200 -36000 1 BDT}. {152107200 -39600 0 BST}. {162392400 -36000 1 BDT}. {183556800 -39600 0 BST}. {199285200 -36000 1 BDT}. {215611200 -39600 0 BST}. {230734800 -36000 1 BDT}. {247060800 -39600 0 BST}. {262789200 -36000 1 BDT}. {278510400 -39600 0 BST}. {294238800 -36000 1 BDT}. {309960000 -3
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1349
                                                                                                                                                                                                                                  Entropy (8bit):3.6915980783248976
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ8eHNxrW3YrEnBrur9rTPBrJ2r+KrDv1rn1rHhr33rPxN4brSJrrh4rEgtXrH1W:5PxrW3YrEnBruxrT5rJ2r+KrDv1rn1r/
                                                                                                                                                                                                                                  MD5:10B0C457561BA600E9A39CE20CD22B72
                                                                                                                                                                                                                                  SHA1:07946FBB04D0C8D7CA92204E3E2DF3AB755196AB
                                                                                                                                                                                                                                  SHA-256:96AEE3A529C11C8DBDE3431C65C8C2315DBCFB5686957419EFCEB3D49208AB11
                                                                                                                                                                                                                                  SHA-512:A60AFB3DD064EAB9C4AE5F0A112DA5A7903BDB99DCF78BB99FE13DBB72310E8D47A2A62A58DAD2AB4F33971001F5B9787D663649E05FBD47B75994113CD5E8ED
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Noronha) {. {-9223372036854775808 -7780 0 LMT}. {-1767217820 -7200 0 -02}. {-1206961200 -3600 1 -02}. {-1191366000 -7200 0 -02}. {-1175378400 -3600 1 -02}. {-1159830000 -7200 0 -02}. {-633823200 -3600 1 -02}. {-622072800 -7200 0 -02}. {-602287200 -3600 1 -02}. {-591836400 -7200 0 -02}. {-570751200 -3600 1 -02}. {-560214000 -7200 0 -02}. {-539128800 -3600 1 -02}. {-531356400 -7200 0 -02}. {-191368800 -3600 1 -02}. {-184201200 -7200 0 -02}. {-155167200 -3600 1 -02}. {-150073200 -7200 0 -02}. {-128901600 -3600 1 -02}. {-121129200 -7200 0 -02}. {-99957600 -3600 1 -02}. {-89593200 -7200 0 -02}. {-68421600 -3600 1 -02}. {-57970800 -7200 0 -02}. {499744800 -3600 1 -02}. {511232400 -7200 0 -02}. {530589600 -3600 1 -02}. {540262800 -7200 0 -02}. {562125600 -3600 1 -02}. {571194000 -7200 0 -02}. {592970400 -3600 1 -02}. {602038800 -7200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8278
                                                                                                                                                                                                                                  Entropy (8bit):3.7975723806562063
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:raF2dVtXwDTIRqfhXbdXvDXpVXVto//q7u379zlq3LtVBaANIsrXHEK5Dac5TE35:OFcVtXwDTIRqfh57Tlto//q7u379zlqw
                                                                                                                                                                                                                                  MD5:15AABAE9ABE4AF7ABEADF24A510E9583
                                                                                                                                                                                                                                  SHA1:3DEF11310D02F0492DF09591A039F46A8A72D086
                                                                                                                                                                                                                                  SHA-256:B328CC893D217C4FB6C84AA998009940BFBAE240F944F40E7EB900DEF1C7A5CF
                                                                                                                                                                                                                                  SHA-512:7A12A25EB6D6202C47CFDD9F3CE71342406F0EDA3D1D68B842BCFE97EFF1F2E0C11AD34D4EE0A61DF7E0C7E8F400C8CCA73230BDB3C677F8D15CE5CBA44775D7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/North_Dakota/Beulah) {. {-9223372036854775808 -24427 0 LMT}. {-2717643600 -25200 0 MST}. {-1633273200 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1601823600 -21600 1 MDT}. {-1583683200 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-52930800 -21600 1 MDT}. {-37209600 -25200 0 MST}. {-21481200 -21600 1 MDT}. {-5760000 -25200 0 MST}. {9968400 -21600 1 MDT}. {25689600 -25200 0 MST}. {41418000 -21600 1 MDT}. {57744000 -25200 0 MST}. {73472400 -21600 1 MDT}. {89193600 -25200 0 MST}. {104922000 -21600 1 MDT}. {120643200 -25200 0 MST}. {126694800 -21600 1 MDT}. {152092800 -25200 0 MST}. {162378000 -21600 1 MDT}. {183542400 -25200 0 MST}. {199270800 -21600 1 MDT}. {215596800 -25200 0 MST}. {230720400 -21600 1 MDT}. {247046400 -25200 0 MS
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8278
                                                                                                                                                                                                                                  Entropy (8bit):3.7834920003907664
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:LF2dK7X0N41+IestuNEbYkzbXwDTIRqfhXbdXvDXpVXVto//q7u379zlq3LtVBaT:LFcK7X0N41+IestuNEbYkzbXwDTIRqfK
                                                                                                                                                                                                                                  MD5:AC804124F4CE4626F5C1FDA2BC043011
                                                                                                                                                                                                                                  SHA1:4B3E8CC90671BA543112CEE1AB5450C6EA4615DF
                                                                                                                                                                                                                                  SHA-256:E90121F7D275FDCC7B8DCDEC5F8311194D432510FEF5F5F0D6F211A4AACB78EF
                                                                                                                                                                                                                                  SHA-512:056EF65693C16CB58EC5A223528C636346DB37B75000397D03663925545979792BBC50B20B5AA20139ECE9A9D6B73DA80C2319AA4F0609D6FC1A6D30D0567C58
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/North_Dakota/Center) {. {-9223372036854775808 -24312 0 LMT}. {-2717643600 -25200 0 MST}. {-1633273200 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1601823600 -21600 1 MDT}. {-1583683200 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-52930800 -21600 1 MDT}. {-37209600 -25200 0 MST}. {-21481200 -21600 1 MDT}. {-5760000 -25200 0 MST}. {9968400 -21600 1 MDT}. {25689600 -25200 0 MST}. {41418000 -21600 1 MDT}. {57744000 -25200 0 MST}. {73472400 -21600 1 MDT}. {89193600 -25200 0 MST}. {104922000 -21600 1 MDT}. {120643200 -25200 0 MST}. {126694800 -21600 1 MDT}. {152092800 -25200 0 MST}. {162378000 -21600 1 MDT}. {183542400 -25200 0 MST}. {199270800 -21600 1 MDT}. {215596800 -25200 0 MST}. {230720400 -21600 1 MDT}. {247046400 -25200 0 MS
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8281
                                                                                                                                                                                                                                  Entropy (8bit):3.795939700557522
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:uF2dyuNEbYkzbXwDTIRqfhXbdXvDXpVXVto//q7u379zlq3LtVBaANIsrXHEK5Da:uFcyuNEbYkzbXwDTIRqfh57Tlto//q7k
                                                                                                                                                                                                                                  MD5:E26FC508DFD73B610C5543487C763FF5
                                                                                                                                                                                                                                  SHA1:8FBDE67AF561037AAA2EDF93E9456C7E534F4B5A
                                                                                                                                                                                                                                  SHA-256:387D3C57EDE8CCAAD0655F19B35BC0D124C016D16F06B6F2498C1151E4792778
                                                                                                                                                                                                                                  SHA-512:8A10B7370D1521EDF18AB4D5192C930ABC68AB9AE718ADF3D175EACE9A1F5DAC690A76B02EFB4059374761962D8C2660497F8E951DFE9812FB3CFCFDF9165E45
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/North_Dakota/New_Salem) {. {-9223372036854775808 -24339 0 LMT}. {-2717643600 -25200 0 MST}. {-1633273200 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1601823600 -21600 1 MDT}. {-1583683200 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-52930800 -21600 1 MDT}. {-37209600 -25200 0 MST}. {-21481200 -21600 1 MDT}. {-5760000 -25200 0 MST}. {9968400 -21600 1 MDT}. {25689600 -25200 0 MST}. {41418000 -21600 1 MDT}. {57744000 -25200 0 MST}. {73472400 -21600 1 MDT}. {89193600 -25200 0 MST}. {104922000 -21600 1 MDT}. {120643200 -25200 0 MST}. {126694800 -21600 1 MDT}. {152092800 -25200 0 MST}. {162378000 -21600 1 MDT}. {183542400 -25200 0 MST}. {199270800 -21600 1 MDT}. {215596800 -25200 0 MST}. {230720400 -21600 1 MDT}. {247046400 -25200 0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6621
                                                                                                                                                                                                                                  Entropy (8bit):3.7945318113967823
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5gUFM/6M/Mp5tyTc8Ln4ypZ9giGuWGwZIoktiz+hL5Cw5feQ5BT5rBSNNOVQoh/5:KJNfzo+C2mWBNQMsmNTxf6AeO+cblX
                                                                                                                                                                                                                                  MD5:D88A28F381C79410D816F8D2D1610A02
                                                                                                                                                                                                                                  SHA1:81949A1CACD5907CA5A8649385C03813EEFCDDE0
                                                                                                                                                                                                                                  SHA-256:F65C0F8532387AFE703FACDEE325BF8D7F3D1232DEE92D65426FF917DD582CB3
                                                                                                                                                                                                                                  SHA-512:9A9B0C65ECDFF690EF2933B323B3A1CF2D67D0A43F285BB9FEEFF275316148A07F5AC044C48F64E3D8CFA7C1DE44AF220A6855DC01225F8BFFF63AEC946B944A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Ojinaga) {. {-9223372036854775808 -25060 0 LMT}. {-1514739600 -25200 0 MST}. {-1343066400 -21600 0 CST}. {-1234807200 -25200 0 MST}. {-1220292000 -21600 0 CST}. {-1207159200 -25200 0 MST}. {-1191344400 -21600 0 CST}. {820476000 -21600 0 CST}. {828864000 -18000 1 CDT}. {846399600 -21600 0 CST}. {860313600 -18000 1 CDT}. {877849200 -21600 0 CST}. {883634400 -21600 0 CST}. {891766800 -21600 0 MDT}. {909302400 -25200 0 MST}. {923216400 -21600 1 MDT}. {941356800 -25200 0 MST}. {954666000 -21600 1 MDT}. {972806400 -25200 0 MST}. {989139600 -21600 1 MDT}. {1001836800 -25200 0 MST}. {1018170000 -21600 1 MDT}. {1035705600 -25200 0 MST}. {1049619600 -21600 1 MDT}. {1067155200 -25200 0 MST}. {1081069200 -21600 1 MDT}. {1099209600 -25200 0 MST}. {1112518800 -21600 1 MDT}. {1130659200 -25200 0 MST}. {1143968400 -21600 1 MDT}. {1162108800 -2520
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.924365872261203
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52IAcGEu5fcXGm2OHGf8xYvX5BidhZSsc1HRX1vain:SlSWB9X5290WTm2OHDxYP5GhZE3X1iin
                                                                                                                                                                                                                                  MD5:771816CABF25492752C5DA76C5EF74A5
                                                                                                                                                                                                                                  SHA1:6494F467187F99C9A51AB670CD8DC35078D63904
                                                                                                                                                                                                                                  SHA-256:0E323D15EA84D4B6E838D5DCD99AEE68666AF97A770DA2AF84B7BDCA4AB1DBBA
                                                                                                                                                                                                                                  SHA-512:C32D918E121D800B9DFD5CE1F13A4BF2505C0EDCE0085639C8EDF48073E0888906F1A28EF375BDCF549DB14CD33F7C405E28BC35DDF22445C224FBC64146B4EC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Panama) {. {-9223372036854775808 -19088 0 LMT}. {-2524502512 -19176 0 CMT}. {-1946918424 -18000 0 EST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7484
                                                                                                                                                                                                                                  Entropy (8bit):3.768929501362495
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:i2KFEUlpde9pXbO53or0gqvOTFhPI1jFIL:n0r3+
                                                                                                                                                                                                                                  MD5:2701DA468F9F1C819301374E807AAA27
                                                                                                                                                                                                                                  SHA1:F08D7525639EA752D52F36A6D14F14C5514CED8E
                                                                                                                                                                                                                                  SHA-256:6C7DFDE581AC9DE7B4ED6A525A40F905B7550BD2AE7E55D7E2E1B81B771D030B
                                                                                                                                                                                                                                  SHA-512:98BD9EDD40D2982E20A169B8B8E8D411382E5707634BB4F8365CFFF73DB17B8C042D7ED1A59B9511A3A7EB587895119532CCED69F5EFBC49D74FFDC9CA91966F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Pangnirtung) {. {-9223372036854775808 0 0 -00}. {-1546300800 -14400 0 AST}. {-880221600 -10800 1 AWT}. {-769395600 -10800 1 APT}. {-765399600 -14400 0 AST}. {-147902400 -7200 1 ADDT}. {-131572800 -14400 0 AST}. {325663200 -10800 1 ADT}. {341384400 -14400 0 AST}. {357112800 -10800 1 ADT}. {372834000 -14400 0 AST}. {388562400 -10800 1 ADT}. {404888400 -14400 0 AST}. {420012000 -10800 1 ADT}. {436338000 -14400 0 AST}. {452066400 -10800 1 ADT}. {467787600 -14400 0 AST}. {483516000 -10800 1 ADT}. {499237200 -14400 0 AST}. {514965600 -10800 1 ADT}. {530686800 -14400 0 AST}. {544600800 -10800 1 ADT}. {562136400 -14400 0 AST}. {576050400 -10800 1 ADT}. {594190800 -14400 0 AST}. {607500000 -10800 1 ADT}. {625640400 -14400 0 AST}. {638949600 -10800 1 ADT}. {657090000 -14400 0 AST}. {671004000 -10800 1 ADT}. {688539600 -14400 0 AST}. {702
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):244
                                                                                                                                                                                                                                  Entropy (8bit):4.731092370398455
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5290oldJm2OHeke3FIMVTvVOzGXg/VVFAHC:MBp5290olLmdHeV3qSv4zX/OHC
                                                                                                                                                                                                                                  MD5:5D11C2A86B0CDE60801190BFC8FA5E0B
                                                                                                                                                                                                                                  SHA1:38A63200995E359E61F1DEA00C5716938ED7A499
                                                                                                                                                                                                                                  SHA-256:D2078D8D396D5189E1D3555628960990FD63694D08256FF814EE841E01A3F56E
                                                                                                                                                                                                                                  SHA-512:D4D83019E5AE05C3FCDE3518672DC08925C0DECC9FCA6927D75ADA969647CE8EF2D1C67FFD1A075969309CD1B1AADDF15DB21ABDAF241EAA450D2C9E038AEF6A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Paramaribo) {. {-9223372036854775808 -13240 0 LMT}. {-1861906760 -13252 0 PMT}. {-1104524348 -13236 0 PMT}. {-765317964 -12600 0 -0330}. {465449400 -10800 0 -03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):479
                                                                                                                                                                                                                                  Entropy (8bit):4.379302206927978
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5290OQmdH514YPFotFg4tFQxRgmjtFdRb2:cQCeksFsFgcFQxBhF7b2
                                                                                                                                                                                                                                  MD5:1B5C5CBC4168FCCC9100487D3145AF6D
                                                                                                                                                                                                                                  SHA1:6E9E3074B783108032469C8E601D2C63A573B840
                                                                                                                                                                                                                                  SHA-256:9E28F87C0D9EE6AD6791A220742C10C135448965E1F66A7EB04D6477D8FA11B0
                                                                                                                                                                                                                                  SHA-512:4A6527FF5C7F0A0FDC574629714399D9A475EDC1338BF4C9EEEEDCC8CA23E14D2DE4DCA421D46FABA813A65236CD7B8ADBE103B641A763C6BC508738BF73A58C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Phoenix) {. {-9223372036854775808 -26898 0 LMT}. {-2717643600 -25200 0 MST}. {-1633273200 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1601823600 -21600 1 MDT}. {-1583683200 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-820519140 -25200 0 MST}. {-796841940 -25200 0 MST}. {-94669200 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-56221200 -25200 0 MST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6398
                                                                                                                                                                                                                                  Entropy (8bit):3.770736282266079
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5IV1C8phBVSWroLMEbF8xzqXtWl5Hm0RU+5oaIOWIF4IPWFeB/5udPOcBqYZ4vxl:mKXrvOTFhP5S+ijFnRaJeaX1eyDt
                                                                                                                                                                                                                                  MD5:7802A7D0CAEECF52062EA9AAC665051A
                                                                                                                                                                                                                                  SHA1:D965CD157A99FD258331A45F5E86B8F17A444D2B
                                                                                                                                                                                                                                  SHA-256:3D1BEDC932E5CB6315438C7EF060824C927C547009EEA25E8CF16C9D8C4A28B6
                                                                                                                                                                                                                                  SHA-512:4D369FF44CC1B1CBA75C0249B032581BA792830479D22C418C5B0599975E715B8983D93F52B00793F2A419F530BC8877D2DA251393592FD6B865499A97875FD8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Port-au-Prince) {. {-9223372036854775808 -17360 0 LMT}. {-2524504240 -17340 0 PPMT}. {-1670483460 -18000 0 EST}. {421218000 -14400 1 EDT}. {436334400 -18000 0 EST}. {452062800 -14400 1 EDT}. {467784000 -18000 0 EST}. {483512400 -14400 1 EDT}. {499233600 -18000 0 EST}. {514962000 -14400 1 EDT}. {530683200 -18000 0 EST}. {546411600 -14400 1 EDT}. {562132800 -18000 0 EST}. {576050400 -14400 1 EDT}. {594194400 -18000 0 EST}. {607500000 -14400 1 EDT}. {625644000 -18000 0 EST}. {638949600 -14400 1 EDT}. {657093600 -18000 0 EST}. {671004000 -14400 1 EDT}. {688543200 -18000 0 EST}. {702453600 -14400 1 EDT}. {719992800 -18000 0 EST}. {733903200 -14400 1 EDT}. {752047200 -18000 0 EST}. {765352800 -14400 1 EDT}. {783496800 -18000 0 EST}. {796802400 -14400 1 EDT}. {814946400 -18000 0 EST}. {828856800 -14400 1 EDT}. {846396000 -18000 0 EST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):155
                                                                                                                                                                                                                                  Entropy (8bit):5.077805073731929
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52IAcGEuPXGkXGm2OHUnvUdxKzVvwvYv:SlSWB9X5290eSm2OHkzVr
                                                                                                                                                                                                                                  MD5:8169D55899164E2168EF50E219115727
                                                                                                                                                                                                                                  SHA1:42848A510C120D4E834BE61FC76A1C539BA88C8A
                                                                                                                                                                                                                                  SHA-256:6C8718C65F99AB43377609705E773C93F7993FBB3B425E1989E8231308C475AF
                                                                                                                                                                                                                                  SHA-512:1590D42E88DD92542CADC022391C286842C156DA4795877EA67FEF045E0A831615C3935E08098DD71CF29C972EDC79084FFCC9AFAB7813AE74EEE14D6CFEFB9D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Port_of_Spain) {. {-9223372036854775808 -14764 0 LMT}. {-1825098836 -14400 0 AST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):196
                                                                                                                                                                                                                                  Entropy (8bit):4.818272118524638
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7thtedVAIgpthKQ290msh490thB:MBaIMYdxpR290v490x
                                                                                                                                                                                                                                  MD5:1C0C736D0593654230FCBB0DC275313B
                                                                                                                                                                                                                                  SHA1:00518615F97BCFF2F6862116F4DF834B70E2D4CA
                                                                                                                                                                                                                                  SHA-256:5C97E6DF0FC03F13A0814274A9C3A983C474000AE3E78806B38DF9208372FD54
                                                                                                                                                                                                                                  SHA-512:2252D17CB4F770124586BBF35974077212B92C1587071C9F552F1EFAC15CBF92128E61C456F9F5154D212F7D66CC5BD85B76B1187D5A6F24E89E14EDF322D67F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Rio_Branco)]} {. LoadTimeZoneFile America/Rio_Branco.}.set TZData(:America/Porto_Acre) $TZData(:America/Rio_Branco).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1016
                                                                                                                                                                                                                                  Entropy (8bit):3.7660008200834842
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQQe478Sos/USws/QSI/LHSD/vOSy/WS3o/aS2/vSh/TSSX/WcSp/ySZd/YlSj/f:5bSaSwXS4SqSbS3JSySxSxcSESAlSQSv
                                                                                                                                                                                                                                  MD5:5E4CB713378D22D90A1A86F0AF33D6E8
                                                                                                                                                                                                                                  SHA1:CF4B2A68873BF778257D40AEA887D4BCBEE6CC72
                                                                                                                                                                                                                                  SHA-256:6D7F49E0A67C69A3945DA4BC780653C8D875650536A810610A6518080CC483DB
                                                                                                                                                                                                                                  SHA-512:06559B6E80BCDD42120398E19CCB3AEE8A1B08E09D0DF07DB9CCD68A863A7670D6D6457018CE3D9E23FE359D3E2EC0D249134EE0D969C0312665975B67DB8E80
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Porto_Velho) {. {-9223372036854775808 -15336 0 LMT}. {-1767210264 -14400 0 -04}. {-1206954000 -10800 1 -04}. {-1191358800 -14400 0 -04}. {-1175371200 -10800 1 -04}. {-1159822800 -14400 0 -04}. {-633816000 -10800 1 -04}. {-622065600 -14400 0 -04}. {-602280000 -10800 1 -04}. {-591829200 -14400 0 -04}. {-570744000 -10800 1 -04}. {-560206800 -14400 0 -04}. {-539121600 -10800 1 -04}. {-531349200 -14400 0 -04}. {-191361600 -10800 1 -04}. {-184194000 -14400 0 -04}. {-155160000 -10800 1 -04}. {-150066000 -14400 0 -04}. {-128894400 -10800 1 -04}. {-121122000 -14400 0 -04}. {-99950400 -10800 1 -04}. {-89586000 -14400 0 -04}. {-68414400 -10800 1 -04}. {-57963600 -14400 0 -04}. {499752000 -10800 1 -04}. {511239600 -14400 0 -04}. {530596800 -10800 1 -04}. {540270000 -14400 0 -04}. {562132800 -10800 1 -04}. {571201200 -14400 0 -04}. {590036400
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):273
                                                                                                                                                                                                                                  Entropy (8bit):4.728240676465187
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5290pbm2OH9VPMGoeVVFrZVVFUFkeF3k/eJpR/r:MBp5290lmdHvPMpe/ZZ/uFkeF3k/eJ/D
                                                                                                                                                                                                                                  MD5:2FB893819124F19A7068F802D6A59357
                                                                                                                                                                                                                                  SHA1:6B35C198F74FF5880714A3182407858193CE37A4
                                                                                                                                                                                                                                  SHA-256:F05530CFBCE7242847BE265C2D26C8B95B00D927817B050A523FFB139991B09E
                                                                                                                                                                                                                                  SHA-512:80739F431F6B3548EFD4F70FE3630F66F70CB29B66845B8072D26393ADD7DAB22675BE6DA5FBDC7561D4F3F214816AAD778B6CD0EE45264B4D6FFA48B3AC7C43
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Puerto_Rico) {. {-9223372036854775808 -15865 0 LMT}. {-2233035335 -14400 0 AST}. {-873057600 -10800 0 AWT}. {-769395600 -10800 1 APT}. {-765399600 -14400 0 AST}. {-757368000 -14400 0 AST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3576
                                                                                                                                                                                                                                  Entropy (8bit):3.5316229197228632
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:Yv9+P8pYraRo+kP0pDrMb6UHlRnHqhTxxJAHXEa9c0yq/g2tw5E8fIk5iWpOFZAd:YoP8pYraRo+kP0pDrMb60RnHqhTxxJAw
                                                                                                                                                                                                                                  MD5:1FFFED9AA83AA3CA9E7330AA27E8D188
                                                                                                                                                                                                                                  SHA1:9B45F2662C1F3F0799ED4221E843483674878F43
                                                                                                                                                                                                                                  SHA-256:FECDC08709D5852A07D8F5C7DD7DBDBCD3D864A0893248E3D3932A2F848EB4B2
                                                                                                                                                                                                                                  SHA-512:8F6D51F94A91168EE092972316E150C2B487808EA3506F77FD028F84436FE29AD5BAD50A8DB65BCFB524D5A12DC1C66C5C0BC9A7FC6AE8A0EAAED6F4BA5ADED7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Punta_Arenas) {. {-9223372036854775808 -17020 0 LMT}. {-2524504580 -16966 0 SMT}. {-1892661434 -18000 0 -05}. {-1688410800 -16966 0 SMT}. {-1619205434 -14400 0 -04}. {-1593806400 -16966 0 SMT}. {-1335986234 -18000 0 -05}. {-1335985200 -14400 1 -05}. {-1317585600 -18000 0 -05}. {-1304362800 -14400 1 -05}. {-1286049600 -18000 0 -05}. {-1272826800 -14400 1 -05}. {-1254513600 -18000 0 -05}. {-1241290800 -14400 1 -05}. {-1222977600 -18000 0 -05}. {-1209754800 -14400 1 -05}. {-1191355200 -18000 0 -05}. {-1178132400 -14400 0 -04}. {-870552000 -18000 0 -05}. {-865278000 -14400 0 -04}. {-718056000 -18000 0 -05}. {-713649600 -14400 0 -04}. {-36619200 -10800 1 -04}. {-23922000 -14400 0 -04}. {-3355200 -10800 1 -04}. {7527600 -14400 0 -04}. {24465600 -10800 1 -04}. {37767600 -14400 0 -04}. {55915200 -10800 1 -04}. {69217200 -14400 0 -04}. {87
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7840
                                                                                                                                                                                                                                  Entropy (8bit):3.75014960690837
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:k+iBktTzZSJw5/9/yuvQ+hcrD57X0N41+IestuNEbYkzbXwDTIRqfhXbdXvDXpVS:k+iBmTzZSJw5/9/yuvQ6crD57X0N41+a
                                                                                                                                                                                                                                  MD5:9C10496730E961187C33C1AE91C8A60D
                                                                                                                                                                                                                                  SHA1:A77E3508859FB6F76A7445CD13CD42348CB4EBC7
                                                                                                                                                                                                                                  SHA-256:136F0A49742F30B05B7C6BF3BF014CC999104F4957715D0BEB39F5440D5216DF
                                                                                                                                                                                                                                  SHA-512:70936E65D0B439F6BE6E31E27032F10BA2EB54672647DA615744ABC7A767F197F0C7FDBCCEE0D335CBCECB6855B7BD899D1A5B97BA5083FFA42AF5F30343EA7F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Rainy_River) {. {-9223372036854775808 -22696 0 LMT}. {-2366732504 -21600 0 CST}. {-1632067200 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-923248800 -18000 1 CDT}. {-880214400 -18000 0 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {136368000 -18000 1 CDT}. {152089200 -21600 0 CST}. {167817600 -18000 1 CDT}. {183538800 -21600 0 CST}. {199267200 -18000 1 CDT}. {215593200 -21600 0 CST}. {230716800 -18000 1 CDT}. {247042800 -21600 0 CST}. {262771200 -18000 1 CDT}. {278492400 -21600 0 CST}. {294220800 -18000 1 CDT}. {309942000 -21600 0 CST}. {325670400 -18000 1 CDT}. {341391600 -21600 0 CST}. {357120000 -18000 1 CDT}. {372841200 -21600 0 CST}. {388569600 -18000 1 CDT}. {404895600 -21600 0 CST}. {420019200 -18000 1 CDT}. {436345200 -21600 0 CST}. {452073600 -18000 1 CDT}. {467794800 -21600 0 CST}. {483523200 -18000 1 CDT}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7366
                                                                                                                                                                                                                                  Entropy (8bit):3.749928775816306
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:vw5/9/yuvQ+hcrD57X0N41+IstuNEbYkzbXwDTIRqfhXbdXvDXpVXVto//q7u37N:vw5/9/yuvQ6crD57X0N41+IstuNEbYkJ
                                                                                                                                                                                                                                  MD5:54F6D5098A0CF940F066EADEEA234A57
                                                                                                                                                                                                                                  SHA1:20B9FE5F6F70E97420A6D9939AA43C4CCFA8231B
                                                                                                                                                                                                                                  SHA-256:AA68088E41A018002E5CE12B14F8910E5ECE5F26D5854092E351BAAC2F90DB2B
                                                                                                                                                                                                                                  SHA-512:9EC1AF599604CEE266D9A4377B6CDABF94E61D0177CBC2158122406BF551AE0E3EE4CF147B28A382277B015CCB8F4405DB3EB3AE6425431EBB43CCDE08AEA3E1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Rankin_Inlet) {. {-9223372036854775808 0 0 -00}. {-410227200 -21600 0 CST}. {-147895200 -14400 1 CDDT}. {-131565600 -21600 0 CST}. {325670400 -18000 1 CDT}. {341391600 -21600 0 CST}. {357120000 -18000 1 CDT}. {372841200 -21600 0 CST}. {388569600 -18000 1 CDT}. {404895600 -21600 0 CST}. {420019200 -18000 1 CDT}. {436345200 -21600 0 CST}. {452073600 -18000 1 CDT}. {467794800 -21600 0 CST}. {483523200 -18000 1 CDT}. {499244400 -21600 0 CST}. {514972800 -18000 1 CDT}. {530694000 -21600 0 CST}. {544608000 -18000 1 CDT}. {562143600 -21600 0 CST}. {576057600 -18000 1 CDT}. {594198000 -21600 0 CST}. {607507200 -18000 1 CDT}. {625647600 -21600 0 CST}. {638956800 -18000 1 CDT}. {657097200 -21600 0 CST}. {671011200 -18000 1 CDT}. {688546800 -21600 0 CST}. {702460800 -18000 1 CDT}. {719996400 -21600 0 CST}. {733910400 -18000 1 CDT}. {75205
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1372
                                                                                                                                                                                                                                  Entropy (8bit):3.6943875149362064
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQHJeHQc4h1u80V2dBUGphmC17ewGtN3rvIh0VBHZDIykqWoN:5Kh4h19U2dBUGrmO7XGtN3kh0VBHZUnk
                                                                                                                                                                                                                                  MD5:1567A3F3419D1A4FCF817A6EDC11769E
                                                                                                                                                                                                                                  SHA1:2970F9EDD76B77A843D31F518587C17A05EC4C43
                                                                                                                                                                                                                                  SHA-256:3F62246DF3A378815772D9D942033FB235B048B62F5EF52A3DCD6DB3871E0DB5
                                                                                                                                                                                                                                  SHA-512:567BEAC48AE0FEEB32FE40EEA73EB4601DBDBF72FA963777E5F5C3E9972E2AD7A359301E80E574592AFB3045414A177D0ABD38DF958BD5317B02D4DFD2DCE607
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Recife) {. {-9223372036854775808 -8376 0 LMT}. {-1767217224 -10800 0 -03}. {-1206957600 -7200 1 -03}. {-1191362400 -10800 0 -03}. {-1175374800 -7200 1 -03}. {-1159826400 -10800 0 -03}. {-633819600 -7200 1 -03}. {-622069200 -10800 0 -03}. {-602283600 -7200 1 -03}. {-591832800 -10800 0 -03}. {-570747600 -7200 1 -03}. {-560210400 -10800 0 -03}. {-539125200 -7200 1 -03}. {-531352800 -10800 0 -03}. {-191365200 -7200 1 -03}. {-184197600 -10800 0 -03}. {-155163600 -7200 1 -03}. {-150069600 -10800 0 -03}. {-128898000 -7200 1 -03}. {-121125600 -10800 0 -03}. {-99954000 -7200 1 -03}. {-89589600 -10800 0 -03}. {-68418000 -7200 1 -03}. {-57967200 -10800 0 -03}. {499748400 -7200 1 -03}. {511236000 -10800 0 -03}. {530593200 -7200 1 -03}. {540266400 -10800 0 -03}. {562129200 -7200 1 -03}. {571197600 -10800 0 -03}. {592974000 -7200 1 -03}. {60
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1723
                                                                                                                                                                                                                                  Entropy (8bit):3.956012642028802
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:56ecDOBDgE+hIZVEa3lGw+6yZgTX+rNO46wYDW:86VlGS8
                                                                                                                                                                                                                                  MD5:7D955B277C43D51F19377A91B987FAF9
                                                                                                                                                                                                                                  SHA1:F2F3E11E955C3E58E21654F3D841B5B1528C0913
                                                                                                                                                                                                                                  SHA-256:A1FA7BF002B3BA8DCA4D52AA0BB41C047DDAF88B2E542E1FCF81CB3AAF91AA75
                                                                                                                                                                                                                                  SHA-512:719DEE7A932EDB9255D711E82AC0CA3FCFB07AF3EFE2EE0D887D7137F6059BEBE07F85D910CC0005391D244B4EADA16257BE49787938386FD4B5DB6D8E31D513
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Regina) {. {-9223372036854775808 -25116 0 LMT}. {-2030202084 -25200 0 MST}. {-1632063600 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1251651600 -21600 1 MDT}. {-1238349600 -25200 0 MST}. {-1220202000 -21600 1 MDT}. {-1206900000 -25200 0 MST}. {-1188752400 -21600 1 MDT}. {-1175450400 -25200 0 MST}. {-1156698000 -21600 1 MDT}. {-1144000800 -25200 0 MST}. {-1125248400 -21600 1 MDT}. {-1111946400 -25200 0 MST}. {-1032714000 -21600 1 MDT}. {-1016992800 -25200 0 MST}. {-1001264400 -21600 1 MDT}. {-986148000 -25200 0 MST}. {-969814800 -21600 1 MDT}. {-954093600 -25200 0 MST}. {-937760400 -21600 1 MDT}. {-922039200 -25200 0 MST}. {-906310800 -21600 1 MDT}. {-890589600 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-748450800 -21600 1 MDT}. {-732729600 -25200 0 MST}. {-715791600 -21600 1 MDT}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7362
                                                                                                                                                                                                                                  Entropy (8bit):3.7460671071064846
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:iw5/9/yuvQ+hcrD57X0N41+IstuNESkzbXwDTIRqfhXbdXvDXpVXVto//q7u379L:iw5/9/yuvQ6crD57X0N41+IstuNESkzV
                                                                                                                                                                                                                                  MD5:07FFF43B350D520D13D91701618AD72E
                                                                                                                                                                                                                                  SHA1:8D4B36A6D3257509C209D0B78B58982709FB8807
                                                                                                                                                                                                                                  SHA-256:39E13235F87A1B8621ADA62C9AD2EBF8E17687C5533658E075EFA70A04D5C78D
                                                                                                                                                                                                                                  SHA-512:37397A2621F0A1EA6B46F6769D583CAEA9703924A2C652B8B58FA4C7DBA8E789BA8FE442FB2C77504E495617591FB138AD733063E3A4A0153ED2B26D4B863018
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Resolute) {. {-9223372036854775808 0 0 -00}. {-704937600 -21600 0 CST}. {-147895200 -14400 1 CDDT}. {-131565600 -21600 0 CST}. {325670400 -18000 1 CDT}. {341391600 -21600 0 CST}. {357120000 -18000 1 CDT}. {372841200 -21600 0 CST}. {388569600 -18000 1 CDT}. {404895600 -21600 0 CST}. {420019200 -18000 1 CDT}. {436345200 -21600 0 CST}. {452073600 -18000 1 CDT}. {467794800 -21600 0 CST}. {483523200 -18000 1 CDT}. {499244400 -21600 0 CST}. {514972800 -18000 1 CDT}. {530694000 -21600 0 CST}. {544608000 -18000 1 CDT}. {562143600 -21600 0 CST}. {576057600 -18000 1 CDT}. {594198000 -21600 0 CST}. {607507200 -18000 1 CDT}. {625647600 -21600 0 CST}. {638956800 -18000 1 CDT}. {657097200 -21600 0 CST}. {671011200 -18000 1 CDT}. {688546800 -21600 0 CST}. {702460800 -18000 1 CDT}. {719996400 -21600 0 CST}. {733910400 -18000 1 CDT}. {752050800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1075
                                                                                                                                                                                                                                  Entropy (8bit):3.7557219407321303
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQYEeH5yyss/u/C5/ukCI/uiCk/u8CHe/uOCXs/um4Co/uN3Cc/ux8CL/uiFCy/i:5q5xs5IlTToo4mdGFtapG8dtedkFL
                                                                                                                                                                                                                                  MD5:9AA66AEB91380EFD3313338A2DCBE432
                                                                                                                                                                                                                                  SHA1:2D86915D1F331CC7050BBFAAE3315CE1440813C1
                                                                                                                                                                                                                                  SHA-256:53DB45CF4CB369DA06C31478A793E787541DA0E77C042EBC7A10175A6BB6EFF6
                                                                                                                                                                                                                                  SHA-512:C9B4F6544B4A1E77BFF6D423A9AD5E003E32FA77B00ECC2A7AF6D2279ACC849ABE331E5DE27C450A6BF86ECC2450CEBFAB4880AB69C54649D4C7EE0AF05CD377
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Rio_Branco) {. {-9223372036854775808 -16272 0 LMT}. {-1767209328 -18000 0 -05}. {-1206950400 -14400 1 -05}. {-1191355200 -18000 0 -05}. {-1175367600 -14400 1 -05}. {-1159819200 -18000 0 -05}. {-633812400 -14400 1 -05}. {-622062000 -18000 0 -05}. {-602276400 -14400 1 -05}. {-591825600 -18000 0 -05}. {-570740400 -14400 1 -05}. {-560203200 -18000 0 -05}. {-539118000 -14400 1 -05}. {-531345600 -18000 0 -05}. {-191358000 -14400 1 -05}. {-184190400 -18000 0 -05}. {-155156400 -14400 1 -05}. {-150062400 -18000 0 -05}. {-128890800 -14400 1 -05}. {-121118400 -18000 0 -05}. {-99946800 -14400 1 -05}. {-89582400 -18000 0 -05}. {-68410800 -14400 1 -05}. {-57960000 -18000 0 -05}. {499755600 -14400 1 -05}. {511243200 -18000 0 -05}. {530600400 -14400 1 -05}. {540273600 -18000 0 -05}. {562136400 -14400 1 -05}. {571204800 -18000 0 -05}. {590040000 -
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):214
                                                                                                                                                                                                                                  Entropy (8bit):4.752946571641783
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7/MdVAIgp/MOF290rI5290/Msn:MBaIMY/M4p/MOF290r190/Ms
                                                                                                                                                                                                                                  MD5:4FC460A084DF33A73F2F87B7962B0084
                                                                                                                                                                                                                                  SHA1:45E70D5D68FC2DE0ACFF76B062ADA17E0021460F
                                                                                                                                                                                                                                  SHA-256:D1F5FFD2574A009474230E0AA764256B039B1D78D91A1CB944B21776377B5B70
                                                                                                                                                                                                                                  SHA-512:40045420FE88FA54DE4A656534C0A51357FBAB3EA3B9120DA15526A9DEC7EEC2C9799F4D9A72B6050474AD67490BC28540FDA0F17B7FCAF125D41CBCA96ECCDE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Argentina/Cordoba)]} {. LoadTimeZoneFile America/Argentina/Cordoba.}.set TZData(:America/Rosario) $TZData(:America/Argentina/Cordoba).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):189
                                                                                                                                                                                                                                  Entropy (8bit):4.820569634622523
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0qfSwVAIg20qfo2IAcGEtX2exp4IAcGEqfu:SlSWB9IZaM3y7eHVAIgpeo290tX2U49Q
                                                                                                                                                                                                                                  MD5:75EA3845AFED3FBBF8496824A353DA32
                                                                                                                                                                                                                                  SHA1:207A1520F041B09CCD5034E6E87D3F7A4FBD460E
                                                                                                                                                                                                                                  SHA-256:2FACC167377FC1F592D2926829EB2980F58BE38D50424F64DFA04A2ECBBE1559
                                                                                                                                                                                                                                  SHA-512:B9D4DB95CEA1DADCE27264BBD198676465854E9C55D6BB175966D860D9AF7014F6635A945510602C0A9FBF08596B064DAE7D30589886960F06B2F8E69786CFF6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Tijuana)]} {. LoadTimeZoneFile America/Tijuana.}.set TZData(:America/Santa_Isabel) $TZData(:America/Tijuana).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1043
                                                                                                                                                                                                                                  Entropy (8bit):3.7336343389566795
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQceUh8Sos/USws/QSI/LHSD/vOSy/WS3o/aS2/vSh/TSSX/WcSp/ySZd/YlSj/X:57SaSwXS4SqSbS3JSySxSxcSESAlSQSn
                                                                                                                                                                                                                                  MD5:8F5EAA4F5099B82EDD68893C5D99A0EF
                                                                                                                                                                                                                                  SHA1:1B21DAD0CD54E083A6EADCFD57CA8F58759189AD
                                                                                                                                                                                                                                  SHA-256:1A46357BC4FE682AF78FFAB10A6A88893BEF50AECC6ACA217A5EBC1B98C01C07
                                                                                                                                                                                                                                  SHA-512:2C82822CCA208E900383A1B55882BFC3559EC116C5B5AD2452BA367594AEF36F34C316FFA18B2BAB71A82FC382559069385947548EE9902FEDCDED084801ABF2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Santarem) {. {-9223372036854775808 -13128 0 LMT}. {-1767212472 -14400 0 -04}. {-1206954000 -10800 1 -04}. {-1191358800 -14400 0 -04}. {-1175371200 -10800 1 -04}. {-1159822800 -14400 0 -04}. {-633816000 -10800 1 -04}. {-622065600 -14400 0 -04}. {-602280000 -10800 1 -04}. {-591829200 -14400 0 -04}. {-570744000 -10800 1 -04}. {-560206800 -14400 0 -04}. {-539121600 -10800 1 -04}. {-531349200 -14400 0 -04}. {-191361600 -10800 1 -04}. {-184194000 -14400 0 -04}. {-155160000 -10800 1 -04}. {-150066000 -14400 0 -04}. {-128894400 -10800 1 -04}. {-121122000 -14400 0 -04}. {-99950400 -10800 1 -04}. {-89586000 -14400 0 -04}. {-68414400 -10800 1 -04}. {-57963600 -14400 0 -04}. {499752000 -10800 1 -04}. {511239600 -14400 0 -04}. {530596800 -10800 1 -04}. {540270000 -14400 0 -04}. {562132800 -10800 1 -04}. {571201200 -14400 0 -04}. {590036400 -14
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8582
                                                                                                                                                                                                                                  Entropy (8bit):3.4381885094053835
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:LCA/E8pYraRo+kP0pDrMb60RnHqhTxxJA3Ea9c0yq/g2tw5E8Q+iWMFeHpkUu9/6:LRNBnrR59bPYUt
                                                                                                                                                                                                                                  MD5:47BED3B60EF45B00267B4D628A2F18C4
                                                                                                                                                                                                                                  SHA1:B3827DF571CF2CA16074188CE0E3061E296B8B26
                                                                                                                                                                                                                                  SHA-256:51BB12A2397CAD3D412C9E8F3BA06DD98CC379F999DB3D00ED651A84DA1D6D1C
                                                                                                                                                                                                                                  SHA-512:8DA831A0EAB180C982395F2BA85952959A676AADA87823E56C5B643FEB7082B6605FD3645D880B19F3F9EE5B25353002309CDB37AE68F1B3A192AE1280B74404
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Santiago) {. {-9223372036854775808 -16966 0 LMT}. {-2524504634 -16966 0 SMT}. {-1892661434 -18000 0 -05}. {-1688410800 -16966 0 SMT}. {-1619205434 -14400 0 -04}. {-1593806400 -16966 0 SMT}. {-1335986234 -18000 0 -05}. {-1335985200 -14400 1 -05}. {-1317585600 -18000 0 -05}. {-1304362800 -14400 1 -05}. {-1286049600 -18000 0 -05}. {-1272826800 -14400 1 -05}. {-1254513600 -18000 0 -05}. {-1241290800 -14400 1 -05}. {-1222977600 -18000 0 -05}. {-1209754800 -14400 1 -05}. {-1191355200 -18000 0 -05}. {-1178132400 -14400 0 -04}. {-870552000 -18000 0 -05}. {-865278000 -14400 0 -04}. {-740520000 -10800 1 -03}. {-736376400 -14400 0 -04}. {-718056000 -18000 0 -05}. {-713649600 -14400 0 -04}. {-36619200 -10800 1 -04}. {-23922000 -14400 0 -04}. {-3355200 -10800 1 -04}. {7527600 -14400 0 -04}. {24465600 -10800 1 -04}. {37767600 -14400 0 -04}. {55
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):595
                                                                                                                                                                                                                                  Entropy (8bit):4.2614212422453726
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5290/SyJmdHhvPu4/G/uFNM/KMVvMj/+MVvMqx/r0XVvMnUB/B7VvMa6I8/0p:cQ+DJeVu4e/uICEkFvxwdqUBZp965VPO
                                                                                                                                                                                                                                  MD5:04F2A2C789E041270354376C3FD90D2D
                                                                                                                                                                                                                                  SHA1:D0B89262D559021FAC035A519C96D2A2FA417F9C
                                                                                                                                                                                                                                  SHA-256:42EF317EA851A781B041DC1951EA5A3EA1E924149C4B868ECD75F24672B28FA8
                                                                                                                                                                                                                                  SHA-512:F8D072527ED38C2FF1C9E08219104213352B2EFA1171C0D1E02B6B1542B4929D0C4640B441326791CC86F23206621CD4E0D3247CBAB1F99B63E65DB667F3DFED
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Santo_Domingo) {. {-9223372036854775808 -16776 0 LMT}. {-2524504824 -16800 0 SDMT}. {-1159773600 -18000 0 EST}. {-100119600 -14400 1 EDT}. {-89668800 -18000 0 EST}. {-5770800 -16200 1 -0430}. {4422600 -18000 0 EST}. {25678800 -16200 1 -0430}. {33193800 -18000 0 EST}. {57733200 -16200 1 -0430}. {64816200 -18000 0 EST}. {89182800 -16200 1 -0430}. {96438600 -18000 0 EST}. {120632400 -16200 1 -0430}. {127974600 -18000 0 EST}. {152082000 -14400 0 AST}. {975823200 -14400 0 AST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7552
                                                                                                                                                                                                                                  Entropy (8bit):3.4588792656032914
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Lam19U2gUGrpzsVE0OjmicnyVkHZWWWE/+ZqPuWcBpR4xHtMlAbGCoGzvGmFGgh4:L3Yc8u9U
                                                                                                                                                                                                                                  MD5:DEA27A3FE65A22BE42A97C6AB58E9687
                                                                                                                                                                                                                                  SHA1:CD50184C4D1739CF5568E21683980FC63C9BFF24
                                                                                                                                                                                                                                  SHA-256:AFA706258270F20F9317FF5B84957A2DF77842D564922C15DC302F7A8AB59CEC
                                                                                                                                                                                                                                  SHA-512:34C306EC889C10988B3D9C236903417BCA1590E96CD60AE700882C064CCC410132265F106BB10D9593AFFA32B923728FBDDFB6DEE77CAF4A058C877F4D5F1EF1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Sao_Paulo) {. {-9223372036854775808 -11188 0 LMT}. {-1767214412 -10800 0 -03}. {-1206957600 -7200 1 -03}. {-1191362400 -10800 0 -03}. {-1175374800 -7200 1 -03}. {-1159826400 -10800 0 -03}. {-633819600 -7200 1 -03}. {-622069200 -10800 0 -03}. {-602283600 -7200 1 -03}. {-591832800 -10800 0 -03}. {-570747600 -7200 1 -03}. {-560210400 -10800 0 -03}. {-539125200 -7200 1 -03}. {-531352800 -10800 0 -03}. {-195429600 -7200 1 -02}. {-189381600 -7200 0 -03}. {-184197600 -10800 0 -03}. {-155163600 -7200 1 -03}. {-150069600 -10800 0 -03}. {-128898000 -7200 1 -03}. {-121125600 -10800 0 -03}. {-99954000 -7200 1 -03}. {-89589600 -10800 0 -03}. {-68418000 -7200 1 -03}. {-57967200 -10800 0 -03}. {499748400 -7200 1 -03}. {511236000 -10800 0 -03}. {530593200 -7200 1 -03}. {540266400 -10800 0 -03}. {562129200 -7200 1 -03}. {571197600 -10800 0 -03}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6593
                                                                                                                                                                                                                                  Entropy (8bit):3.4670685654529194
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:URW/ukG9UDHaXZgsP/N/LWAWVF20V/VapcJlNcnkF0:BuZUDHaXZgsN/FWVFjHv0
                                                                                                                                                                                                                                  MD5:7E7EF4D67CCD455833603F7EF9E374A6
                                                                                                                                                                                                                                  SHA1:4AD722F75FC88572DD5A2CD1845FF5F68ED4B58A
                                                                                                                                                                                                                                  SHA-256:2B5B2A00793545C8D32437D7DAA2A36B42D3B1B7421054621841E2919F713294
                                                                                                                                                                                                                                  SHA-512:0688EB3EBDE78E18EE5E31DE57F1CBE0BF10071A6EDC97D284B2B3E1E22975262190934446C202E90EFD161686F4790342EDDBCACADB3A65B0AC6C1A9099C79F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Scoresbysund) {. {-9223372036854775808 -5272 0 LMT}. {-1686090728 -7200 0 -02}. {323841600 -3600 0 -01}. {338961600 -7200 0 -02}. {354679200 0 0 +00}. {370400400 -3600 0 -01}. {386125200 0 1 +00}. {401850000 -3600 0 -01}. {417574800 0 1 +00}. {433299600 -3600 0 -01}. {449024400 0 1 +00}. {465354000 -3600 0 -01}. {481078800 0 1 +00}. {496803600 -3600 0 -01}. {512528400 0 1 +00}. {528253200 -3600 0 -01}. {543978000 0 1 +00}. {559702800 -3600 0 -01}. {575427600 0 1 +00}. {591152400 -3600 0 -01}. {606877200 0 1 +00}. {622602000 -3600 0 -01}. {638326800 0 1 +00}. {654656400 -3600 0 -01}. {670381200 0 1 +00}. {686106000 -3600 0 -01}. {701830800 0 1 +00}. {717555600 -3600 0 -01}. {733280400 0 1 +00}. {749005200 -3600 0 -01}. {764730000 0 1 +00}. {780454800 -3600 0 -01}. {796179600 0 1 +00}. {811904400 -3600 0 -01}. {828234000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):182
                                                                                                                                                                                                                                  Entropy (8bit):4.840231755053259
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx06RGFwVAIg206RAO0L2IAcGEtOFBx+IAcGE6Ru:SlSWB9IZaM3y7+SwVAIgp+iL290tO09G
                                                                                                                                                                                                                                  MD5:65307038DB12A7A447284DF4F3E6A3E8
                                                                                                                                                                                                                                  SHA1:DC28D6863986D7A158CEF239D46BE9F5033DF897
                                                                                                                                                                                                                                  SHA-256:3FD862C9DB2D5941DFDBA5622CC53487A7FC5039F7012B78D3EE4B58753D078D
                                                                                                                                                                                                                                  SHA-512:91BC29B7EC9C49D4020DC26F682D0EFBBBEE83D10D79C766A08C78D5FF04D9C0A09288D9696A378E777B65E0C2C2AC8A218C12F86C45BD6E7B5E204AE5FC2335
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Denver)]} {. LoadTimeZoneFile America/Denver.}.set TZData(:America/Shiprock) $TZData(:America/Denver).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8376
                                                                                                                                                                                                                                  Entropy (8bit):3.8793735356495116
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:lG19jJps/Q7Ddh5sBPyNsSLFOMM/EowALVZVmWa86Eac8rQ:lM9jI/4h5sBPy+CMt/ElALLVuAH
                                                                                                                                                                                                                                  MD5:2F2C91BD29B32A281F9FB1F811953ACB
                                                                                                                                                                                                                                  SHA1:49102C37397CC9B7CDCDCE6A76F9BE03D0B446AB
                                                                                                                                                                                                                                  SHA-256:6ABBF55FEE7839B9EEEBB97EA53E185E1A0E189843531257708258841A35EB76
                                                                                                                                                                                                                                  SHA-512:FB06D4FE28BD9DD9D56A7365F1E2CC7434678B8850CECF99A232F07B4B720F092980EC337C279E599A12E54548DE6AC253547FE4C255BEFA7B545F8C93375589
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Sitka) {. {-9223372036854775808 53927 0 LMT}. {-3225223727 -32473 0 LMT}. {-2188954727 -28800 0 PST}. {-883584000 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-757353600 -28800 0 PST}. {-31507200 -28800 0 PST}. {-21477600 -25200 1 PDT}. {-5756400 -28800 0 PST}. {9972000 -25200 1 PDT}. {25693200 -28800 0 PST}. {41421600 -25200 1 PDT}. {57747600 -28800 0 PST}. {73476000 -25200 1 PDT}. {89197200 -28800 0 PST}. {104925600 -25200 1 PDT}. {120646800 -28800 0 PST}. {126698400 -25200 1 PDT}. {152096400 -28800 0 PST}. {162381600 -25200 1 PDT}. {183546000 -28800 0 PST}. {199274400 -25200 1 PDT}. {215600400 -28800 0 PST}. {230724000 -25200 1 PDT}. {247050000 -28800 0 PST}. {262778400 -25200 1 PDT}. {278499600 -28800 0 PST}. {294228000 -25200 1 PDT}. {309949200 -28800 0 PST}. {325677600 -
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):208
                                                                                                                                                                                                                                  Entropy (8bit):4.905980413237828
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290txP90e/:MBaIMY9QpI2907P90O
                                                                                                                                                                                                                                  MD5:B6E45D20EB8CC73A77B9A75578E5C246
                                                                                                                                                                                                                                  SHA1:19C6BB6ED12B6943CF7BDFFE4C8A8D72DB491E44
                                                                                                                                                                                                                                  SHA-256:31E60EAC8ABFA8D3DAD501D3BCDCA7C4DB7031B65ADDA24EC11A6DEE1E3D14C3
                                                                                                                                                                                                                                  SHA-512:C0F3BF8D106E77C1000E45D0A6C8E7C05B7B97EFA2EECCA45FEF48EB42FBDD5336FD551C794064EADFB6919A12813FF66B2F95722877432B4A48B1FBA6C5409D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/St_Barthelemy) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10917
                                                                                                                                                                                                                                  Entropy (8bit):3.7872036312069963
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Vvprjhbvd8mSGu9EnkBVAZK2GrbrvZeuqpNFT:Vvbvd7SGu9lzoVpDT
                                                                                                                                                                                                                                  MD5:F87531D6DC9AAFB2B0F79248C5ADA772
                                                                                                                                                                                                                                  SHA1:E14C52B0F564FA3A3536B7576A2B27D4738CA76B
                                                                                                                                                                                                                                  SHA-256:0439DA60D4C52F0E777431BF853D366E2B5D89275505201080954D88F6CA9478
                                                                                                                                                                                                                                  SHA-512:5B43CE25D970EEEFD09865D89137388BD879C599191DE8ACE37DA657C142B6DF63143DBF9DED7659CBD5E45BAB699E2A3AFDD28C76A7CB2F300EBD9B74CDA59D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/St_Johns) {. {-9223372036854775808 -12652 0 LMT}. {-2713897748 -12652 0 NST}. {-1664130548 -9052 1 NDT}. {-1650137348 -12652 0 NST}. {-1640982548 -12652 0 NST}. {-1632076148 -9052 1 NDT}. {-1615145348 -12652 0 NST}. {-1609446548 -12652 0 NST}. {-1598650148 -9052 1 NDT}. {-1590100148 -12652 0 NST}. {-1567286948 -9052 1 NDT}. {-1551565748 -12652 0 NST}. {-1535837348 -9052 1 NDT}. {-1520116148 -12652 0 NST}. {-1503782948 -9052 1 NDT}. {-1488666548 -12652 0 NST}. {-1472333348 -9052 1 NDT}. {-1457216948 -12652 0 NST}. {-1440883748 -9052 1 NDT}. {-1425767348 -12652 0 NST}. {-1409434148 -9052 1 NDT}. {-1394317748 -12652 0 NST}. {-1377984548 -9052 1 NDT}. {-1362263348 -12652 0 NST}. {-1346534948 -9052 1 NDT}. {-1330813748 -12652 0 NST}. {-1314480548 -9052 1 NDT}. {-1299364148 -12652 0 NST}. {-1283030948 -9052 1 NDT}. {-1267914548 -12652 0 NS
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):203
                                                                                                                                                                                                                                  Entropy (8bit):4.878034750755565
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290tMp490e/:MBaIMY9QpI290g490O
                                                                                                                                                                                                                                  MD5:B149DC2A23F741BA943E5511E35370D3
                                                                                                                                                                                                                                  SHA1:3C8D3CFDB329B7ECB90C19D3EB3DE6F33A063ADD
                                                                                                                                                                                                                                  SHA-256:36046A74F6BB23EA8EABA25AD3B93241EBB509EF1821CC4BEC860489F5EC6DCA
                                                                                                                                                                                                                                  SHA-512:CEB38EC2405A3B0A4E09CDD2D69A11884CCB28DA0FD7CF8B344E1472642A0571674D3ED33C639E745DDEEE741E52B0948B86DFFFD324BB07A9F1A6B9F38F898E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/St_Kitts) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):203
                                                                                                                                                                                                                                  Entropy (8bit):4.89157166321909
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0uPXoFVAIg20uPXhF2IAcGEtkS+IAcGEuPX/:SlSWB9IZaM3y7eoFVAIgpeX290tY90e/
                                                                                                                                                                                                                                  MD5:7B7FCA150465F48FAC9F392C079B6376
                                                                                                                                                                                                                                  SHA1:1B501288CC00E8B90A2FAD82619B49A9DDBE4475
                                                                                                                                                                                                                                  SHA-256:87203A4BF42B549FEBF467CC51E8BCAE01BE1A44C193BED7E2D697B1C3D268C9
                                                                                                                                                                                                                                  SHA-512:5E4F7EE08493547A012144884586D45020D83B5838254C257FD341B8B6D3F9E279013D068EFC7D6DF7569DDD20122B3B23E9C93A0017FB64E941A50311ED1F18
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/St_Lucia) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):204
                                                                                                                                                                                                                                  Entropy (8bit):4.888871207225013
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290tXIMFJ490e/:MBaIMY9QpI290tJ490O
                                                                                                                                                                                                                                  MD5:7E272CE31D788C2556FF7421F6832314
                                                                                                                                                                                                                                  SHA1:A7D89A1A9AC2B61D98690126D1E4C1595E160C8F
                                                                                                                                                                                                                                  SHA-256:F0E10D45C929477A803085B2D4CE02EE31FD1DB24855836D02861AD246BC34D9
                                                                                                                                                                                                                                  SHA-512:CCDF0B1B5971B77F6FA27F25900DB1AB9A4A4C69E15DCDF4EA35E1E1FC31AAD957C2E5862B411B0155BB1E25E2DD417A89168295317B1E603DA59142D76CE80A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/St_Thomas) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):205
                                                                                                                                                                                                                                  Entropy (8bit):4.876306758637305
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290tzb+Q90e/:MBaIMY9QpI290xyQ90O
                                                                                                                                                                                                                                  MD5:52DAAF1636B5B70E0BA2015E9F322A74
                                                                                                                                                                                                                                  SHA1:4BD05207601CF6DB467C27052EBB25C9A64DAC96
                                                                                                                                                                                                                                  SHA-256:A5B3687BBA1D14D52599CB355BA5F4399632BF98DF4CEB258F9C479B1EA73586
                                                                                                                                                                                                                                  SHA-512:E3DE0447236F6EA24D173CCB46EA1A4A31B5FFBCE2A442CD542DA8C54DAD22391FD1CA301776C0FB07CBCF256FC708E61B7BBA682C02EEBE03BECCEA2B6D3BD0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/St_Vincent) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):845
                                                                                                                                                                                                                                  Entropy (8bit):4.182525430299964
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQce7eUFLxsOCX+FmFyyFDVFdPFxFZA8uFZYV:5NecLGO+6yZzXDZA8KZG
                                                                                                                                                                                                                                  MD5:1502A6DD85B55B9619E42D1E08C09738
                                                                                                                                                                                                                                  SHA1:70FF58E29CCDB53ABABA7EBD449A9B34AC152AA6
                                                                                                                                                                                                                                  SHA-256:54E541D1F410AFF34CE898BBB6C7CC945B66DFC9D7C4E986BD9514D14560CC6F
                                                                                                                                                                                                                                  SHA-512:99F0EFF9F2DA4CDD6AB508BB85002F38B01BDFDE0CBA1EB2F4B5CA8EAD8AAB645A3C26BECF777DE49574111B37F847EFF9320331AC07E84C8E892B688B01D36B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Swift_Current) {. {-9223372036854775808 -25880 0 LMT}. {-2030201320 -25200 0 MST}. {-1632063600 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-747241200 -21600 0 MDT}. {-732729600 -25200 0 MST}. {-715791600 -21600 1 MDT}. {-702489600 -25200 0 MST}. {-684342000 -21600 1 MDT}. {-671040000 -25200 0 MST}. {-652892400 -21600 1 MDT}. {-639590400 -25200 0 MST}. {-631126800 -25200 0 MST}. {-400086000 -21600 1 MDT}. {-384364800 -25200 0 MST}. {-337186800 -21600 1 MDT}. {-321465600 -25200 0 MST}. {-305737200 -21600 1 MDT}. {-292435200 -25200 0 MST}. {-273682800 -21600 1 MDT}. {-260985600 -25200 0 MST}. {73472400 -21600 0 CST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):329
                                                                                                                                                                                                                                  Entropy (8bit):4.580220354026118
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5290Em2OHskeRbV1UcgdrV/uFn/acD3/uFn/sb9/uFn/yn:MBp5290EmdHsVH1UDB/uFn/z/uFn/k/N
                                                                                                                                                                                                                                  MD5:004588073FADF67C3167FF007759BCEA
                                                                                                                                                                                                                                  SHA1:64A6344776A95E357071D4FC65F71673382DAF9D
                                                                                                                                                                                                                                  SHA-256:55C18EA96D3BA8FD9E8C4F01D4713EC133ACCD2C917EC02FD5E74A4E0089BFBF
                                                                                                                                                                                                                                  SHA-512:ADC834C393C5A3A7BFD86A933E7C7F594AC970A3BD1E38110467A278DC4266D81C3E96394C102E565F05DE7FBBDA623C673597E19BEC1EA26AB12E4354991066
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Tegucigalpa) {. {-9223372036854775808 -20932 0 LMT}. {-1538503868 -21600 0 CST}. {547020000 -18000 1 CDT}. {559717200 -21600 0 CST}. {578469600 -18000 1 CDT}. {591166800 -21600 0 CST}. {1146981600 -18000 1 CDT}. {1154926800 -21600 0 CST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6666
                                                                                                                                                                                                                                  Entropy (8bit):3.7481713130223295
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:pJunToVmM7IEc2fVGYu2yeB/T/eleWmBk81kS/kV6kef4zjyvUP/ZbJitpJxSIRj:pAWJv
                                                                                                                                                                                                                                  MD5:8FFE81344C31A51489A254DE97E83C3E
                                                                                                                                                                                                                                  SHA1:4397D9EDAC304668D95921EF03DFD90F967E772F
                                                                                                                                                                                                                                  SHA-256:EF6AF4A3FA500618B37AF3CDD40C475E54347D7510274051006312A42C79F20C
                                                                                                                                                                                                                                  SHA-512:F34A6D44499DE5A4E328A8EAFBA5E77B1B8C04A843160D74978398F1545C821C3034FCBD5ADBFAD8D14D1688907C57E7570023ABD3096D4E4C19E3D3C04428B3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Thule) {. {-9223372036854775808 -16508 0 LMT}. {-1686079492 -14400 0 AST}. {670399200 -10800 1 ADT}. {686120400 -14400 0 AST}. {701848800 -10800 1 ADT}. {717570000 -14400 0 AST}. {733903200 -10800 1 ADT}. {752043600 -14400 0 AST}. {765352800 -10800 1 ADT}. {783493200 -14400 0 AST}. {796802400 -10800 1 ADT}. {814942800 -14400 0 AST}. {828856800 -10800 1 ADT}. {846392400 -14400 0 AST}. {860306400 -10800 1 ADT}. {877842000 -14400 0 AST}. {891756000 -10800 1 ADT}. {909291600 -14400 0 AST}. {923205600 -10800 1 ADT}. {941346000 -14400 0 AST}. {954655200 -10800 1 ADT}. {972795600 -14400 0 AST}. {986104800 -10800 1 ADT}. {1004245200 -14400 0 AST}. {1018159200 -10800 1 ADT}. {1035694800 -14400 0 AST}. {1049608800 -10800 1 ADT}. {1067144400 -14400 0 AST}. {1081058400 -10800 1 ADT}. {1099198800 -14400 0 AST}. {1112508000 -10800 1 ADT}. {1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8058
                                                                                                                                                                                                                                  Entropy (8bit):3.7473289441354263
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:hePraC3Xm8sHRwvOTFhP5S+ijFnRaJeaX1eyDt:hirrn+qvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:CE6E17F16AA8BAD3D9DB8BD2E61A6406
                                                                                                                                                                                                                                  SHA1:7DF466E7BB5EDD8E1CDF0ADC8740248EF31ECB15
                                                                                                                                                                                                                                  SHA-256:E29F83A875E2E59EC99A836EC9203D5ABC2355D6BD4683A5AEAF31074928D572
                                                                                                                                                                                                                                  SHA-512:833300D17B7767DE74E6F2757513058FF5B25A9E7A04AB97BBBFFAC5D9ADCC43366A5737308894266A056382D2589D0778EEDD85D56B0F336C84054AB05F1079
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Thunder_Bay) {. {-9223372036854775808 -21420 0 LMT}. {-2366733780 -21600 0 CST}. {-1893434400 -18000 0 EST}. {-883594800 -18000 0 EST}. {-880218000 -14400 1 EWT}. {-769395600 -14400 1 EPT}. {-765396000 -18000 0 EST}. {18000 -18000 0 EST}. {9961200 -14400 1 EDT}. {25682400 -18000 0 EST}. {41410800 -14400 1 EDT}. {57736800 -18000 0 EST}. {73465200 -14400 1 EDT}. {89186400 -18000 0 EST}. {94712400 -18000 0 EST}. {126248400 -18000 0 EST}. {136364400 -14400 1 EDT}. {152085600 -18000 0 EST}. {167814000 -14400 1 EDT}. {183535200 -18000 0 EST}. {199263600 -14400 1 EDT}. {215589600 -18000 0 EST}. {230713200 -14400 1 EDT}. {247039200 -18000 0 EST}. {262767600 -14400 1 EDT}. {278488800 -18000 0 EST}. {294217200 -14400 1 EDT}. {309938400 -18000 0 EST}. {325666800 -14400 1 EDT}. {341388000 -18000 0 EST}. {357116400 -14400 1 EDT}. {372837600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8470
                                                                                                                                                                                                                                  Entropy (8bit):3.767364707906483
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:mb4O5mC2ZCAFBWsBNwj/lpmlOxGcKcnRH31t+ucgge:Q5DaYaNwj/lpmlOxnKcndIG
                                                                                                                                                                                                                                  MD5:F76D5FB5BC773872B556A6EDF660E5CC
                                                                                                                                                                                                                                  SHA1:3FD19FCD0FFD3308D2E7D9A3553C14B6A6C3A903
                                                                                                                                                                                                                                  SHA-256:170540AA3C0962AFE4267F83AC679241B2D135B1C18E8E7220C2608B94DDDE0E
                                                                                                                                                                                                                                  SHA-512:7FC5D2BC39EF3A3C902A56272474E28CD9C56DE37A7AE9FAEADE974993677CCF3A9E6CE64C064D69B7587BD47951BFFFD751412D97F4066656CBB42AD9B619DF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Tijuana) {. {-9223372036854775808 -28084 0 LMT}. {-1514736000 -25200 0 MST}. {-1451667600 -28800 0 PST}. {-1343062800 -25200 0 MST}. {-1234803600 -28800 0 PST}. {-1222963200 -25200 1 PDT}. {-1207242000 -28800 0 PST}. {-873820800 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-761677200 -28800 0 PST}. {-686073600 -25200 1 PDT}. {-661539600 -28800 0 PST}. {-504892800 -28800 0 PST}. {-495039600 -25200 1 PDT}. {-481734000 -28800 0 PST}. {-463590000 -25200 1 PDT}. {-450284400 -28800 0 PST}. {-431535600 -25200 1 PDT}. {-418230000 -28800 0 PST}. {-400086000 -25200 1 PDT}. {-386780400 -28800 0 PST}. {-368636400 -25200 1 PDT}. {-355330800 -28800 0 PST}. {-337186800 -25200 1 PDT}. {-323881200 -28800 0 PST}. {-305737200 -25200 1 PDT}. {-292431600 -28800 0 PST}. {-283968000 -28800 0 PST}. {189331200 -28800 0 PST}. {199274400 -25200 1 PDT}. {21560
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10883
                                                                                                                                                                                                                                  Entropy (8bit):3.7202964099536917
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:9wUYG1dbgZ8UMrEUWraC3Xm8sHRwvOTFhP5S+ijFnRaJeaX1eyDt:9wS1dbgZ8UMrVWrrn+qvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:9C60AFDFA3BA2002BA68673B778194CF
                                                                                                                                                                                                                                  SHA1:D6D17C82AEC4B85BA7B0F6FCB36A7582CA26A82B
                                                                                                                                                                                                                                  SHA-256:7744DB6EFE39D636F1C88F8325ED3EB6BF8FA615F52A60333A58BCE579983E87
                                                                                                                                                                                                                                  SHA-512:3C793BB00725CF37474683EAB70A0F2B2ACAE1656402CDD7E75182988DC20361A8651A624A5220983E3E05333B9817DCBEAF20D34BD55C5128F55474A02A9455
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Toronto) {. {-9223372036854775808 -19052 0 LMT}. {-2366736148 -18000 0 EST}. {-1632070800 -14400 1 EDT}. {-1615140000 -18000 0 EST}. {-1609441200 -18000 0 EST}. {-1601753400 -14400 1 EDT}. {-1583697600 -18000 0 EST}. {-1567357200 -14400 1 EDT}. {-1554667200 -18000 0 EST}. {-1534698000 -14400 1 EDT}. {-1524074400 -18000 0 EST}. {-1503248400 -14400 1 EDT}. {-1492365600 -18000 0 EST}. {-1471798800 -14400 1 EDT}. {-1460916000 -18000 0 EST}. {-1440954000 -14400 1 EDT}. {-1428861600 -18000 0 EST}. {-1409504400 -14400 1 EDT}. {-1397412000 -18000 0 EST}. {-1378054800 -14400 1 EDT}. {-1365962400 -18000 0 EST}. {-1346605200 -14400 1 EDT}. {-1333908000 -18000 0 EST}. {-1315155600 -14400 1 EDT}. {-1301853600 -18000 0 EST}. {-1283706000 -14400 1 EDT}. {-1270404000 -18000 0 EST}. {-1252256400 -14400 1 EDT}. {-1238954400 -18000 0 EST}. {-1220806800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):202
                                                                                                                                                                                                                                  Entropy (8bit):4.854311472609309
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290RRKl290e/:MBaIMY9QpI290V90O
                                                                                                                                                                                                                                  MD5:B931564D937C807282F1432FF6EA52A6
                                                                                                                                                                                                                                  SHA1:7ECA025D97717EEA7C91B5390122D3A47A25CAD0
                                                                                                                                                                                                                                  SHA-256:FF5CF153C4EC65E7E57A608A481F12939B6E4ACC8D62C5B01FEB5A04769A6F07
                                                                                                                                                                                                                                  SHA-512:97271500C7D7959B90A6AC0A98D5D0D29DA00E92F9FC973594267DF906DEE767243698DBA2F3A0CF00156E949E29CDDD45A151F263583514090717CFDF1FB4DD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Tortola) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9495
                                                                                                                                                                                                                                  Entropy (8bit):3.7630000632404426
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:2f7f/5LB6xi9C7Nf+aNwj/lpmlOxnKcndIG:2f735LB6xi9cfefnK6
                                                                                                                                                                                                                                  MD5:1ACC41DA124C0CA5E67432760FDC91EC
                                                                                                                                                                                                                                  SHA1:13F56C3F53076E0027BB8C5814EC81256A37F4AF
                                                                                                                                                                                                                                  SHA-256:DFC19B5231F6A0AB9E9B971574FB612695A425A3B290699DF2819D46F1250DB0
                                                                                                                                                                                                                                  SHA-512:2F2E358F5743248DE946B90877EFCCCACAF039956249F17D24B7DA026830A181A125045E2C8937A6ACD674E32887049F2D36A1941F09803DF514ADCDA4055CC5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Vancouver) {. {-9223372036854775808 -29548 0 LMT}. {-2713880852 -28800 0 PST}. {-1632060000 -25200 1 PDT}. {-1615129200 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-747237600 -25200 1 PDT}. {-732726000 -28800 0 PST}. {-715788000 -25200 1 PDT}. {-702486000 -28800 0 PST}. {-684338400 -25200 1 PDT}. {-671036400 -28800 0 PST}. {-652888800 -25200 1 PDT}. {-639586800 -28800 0 PST}. {-620834400 -25200 1 PDT}. {-608137200 -28800 0 PST}. {-589384800 -25200 1 PDT}. {-576082800 -28800 0 PST}. {-557935200 -25200 1 PDT}. {-544633200 -28800 0 PST}. {-526485600 -25200 1 PDT}. {-513183600 -28800 0 PST}. {-495036000 -25200 1 PDT}. {-481734000 -28800 0 PST}. {-463586400 -25200 1 PDT}. {-450284400 -28800 0 PST}. {-431532000 -25200 1 PDT}. {-418230000 -28800 0 PST}. {-400082400 -25200 1 PDT}. {-386
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):201
                                                                                                                                                                                                                                  Entropy (8bit):4.901732290886438
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7eoFVAIgpeX290RXgr490e/:MBaIMY9QpI290xg090O
                                                                                                                                                                                                                                  MD5:DEB77B4016D310DFB38E6587190886FB
                                                                                                                                                                                                                                  SHA1:B308A2D187C153D3ED821B205A4F2D0F73DA94B0
                                                                                                                                                                                                                                  SHA-256:A6B8CFE8B9381EC61EAB553CFA2A815F93BBB224A6C79D74C08AC54BE4B8413B
                                                                                                                                                                                                                                  SHA-512:04A0D598A24C0F3A1881D3412352F65C610F75281CC512B46248847A798A12AEA551E3DE9EA3FD5BB6B3687A0BB65746392F301F72746876D30697D66B3A3604
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Port_of_Spain)]} {. LoadTimeZoneFile America/Port_of_Spain.}.set TZData(:America/Virgin) $TZData(:America/Port_of_Spain).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7613
                                                                                                                                                                                                                                  Entropy (8bit):3.789738507183991
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:hmD+C2ZCHtffWsBNwj/lpmlOxGcKcnRH31t+ucgge:hm3Nf+aNwj/lpmlOxnKcndIG
                                                                                                                                                                                                                                  MD5:CBCFD98E08FCCEB580F66AFE8E670AF5
                                                                                                                                                                                                                                  SHA1:7E922CCD99CD7758709205E4C9210A2F09F09800
                                                                                                                                                                                                                                  SHA-256:72992080AA9911184746633C7D6E47570255EE85CC6FE5E843F62331025B2A61
                                                                                                                                                                                                                                  SHA-512:18290654E5330186B739DEDBC7D6860FD017D089DAE19E480F868E1FB56A3CF2E685D0099C4CF1D4F2AE5F36D0B72ABE52FBAC29AD4F6AB8A45C4C420D90E2D5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Whitehorse) {. {-9223372036854775808 -32412 0 LMT}. {-2188997988 -32400 0 YST}. {-1632056400 -28800 1 YDT}. {-1615125600 -32400 0 YST}. {-1596978000 -28800 1 YDT}. {-1583164800 -32400 0 YST}. {-880203600 -28800 1 YWT}. {-769395600 -28800 1 YPT}. {-765381600 -32400 0 YST}. {-147884400 -25200 1 YDDT}. {-131554800 -32400 0 YST}. {315561600 -28800 0 PST}. {325677600 -25200 1 PDT}. {341398800 -28800 0 PST}. {357127200 -25200 1 PDT}. {372848400 -28800 0 PST}. {388576800 -25200 1 PDT}. {404902800 -28800 0 PST}. {420026400 -25200 1 PDT}. {436352400 -28800 0 PST}. {452080800 -25200 1 PDT}. {467802000 -28800 0 PST}. {483530400 -25200 1 PDT}. {499251600 -28800 0 PST}. {514980000 -25200 1 PDT}. {530701200 -28800 0 PST}. {544615200 -25200 1 PDT}. {562150800 -28800 0 PST}. {576064800 -25200 1 PDT}. {594205200 -28800 0 PST}. {607514400 -25200 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9379
                                                                                                                                                                                                                                  Entropy (8bit):3.7354364023000937
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:t7K22m2eQ7SRWu3O559BxXWDpws1dwVyUAitGeZiSI0PMnp4ozDCM9LfLPix3QWZ:t7K22m2eQ7Swu3O559BxXWDpws1dwVyU
                                                                                                                                                                                                                                  MD5:F6B8A2DA74DC3429EC1FAF7A38CB0361
                                                                                                                                                                                                                                  SHA1:1651AD179DB98C9755CDF17FBFC29EF35DE7F588
                                                                                                                                                                                                                                  SHA-256:FEAA62063316C8F4AD5FABBF5F2A7DD21812B6658FEC40893657E909DE605317
                                                                                                                                                                                                                                  SHA-512:46C61EFF429075A77C01AF1C02FD6136529237B30B7F06795BCEE26CDB75DDAB2D418283CD95C9A0140D1510E02F393F0A7E9414C99D1B31301AE213BAF50681
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Winnipeg) {. {-9223372036854775808 -23316 0 LMT}. {-2602258284 -21600 0 CST}. {-1694368800 -18000 1 CDT}. {-1681671600 -21600 0 CST}. {-1632067200 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1029686400 -18000 1 CDT}. {-1018198800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-746035200 -18000 1 CDT}. {-732733200 -21600 0 CST}. {-715795200 -18000 1 CDT}. {-702493200 -21600 0 CST}. {-684345600 -18000 1 CDT}. {-671043600 -21600 0 CST}. {-652896000 -18000 1 CDT}. {-639594000 -21600 0 CST}. {-620755200 -18000 1 CDT}. {-607626000 -21600 0 CST}. {-589392000 -18000 1 CDT}. {-576090000 -21600 0 CST}. {-557942400 -18000 1 CDT}. {-544640400 -21600 0 CST}. {-526492800 -18000 1 CDT}. {-513190800 -21600 0 CST}. {-495043200 -18000 1 CDT}. {-481741200 -21600 0 CST}. {-463593600 -18000 1 CDT}. {-
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8407
                                                                                                                                                                                                                                  Entropy (8bit):3.8776961667057868
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:ugOZVKyjVYus/Q7Ddh5sBPyNsSLFOMM/EowALVZVmWa86Eac8rQ:uBZVKH/4h5sBPy+CMt/ElALLVuAH
                                                                                                                                                                                                                                  MD5:9C0E781669E3E5549F82ED378EE3423B
                                                                                                                                                                                                                                  SHA1:32184EA198156731C58616A0D88F169441C8CC7F
                                                                                                                                                                                                                                  SHA-256:FE1C632FE9AF7E54A8CC9ED839818FAE98F14928921FD78C92A8D8E22F07A415
                                                                                                                                                                                                                                  SHA-512:D1CDAB3DBAFFB4C30F6EEBDD413D748980C156437FBE99E7DF0C1E17AFA4CC33876AF2BB44C90E1FE5347071E64E83823EED47AE9BE39863C12989CB3EA44BDA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Yakutat) {. {-9223372036854775808 52865 0 LMT}. {-3225223727 -33535 0 LMT}. {-2188953665 -32400 0 YST}. {-883580400 -32400 0 YST}. {-880203600 -28800 1 YWT}. {-769395600 -28800 1 YPT}. {-765381600 -32400 0 YST}. {-757350000 -32400 0 YST}. {-31503600 -32400 0 YST}. {-21474000 -28800 1 YDT}. {-5752800 -32400 0 YST}. {9975600 -28800 1 YDT}. {25696800 -32400 0 YST}. {41425200 -28800 1 YDT}. {57751200 -32400 0 YST}. {73479600 -28800 1 YDT}. {89200800 -32400 0 YST}. {104929200 -28800 1 YDT}. {120650400 -32400 0 YST}. {126702000 -28800 1 YDT}. {152100000 -32400 0 YST}. {162385200 -28800 1 YDT}. {183549600 -32400 0 YST}. {199278000 -28800 1 YDT}. {215604000 -32400 0 YST}. {230727600 -28800 1 YDT}. {247053600 -32400 0 YST}. {262782000 -28800 1 YDT}. {278503200 -32400 0 YST}. {294231600 -28800 1 YDT}. {309952800 -32400 0 YST}. {325681200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7485
                                                                                                                                                                                                                                  Entropy (8bit):3.781666511020802
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:rGzGm+4I1zXN+C2mWBNQMsmNTxf6AeO+cblX:zVUC2mWBNwWTxyWR
                                                                                                                                                                                                                                  MD5:C9050AC32086644B15631E6FBE4D6292
                                                                                                                                                                                                                                  SHA1:8C074D0E04CAFB1BDD11953AE77687CFBC53C449
                                                                                                                                                                                                                                  SHA-256:447B801066A92624F58C00DA66FBB90B54195F4AB06886AE4796228244E19E85
                                                                                                                                                                                                                                  SHA-512:E7C73E67B247F912E774EF245D2323B24DDF75054C7BE9095BC19E3C58CB5AE287747076B2436ABF735738A969DAFCDB128F0BA2C76A0AFAB5449CF157BEB190
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:America/Yellowknife) {. {-9223372036854775808 0 0 -00}. {-1104537600 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-147891600 -18000 1 MDDT}. {-131562000 -25200 0 MST}. {315558000 -25200 0 MST}. {325674000 -21600 1 MDT}. {341395200 -25200 0 MST}. {357123600 -21600 1 MDT}. {372844800 -25200 0 MST}. {388573200 -21600 1 MDT}. {404899200 -25200 0 MST}. {420022800 -21600 1 MDT}. {436348800 -25200 0 MST}. {452077200 -21600 1 MDT}. {467798400 -25200 0 MST}. {483526800 -21600 1 MDT}. {499248000 -25200 0 MST}. {514976400 -21600 1 MDT}. {530697600 -25200 0 MST}. {544611600 -21600 1 MDT}. {562147200 -25200 0 MST}. {576061200 -21600 1 MDT}. {594201600 -25200 0 MST}. {607510800 -21600 1 MDT}. {625651200 -25200 0 MST}. {638960400 -21600 1 MDT}. {657100800 -25200 0 MST}. {671014800 -21600 1 MDT}. {68
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):316
                                                                                                                                                                                                                                  Entropy (8bit):4.338100448107153
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52L09xvFJm2OHlFFbQMFUkjtjKNUkMQTVsklkQEJ:MBp52Lc9mdHfFbQMF5jdK3zTVxE
                                                                                                                                                                                                                                  MD5:4AD8AC155D466E47A6BF075508DC05ED
                                                                                                                                                                                                                                  SHA1:2C911F651B26C27C07756111B5291C63C6954D34
                                                                                                                                                                                                                                  SHA-256:282A352404B30C4336C0E09F3C5371393511C602B9E55648FB0251EACC9C715D
                                                                                                                                                                                                                                  SHA-512:4A7305653D700FF565C9747C8A4E69A79609EB4748F3FFAA60C5A8548BBFAEC541EB8EAF830FF9202508BEAFAC2A0895BC4A52473FA51EBC74FAD83FCD0EB8F5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Casey) {. {-9223372036854775808 0 0 -00}. {-31536000 28800 0 +08}. {1255802400 39600 0 +11}. {1267714800 28800 0 +08}. {1319738400 39600 0 +11}. {1329843600 28800 0 +08}. {1477065600 39600 0 +11}. {1520701200 28800 0 +08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):312
                                                                                                                                                                                                                                  Entropy (8bit):4.290371654524798
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52L0DTm2OHlFFpwz0/MVSYv/JFFv7VoX/MVSYv/bpVQSbRXhNXSMVSYvx:MBp52LeTmdHfFCjF/LFvOkF/bp6SbRRT
                                                                                                                                                                                                                                  MD5:780DA74192C8F569B1450AACE54A0558
                                                                                                                                                                                                                                  SHA1:F2650D6D21A4B4AC8D931383ED343CE916252319
                                                                                                                                                                                                                                  SHA-256:88A4DBB222E9FD2FFC26D9B5A8657FA6552DF6B3B6A14D951CE1168B5646E8F8
                                                                                                                                                                                                                                  SHA-512:7F1E9E5C0F8E2A9D8AC68E19AF3D48D2BEE9840812A219A759475E7D036EA18CB122C40DDB88977079C1831AEF7EFBCB519C691616631D490B3C04382EB993C0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Davis) {. {-9223372036854775808 0 0 -00}. {-409190400 25200 0 +07}. {-163062000 0 0 -00}. {-28857600 25200 0 +07}. {1255806000 18000 0 +05}. {1268251200 25200 0 +07}. {1319742000 18000 0 +05}. {1329854400 25200 0 +07}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):206
                                                                                                                                                                                                                                  Entropy (8bit):4.716730745171491
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52L0/3Om2OHlFFbRX82+c6FFpJ6SpQ:MBp52LdmdHfFbx82+ZFDQ
                                                                                                                                                                                                                                  MD5:83B53540FADB1A36903E2A619954BFFC
                                                                                                                                                                                                                                  SHA1:C9F520043A641104F43FB5422971B4D7A39A421C
                                                                                                                                                                                                                                  SHA-256:0E50BA70DE94E6BABC4847C15865867D0F821F6BDDDC0B9750CB6BF13EF5DF3B
                                                                                                                                                                                                                                  SHA-512:0AE7FE58EED7EAC03CBFFA2EA32CCBF726DBED0A3B1C20CF1D549CDA801CEB2B54F106787BD15B17DA3D9404E2D84936D50E4A2F63D1A72B0FEBCD8F8EA3195F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/DumontDUrville) {. {-9223372036854775808 0 0 -00}. {-725846400 36000 0 +10}. {-566992800 0 0 -00}. {-415497600 36000 0 +10}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2800
                                                                                                                                                                                                                                  Entropy (8bit):3.8632793034261463
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQbTetvk4z/7hLiVVitCinq+D18KmvLx0WWuyymPXObf78FCt7WQi2NjM:5sTlKiG+h5mjKIyym+WQNo
                                                                                                                                                                                                                                  MD5:A3E1A9DFB6D6F061E60739865E6E0D18
                                                                                                                                                                                                                                  SHA1:10C014CB444DEEF093854EE6A415DC17D7C2A4C5
                                                                                                                                                                                                                                  SHA-256:975026D38C4BF136769D31215F2908867EC37E568380F864983DD57FFADA4676
                                                                                                                                                                                                                                  SHA-512:9425CF1B717FBDFD4EA04AAC06CF5ACE365A4FCC911D85130B910D022ED4261F1FFF431CE63BA538871C7D3CA1EF65490A30BEE975884EB39FC1E5C2D88009D0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Macquarie) {. {-9223372036854775808 0 0 -00}. {-2214259200 36000 0 AEST}. {-1680508800 39600 1 AEDT}. {-1669892400 39600 0 AEDT}. {-1665392400 36000 0 AEST}. {-1601719200 0 0 -00}. {-94730400 36000 0 AEST}. {-71136000 39600 1 AEDT}. {-55411200 36000 0 AEST}. {-37267200 39600 1 AEDT}. {-25776000 36000 0 AEST}. {-5817600 39600 1 AEDT}. {5673600 36000 0 AEST}. {25632000 39600 1 AEDT}. {37728000 36000 0 AEST}. {57686400 39600 1 AEDT}. {67968000 36000 0 AEST}. {89136000 39600 1 AEDT}. {100022400 36000 0 AEST}. {120585600 39600 1 AEDT}. {131472000 36000 0 AEST}. {152035200 39600 1 AEDT}. {162921600 36000 0 AEST}. {183484800 39600 1 AEDT}. {194976000 36000 0 AEST}. {215539200 39600 1 AEDT}. {226425600 36000 0 AEST}. {246988800 39600 1 AEDT}. {257875200 36000 0 AEST}. {278438400 39600 1 AEDT}. {289324800 36000 0 AEST}. {309888000 39
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.6965808819415695
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52L0GRHEzyedFkXGm2OHvdFFoVU/VPKVVFSTGFFFjsvUX0VQL:SlSWB9X52L0zyEm2OHlFFzy/UiF/js/G
                                                                                                                                                                                                                                  MD5:A07C6FA0B635EC81C5199F2515888C9E
                                                                                                                                                                                                                                  SHA1:587AC900E285F6298A7287F10466DFA4683B9A87
                                                                                                                                                                                                                                  SHA-256:2D8F0218800F6E0BD645A7270BEAF60A517AE20CBFFD64CF77E3CE4F8F959348
                                                                                                                                                                                                                                  SHA-512:76A3590748F698E51BF29A1D3C119A253A8C07E9F77835CCDFC6AC51C554B5888351C95E6012CDADB106B42A384D49E56537FBF8DB9DC5BB791CB115FDB623FD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Mawson) {. {-9223372036854775808 0 0 -00}. {-501206400 21600 0 +06}. {1255809600 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                  Entropy (8bit):4.832254042797831
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG/u4pVAIgObT/NCxL2L0GRHEz6BVfnUDH/uvn:SlSWB9IZaM3ycqIVAIgOboL2L0z6/fvn
                                                                                                                                                                                                                                  MD5:0048A7427AC7880B9F6413208B216BC9
                                                                                                                                                                                                                                  SHA1:CBB4A29316581CFC7868A779E97DB94F75870F41
                                                                                                                                                                                                                                  SHA-256:487D4845885643700B4FF043AC5EA59E2355FD38357809BE12679ECAFFA93030
                                                                                                                                                                                                                                  SHA-512:EC107FA59203B7BCB58253E2715380EF70DF5470030B83E1DEA8D1AC4E7D3FB2908E8C7009D8136212871EC3DA8B4C4194FF3290E5A41EEE8E7D07CABE80ECC0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Auckland)]} {. LoadTimeZoneFile Pacific/Auckland.}.set TZData(:Antarctica/McMurdo) $TZData(:Pacific/Auckland).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2526
                                                                                                                                                                                                                                  Entropy (8bit):3.514598338545733
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5wcS+SGwRShoSdXvuMSuSYSgS1SWFlSqSySSSoyZSWXSHS9SWS3SbSRSBSUS5ShG:tNURMo8XvuMRnHqhTxxJAHXEa9c0yq/4
                                                                                                                                                                                                                                  MD5:7738686109BCC8AF5271608FCD04EBFB
                                                                                                                                                                                                                                  SHA1:401217F0F69945ADA13F593681D8F13A368BCF94
                                                                                                                                                                                                                                  SHA-256:3EECDA7E4507A321A03171658187D2F50F7C6C46E8A1B0831E6B6B6AAFFAC4AC
                                                                                                                                                                                                                                  SHA-512:F7982BF9D82B2D7C2C1825AF1FF9178849BB699A50367872C11572E6F8A452619A63C9F97CEAF06FD5104075FBDE70936B8363B993F2571FD9A2B699A1D17521
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Palmer) {. {-9223372036854775808 0 0 -00}. {-157766400 -14400 0 -04}. {-152654400 -14400 0 -04}. {-132955200 -10800 1 -04}. {-121122000 -14400 0 -04}. {-101419200 -10800 1 -04}. {-86821200 -14400 0 -04}. {-71092800 -10800 1 -04}. {-54766800 -14400 0 -04}. {-39038400 -10800 1 -04}. {-23317200 -14400 0 -04}. {-7588800 -10800 0 -03}. {128142000 -7200 1 -03}. {136605600 -10800 0 -03}. {389070000 -14400 0 -04}. {403070400 -10800 1 -04}. {416372400 -14400 0 -04}. {434520000 -10800 1 -04}. {447822000 -14400 0 -04}. {466574400 -10800 1 -04}. {479271600 -14400 0 -04}. {498024000 -10800 1 -04}. {510721200 -14400 0 -04}. {529473600 -10800 1 -04}. {545194800 -14400 0 -04}. {560923200 -10800 1 -04}. {574225200 -14400 0 -04}. {592372800 -10800 1 -04}. {605674800 -14400 0 -04}. {624427200 -10800 1 -04}. {637124400 -14400 0 -04}. {653457600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):145
                                                                                                                                                                                                                                  Entropy (8bit):4.778784990010973
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52L0GRHEsKRaXGm2OHvdFFn/H3VVFVGHC:SlSWB9X52L0rRhm2OHlFFn/VVFAHC
                                                                                                                                                                                                                                  MD5:8CAED0DB4C911E84AF29910478D0DBD6
                                                                                                                                                                                                                                  SHA1:80DE97C9959D58C6BF782A948EED735AB4C423CC
                                                                                                                                                                                                                                  SHA-256:9415FA3A573B98A6EBCBFAEEC15B1C52352F2574161648BB977F55072414002F
                                                                                                                                                                                                                                  SHA-512:28F27F7EDDF30EB08F8B37ED13219501D14D2AEA4EFA07AFAD36A643BD448E1BD992463C12C47152C99772D755E6EA0198B51B806A05B57743635A9059676EC2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Rothera) {. {-9223372036854775808 0 0 -00}. {218246400 -10800 0 -03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):193
                                                                                                                                                                                                                                  Entropy (8bit):4.858829912809126
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3ycqIVAIgOboL2L0tlo+plvn:MBaIMdQiO2LMq+p1
                                                                                                                                                                                                                                  MD5:51AC23110E7EAB20319EE8EC82F048D2
                                                                                                                                                                                                                                  SHA1:7B4DE168A3078041841762F468AE65A2EE6C5322
                                                                                                                                                                                                                                  SHA-256:D33E094979B3CE495BEF7109D78F7B77D470AB848E4E2951851A7C57140354BF
                                                                                                                                                                                                                                  SHA-512:13E800DFFA3D65F94FAD6B529FC8A29A26F40F4F29DBF19283392733458AD3C6B27E479218A8C123424E965711B4746976E39EB9FD54CD0B57281134FEAC4F31
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Auckland)]} {. LoadTimeZoneFile Pacific/Auckland.}.set TZData(:Antarctica/South_Pole) $TZData(:Pacific/Auckland).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):143
                                                                                                                                                                                                                                  Entropy (8bit):4.7487926695696006
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52L0GRHEtWlFeEXGm2OHvdFFpoMdsWYAvn:SlSWB9X52L0tQeLm2OHlFFpbaWYAv
                                                                                                                                                                                                                                  MD5:AA415901BB9E53CF7FAEA47E546D9AED
                                                                                                                                                                                                                                  SHA1:CF12572D2C4D0ABF12B0450D366944E297744217
                                                                                                                                                                                                                                  SHA-256:F161CFAB3E40A0358FF0DEC2EB8ED9231D357FAC20710668B9CE31CDA68E8B96
                                                                                                                                                                                                                                  SHA-512:4F90E0EA7086EB729080E77A47C2E998F7AD3BCEA4997DAB06044BCDD2E2E1729A83C679EF2E1D78CD0255C37F24FCC6746518444CC4E96EBB2A0547312D8354
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Syowa) {. {-9223372036854775808 0 0 -00}. {-407808000 10800 0 +03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5174
                                                                                                                                                                                                                                  Entropy (8bit):3.411985404081831
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:q4NUwVb0uJjeH7wZjFH7EPzOLrNrnw/ZklmhEJkJdG:jNUwVAuJjs8JmPzO5ngzG
                                                                                                                                                                                                                                  MD5:CA4730C864AB3CC903F79BDF0F9E8777
                                                                                                                                                                                                                                  SHA1:7B3E9DDB36766F95F9C651CF244EDA9ED22BDDC5
                                                                                                                                                                                                                                  SHA-256:E437539A85E91AD95CD100F9628142FEBB455553C95415DB1147FD25948EBF59
                                                                                                                                                                                                                                  SHA-512:32EE0CCA0AB92D68D6C21A925E5367730A172C49DC5245A61DA1A39E08317569154C52EC695E3FB43BB40D066C4C0E9625C835A7F6E2EB5DDF0768D48DB99F3C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Troll) {. {-9223372036854775808 0 0 -00}. {1108166400 0 0 +00}. {1111885200 7200 1 +02}. {1130634000 0 0 +00}. {1143334800 7200 1 +02}. {1162083600 0 0 +00}. {1174784400 7200 1 +02}. {1193533200 0 0 +00}. {1206838800 7200 1 +02}. {1224982800 0 0 +00}. {1238288400 7200 1 +02}. {1256432400 0 0 +00}. {1269738000 7200 1 +02}. {1288486800 0 0 +00}. {1301187600 7200 1 +02}. {1319936400 0 0 +00}. {1332637200 7200 1 +02}. {1351386000 0 0 +00}. {1364691600 7200 1 +02}. {1382835600 0 0 +00}. {1396141200 7200 1 +02}. {1414285200 0 0 +00}. {1427590800 7200 1 +02}. {1445734800 0 0 +00}. {1459040400 7200 1 +02}. {1477789200 0 0 +00}. {1490490000 7200 1 +02}. {1509238800 0 0 +00}. {1521939600 7200 1 +02}. {1540688400 0 0 +00}. {1553994000 7200 1 +02}. {1572138000 0 0 +00}. {1585443600 7200 1 +02}. {1603587600 0 0 +00}. {1616893200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):144
                                                                                                                                                                                                                                  Entropy (8bit):4.773942010845718
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52L0GRHEoKcMFtXGm2OHvdFFud/bVFXKVVFSTL:SlSWB9X52L0XcMFEm2OHlFFCVFXK/Un
                                                                                                                                                                                                                                  MD5:A07C4769267AFA9501BE44BD406ADA34
                                                                                                                                                                                                                                  SHA1:86747047EFD1F47FEFC7DA44465EAB53F808C9FB
                                                                                                                                                                                                                                  SHA-256:92816E1C4FDE037D982596610A1F6E11D4E7FD408C3B1FAAB7BEC32B09911FE7
                                                                                                                                                                                                                                  SHA-512:051A327C898867228C8B1848162C2604BED8456B61533D4A40FBEB9A0069AE2EAF33F79803A0C6A80C6446C34F757A751F4ABC5AC5CCED6C125E2A42D46A022A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Antarctica/Vostok) {. {-9223372036854775808 0 0 -00}. {-380073600 21600 0 +06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.922114908130109
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVyWJooedVAIgoqxWJ0YF2XbeLo4cA4FH/h8QasWJ/n:SlSWB9IZaM3ymSDdVAIgo2Q2XbUyAK8H
                                                                                                                                                                                                                                  MD5:0F69284483D337DC8202970461A28386
                                                                                                                                                                                                                                  SHA1:0D4592B8EBE070119CB3308534FE9A07A758F309
                                                                                                                                                                                                                                  SHA-256:3A5DB7C2C71F95C495D0884001F82599E794118452E2748E95A7565523546A8E
                                                                                                                                                                                                                                  SHA-512:D9F2618B153BFE4888E893A62128BE0BD59DFAFC824DA629454D5D541A9789536AC029BF73B6E9749409C522F450D53A270D302B2CF084444EA64D9138D77DFE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Oslo)]} {. LoadTimeZoneFile Europe/Oslo.}.set TZData(:Arctic/Longyearbyen) $TZData(:Europe/Oslo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):166
                                                                                                                                                                                                                                  Entropy (8bit):4.7788335911117095
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8t1zVAIgNsM1E2WFK4h4WFK81S:SlSWB9IZaM3yN1zVAIgaM1E2wKs4wK8c
                                                                                                                                                                                                                                  MD5:BBAFEA8E55A739C72E69A619C406BD5D
                                                                                                                                                                                                                                  SHA1:0C2793114CA716C5DBAF081083DF1E137F1D0A63
                                                                                                                                                                                                                                  SHA-256:6E69C5C3C3E1C98F24F5F523EC666B82534C9F33132A93CCC1100F27E594027F
                                                                                                                                                                                                                                  SHA-512:7741F2281FDCA8F01A75ABEBF908F0B70320C4C026D90D4B0C283F3E2B8C47C95263569916EF83CAD40C87D5B6E714045D0B43370A263BC7BE80EC3DA62CC82F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Riyadh)]} {. LoadTimeZoneFile Asia/Riyadh.}.set TZData(:Asia/Aden) $TZData(:Asia/Riyadh).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1580
                                                                                                                                                                                                                                  Entropy (8bit):3.640808791765599
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQveh8mSsOXEFCMiq90DIgb5j6gMJR/4TJTXSATo6SSsMuRFnCYRluoCC1Q0cxfw:50Fqq9iTVrXjS0qBsW
                                                                                                                                                                                                                                  MD5:AC511C65052CE2D780FD583E50CB475C
                                                                                                                                                                                                                                  SHA1:6B9171A13F6E6F33F878A347173A03112BCF1B89
                                                                                                                                                                                                                                  SHA-256:C9739892527CCEBDF91D7E22A6FCD0FD57AAFA6A1B4535915AC82CF6F72F34A4
                                                                                                                                                                                                                                  SHA-512:12743486EB02C241C90ECCEDD323D0F560D5FA1F55CB3EBB5AF3A65331D362433F2EAF7285B19335F5C262DA033EB8BE5A4618794EA74DFCD4107C170035CE96
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Almaty) {. {-9223372036854775808 18468 0 LMT}. {-1441170468 18000 0 +05}. {-1247547600 21600 0 +06}. {354909600 25200 1 +06}. {370717200 21600 0 +06}. {386445600 25200 1 +06}. {402253200 21600 0 +06}. {417981600 25200 1 +06}. {433789200 21600 0 +06}. {449604000 25200 1 +06}. {465336000 21600 0 +06}. {481060800 25200 1 +06}. {496785600 21600 0 +06}. {512510400 25200 1 +06}. {528235200 21600 0 +06}. {543960000 25200 1 +06}. {559684800 21600 0 +06}. {575409600 25200 1 +06}. {591134400 21600 0 +06}. {606859200 25200 1 +06}. {622584000 21600 0 +06}. {638308800 25200 1 +06}. {654638400 21600 0 +06}. {670363200 18000 0 +05}. {670366800 21600 1 +05}. {686091600 18000 0 +05}. {695768400 21600 0 +06}. {701812800 25200 1 +06}. {717537600 21600 0 +06}. {733262400 25200 1 +06}. {748987200 21600 0 +06}. {764712000 25200 1 +06}. {780436800 21
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7055
                                                                                                                                                                                                                                  Entropy (8bit):3.621680472512772
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:Rnv8A4XkyKfUN9QXCkFpej4g2uMekzdgyvwKVuKEZhfuITrar2gsq0teU:RvMw2y3p+4g2PxbLS5
                                                                                                                                                                                                                                  MD5:703F8A37D41186AC8CDBCB86B9FE6C1B
                                                                                                                                                                                                                                  SHA1:B2D7FCBD290DA0FEB31CD310BA29FE27A59822BE
                                                                                                                                                                                                                                  SHA-256:847FA8211956C5930930E2D7E760B1D7F551E8CDF99817DB630222C960069EB8
                                                                                                                                                                                                                                  SHA-512:66504E448469D2358C228966739F0FEB381BF862866A951B092A600A17DAD80E6331F6D88C4CFCE483F45E79451722A19B37291EDA75C7CD4D7E0A7E82096F47
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Amman) {. {-9223372036854775808 8624 0 LMT}. {-1230776624 7200 0 EET}. {108165600 10800 1 EEST}. {118270800 7200 0 EET}. {136591200 10800 1 EEST}. {149806800 7200 0 EET}. {168127200 10800 1 EEST}. {181342800 7200 0 EET}. {199749600 10800 1 EEST}. {215643600 7200 0 EET}. {231285600 10800 1 EEST}. {244501200 7200 0 EET}. {262735200 10800 1 EEST}. {275950800 7200 0 EET}. {481154400 10800 1 EEST}. {496962000 7200 0 EET}. {512949600 10800 1 EEST}. {528670800 7200 0 EET}. {544399200 10800 1 EEST}. {560120400 7200 0 EET}. {575848800 10800 1 EEST}. {592174800 7200 0 EET}. {610581600 10800 1 EEST}. {623624400 7200 0 EET}. {641167200 10800 1 EEST}. {655074000 7200 0 EET}. {671839200 10800 1 EEST}. {685918800 7200 0 EET}. {702856800 10800 1 EEST}. {717973200 7200 0 EET}. {733701600 10800 1 EEST}. {749422800 7200 0 EET}. {765151200 10800 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2014
                                                                                                                                                                                                                                  Entropy (8bit):3.680306971172711
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQMe/VrghhF87/Fpd2kNNxLcULBQdHl2yYvpQ62itgUiRrn5d6kGFF6UERWkBUHA:5ah2zFvpchKvW62XPdXJMwT3Lea
                                                                                                                                                                                                                                  MD5:E0396BBBB3FDDD2B651D2DBB4EF90884
                                                                                                                                                                                                                                  SHA1:C1FFCDC6EB77B5F4CFAFA90EA8E1025DB142D5C5
                                                                                                                                                                                                                                  SHA-256:6A9B4EF8FBED758E8D1737C79D803F9DF4F5BF61F115064ED60DA2397B88FE19
                                                                                                                                                                                                                                  SHA-512:8FB6D19189142F11812B82F5803F4E5C85BF107689D317305D32EF71905DC9E0655DD2F2D4CE234B5872A6BF452670221F94EF1D48EF776C002AA5A484C2481B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Anadyr) {. {-9223372036854775808 42596 0 LMT}. {-1441194596 43200 0 +12}. {-1247572800 46800 0 +14}. {354884400 50400 1 +14}. {370692000 46800 0 +13}. {386420400 43200 0 +13}. {386424000 46800 1 +13}. {402231600 43200 0 +12}. {417960000 46800 1 +13}. {433767600 43200 0 +12}. {449582400 46800 1 +13}. {465314400 43200 0 +12}. {481039200 46800 1 +13}. {496764000 43200 0 +12}. {512488800 46800 1 +13}. {528213600 43200 0 +12}. {543938400 46800 1 +13}. {559663200 43200 0 +12}. {575388000 46800 1 +13}. {591112800 43200 0 +12}. {606837600 46800 1 +13}. {622562400 43200 0 +12}. {638287200 46800 1 +13}. {654616800 43200 0 +12}. {670341600 39600 0 +12}. {670345200 43200 1 +12}. {686070000 39600 0 +11}. {695746800 43200 0 +13}. {701791200 46800 1 +13}. {717516000 43200 0 +12}. {733240800 46800 1 +13}. {748965600 43200 0 +12}. {764690400 46
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1607
                                                                                                                                                                                                                                  Entropy (8bit):3.623112789966889
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQJeoR9NSVYlS7hhmSQcwqSlhJS9yiIoSBHrSLUSIYdDS7/S5c3oSATo03CRJS2I:5fZlkhs7bqIwIoMpqDS7oXb0w+sRBlL
                                                                                                                                                                                                                                  MD5:410226AA30925F31BA963139FD594AEB
                                                                                                                                                                                                                                  SHA1:860E17C83D0DF2CBB4B8E73B9C7CB956994F5549
                                                                                                                                                                                                                                  SHA-256:69402CA6D56138A6A6D09964B90D1781A7CBEFBDFFE506B7292758EC24740B0E
                                                                                                                                                                                                                                  SHA-512:AE2610D1D779500132D5FA12E7529551ECD009848619C7D802F6EE89B0D2C3D6E7C91FB83DA7616180C166CE9C4499D7A2A4FEB5373621353640A71830B655A3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Aqtau) {. {-9223372036854775808 12064 0 LMT}. {-1441164064 14400 0 +04}. {-1247544000 18000 0 +05}. {370724400 21600 0 +06}. {386445600 18000 0 +05}. {386449200 21600 1 +05}. {402256800 18000 0 +05}. {417985200 21600 1 +05}. {433792800 18000 0 +05}. {449607600 21600 1 +05}. {465339600 18000 0 +05}. {481064400 21600 1 +05}. {496789200 18000 0 +05}. {512514000 21600 1 +05}. {528238800 18000 0 +05}. {543963600 21600 1 +05}. {559688400 18000 0 +05}. {575413200 21600 1 +05}. {591138000 18000 0 +05}. {606862800 21600 1 +05}. {622587600 18000 0 +05}. {638312400 21600 1 +05}. {654642000 18000 0 +05}. {670366800 14400 0 +04}. {670370400 18000 1 +04}. {686095200 14400 0 +04}. {695772000 18000 0 +05}. {701816400 21600 1 +05}. {717541200 18000 0 +05}. {733266000 21600 1 +05}. {748990800 18000 0 +05}. {764715600 21600 1 +05}. {780440400 180
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1608
                                                                                                                                                                                                                                  Entropy (8bit):3.6301391279603696
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5FhXlkhs7bqIwIoMpqDS7oXb0w+bBijbbyzIr1jJL:PtCOgZbdp
                                                                                                                                                                                                                                  MD5:B8D914F33D568AE8EB46B7F3FC5BF944
                                                                                                                                                                                                                                  SHA1:91DE61EC025E8F74D9CD10816C3534B5F8D397F7
                                                                                                                                                                                                                                  SHA-256:9C1C30ADD1919951350C86DA6B716326178CF74A849A3350AE147DD2ADC34049
                                                                                                                                                                                                                                  SHA-512:A32B34C15D94C42E9DF13316ACB9E0C9AF151F2EF14F502BE1A75E40735A2BC5D9E59244A72ACFB68184DA0D62A48FCC7AB288F1BA85DBB4DC385FA04BF3075D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Aqtobe) {. {-9223372036854775808 13720 0 LMT}. {-1441165720 14400 0 +04}. {-1247544000 18000 0 +05}. {354913200 21600 1 +06}. {370720800 21600 0 +06}. {386445600 18000 0 +05}. {386449200 21600 1 +05}. {402256800 18000 0 +05}. {417985200 21600 1 +05}. {433792800 18000 0 +05}. {449607600 21600 1 +05}. {465339600 18000 0 +05}. {481064400 21600 1 +05}. {496789200 18000 0 +05}. {512514000 21600 1 +05}. {528238800 18000 0 +05}. {543963600 21600 1 +05}. {559688400 18000 0 +05}. {575413200 21600 1 +05}. {591138000 18000 0 +05}. {606862800 21600 1 +05}. {622587600 18000 0 +05}. {638312400 21600 1 +05}. {654642000 18000 0 +05}. {670366800 14400 0 +04}. {670370400 18000 1 +04}. {686095200 14400 0 +04}. {695772000 18000 0 +05}. {701816400 21600 1 +05}. {717541200 18000 0 +05}. {733266000 21600 1 +05}. {748990800 18000 0 +05}. {764715600 21
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):847
                                                                                                                                                                                                                                  Entropy (8bit):3.852939540326754
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQgZeRHINS62DS7hhmSQcwqSlhJS9yiIoSBHrSLUSIYdDS7/S5c3oSATo03CRJL:5g8U0khs7bqIwIoMpqDS7oXb0L
                                                                                                                                                                                                                                  MD5:BFDAC4AE48AD49E5C0A048234586507E
                                                                                                                                                                                                                                  SHA1:ACFE49AED50D0FDF2978034BB3098331F6266CC8
                                                                                                                                                                                                                                  SHA-256:77FB5A9F578E75EEC3E3B83618C99F33A04C19C8BB9AFB314888091A8DD64AA3
                                                                                                                                                                                                                                  SHA-512:11B412E0856BD384080B982C9DE6CE196E8C71A68096F7ED22972B7617533F9BD92EFA4C153F2CEE7EA4F0DE206281B6B9066C5969AFFE913AF2FA5CF82EDD90
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Ashgabat) {. {-9223372036854775808 14012 0 LMT}. {-1441166012 14400 0 +04}. {-1247544000 18000 0 +05}. {354913200 21600 1 +05}. {370720800 18000 0 +05}. {386449200 21600 1 +05}. {402256800 18000 0 +05}. {417985200 21600 1 +05}. {433792800 18000 0 +05}. {449607600 21600 1 +05}. {465339600 18000 0 +05}. {481064400 21600 1 +05}. {496789200 18000 0 +05}. {512514000 21600 1 +05}. {528238800 18000 0 +05}. {543963600 21600 1 +05}. {559688400 18000 0 +05}. {575413200 21600 1 +05}. {591138000 18000 0 +05}. {606862800 21600 1 +05}. {622587600 18000 0 +05}. {638312400 21600 1 +05}. {654642000 18000 0 +05}. {670366800 14400 0 +04}. {670370400 18000 1 +04}. {686095200 14400 0 +04}. {695772000 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.750782589043179
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8xEYM4DdVAIgN/ZEYvCHt2WFKUNSH+WFKYEYMvn:SlSWB9IZaM3yRhVAIgH1CHt2wKUNSewa
                                                                                                                                                                                                                                  MD5:73E1F618FB430C503A1499E3A0298C97
                                                                                                                                                                                                                                  SHA1:29F31A7C9992F9D9B3447FCBC878F1AF8E4BD57F
                                                                                                                                                                                                                                  SHA-256:5917FC603270C0470D2EC416E6C85E999A52B6A384A2E1C5CFC41B29ABCA963A
                                                                                                                                                                                                                                  SHA-512:FAE39F158A4F47B4C37277A1DC77B8524DD4287EBAD5D8E6CBB906184E6DA275A308B55051114F4CD4908B449AE3C8FD48384271E3F7106801AD765E5958B4DD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Ashgabat)]} {. LoadTimeZoneFile Asia/Ashgabat.}.set TZData(:Asia/Ashkhabad) $TZData(:Asia/Ashgabat).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1608
                                                                                                                                                                                                                                  Entropy (8bit):3.6351436957032477
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:55IZlkhs7bqIwIoMpqDS7oXb0w+bBijbbyblL:X8COgZbd4x
                                                                                                                                                                                                                                  MD5:F2A86E76222B06103F6C1E8F89EB453E
                                                                                                                                                                                                                                  SHA1:D73938EBCA8C1340A7C86E865492EE581DFFC393
                                                                                                                                                                                                                                  SHA-256:211AB2318746486C356091EC2D3508D6FB79B9EBC78FC843BF2ADC96A38C4217
                                                                                                                                                                                                                                  SHA-512:B5F4F8FF11FA6D113B23F60D64E1737C7FABDDEBF12C37138F0FA05254E6C1643A2D3CA6C322943F4E877CE2E3736CF0F0741DD390C79E7EE94D56361B14BF45
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Atyrau) {. {-9223372036854775808 12464 0 LMT}. {-1441164464 10800 0 +03}. {-1247540400 18000 0 +05}. {370724400 21600 0 +06}. {386445600 18000 0 +05}. {386449200 21600 1 +05}. {402256800 18000 0 +05}. {417985200 21600 1 +05}. {433792800 18000 0 +05}. {449607600 21600 1 +05}. {465339600 18000 0 +05}. {481064400 21600 1 +05}. {496789200 18000 0 +05}. {512514000 21600 1 +05}. {528238800 18000 0 +05}. {543963600 21600 1 +05}. {559688400 18000 0 +05}. {575413200 21600 1 +05}. {591138000 18000 0 +05}. {606862800 21600 1 +05}. {622587600 18000 0 +05}. {638312400 21600 1 +05}. {654642000 18000 0 +05}. {670366800 14400 0 +04}. {670370400 18000 1 +04}. {686095200 14400 0 +04}. {695772000 18000 0 +05}. {701816400 21600 1 +05}. {717541200 18000 0 +05}. {733266000 21600 1 +05}. {748990800 18000 0 +05}. {764715600 21600 1 +05}. {780440400 18
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1643
                                                                                                                                                                                                                                  Entropy (8bit):3.6348723729667975
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQcTe0yZH76UtjUtUVmFbmU0cybUJN2cU2U9U56UJMlUoCUUbu/UTbU4UdTbU8U6:5cp6pLmFsyN2LouCIpYZgrCi
                                                                                                                                                                                                                                  MD5:2C0422E86BA0AECAA97CA01F3A27B797
                                                                                                                                                                                                                                  SHA1:C28FD8530B7895B4631EA0CAE03E6019561C4C40
                                                                                                                                                                                                                                  SHA-256:D5D69D7A4FE29761C5C3FFBB41A4F8B6B5F2101A34678B1FA9B1D39FC5478EA8
                                                                                                                                                                                                                                  SHA-512:3C346DE7E82B8EF1783F5A6D8A6099F7A530DD29AD48EDBB72F019ADC47155A703845503B1DD2589315BB67FA40AEF584313150686248DF45F983781F4B18710
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Baghdad) {. {-9223372036854775808 10660 0 LMT}. {-2524532260 10656 0 BMT}. {-1641005856 10800 0 +03}. {389048400 14400 0 +03}. {402264000 10800 0 +03}. {417906000 14400 1 +03}. {433800000 10800 0 +03}. {449614800 14400 1 +03}. {465422400 10800 0 +03}. {481150800 14400 1 +03}. {496792800 10800 0 +03}. {512517600 14400 1 +03}. {528242400 10800 0 +03}. {543967200 14400 1 +03}. {559692000 10800 0 +03}. {575416800 14400 1 +03}. {591141600 10800 0 +03}. {606866400 14400 1 +03}. {622591200 10800 0 +03}. {638316000 14400 1 +03}. {654645600 10800 0 +03}. {670464000 14400 1 +03}. {686275200 10800 0 +03}. {702086400 14400 1 +03}. {717897600 10800 0 +03}. {733622400 14400 1 +03}. {749433600 10800 0 +03}. {765158400 14400 1 +03}. {780969600 10800 0 +03}. {796694400 14400 1 +03}. {812505600 10800 0 +03}. {828316800 14400 1 +03}. {844128000 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):166
                                                                                                                                                                                                                                  Entropy (8bit):4.732157428331905
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8hHVAIgNvZAvxL2WFKENUKMFB/4WFKKu:SlSWB9IZaM3yBHVAIgPAvxL2wKENUr/i
                                                                                                                                                                                                                                  MD5:6291D60E3A30B76FEB491CB944BC2003
                                                                                                                                                                                                                                  SHA1:3D31032CF518A712FBA49DEC42FF3D99DD468140
                                                                                                                                                                                                                                  SHA-256:A462F83DDB0CCC41AC10E0B5B98287B4D89DA8BBBCA869CCFB81979C70613C6C
                                                                                                                                                                                                                                  SHA-512:C62D44527EAD47D2281FF951B9CF84C297859CFDC9A497CB92A583B6012B2B9DAAE9924EF17BC6B7CD317B770FF4924D8E1E77ED2E0EBC02502530D132EDE35B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Qatar)]} {. LoadTimeZoneFile Asia/Qatar.}.set TZData(:Asia/Bahrain) $TZData(:Asia/Qatar).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2075
                                                                                                                                                                                                                                  Entropy (8bit):3.5206282649651808
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ4ekZqpkb/cXXn8UDu5u8WmFeb/RLc9qENkw/ybt8i9E60339UyuU+DTO1KKlYX:5YTVOZmF7N76eHIAMsiWVyv2Te
                                                                                                                                                                                                                                  MD5:460EDC7D17FFA6AF834B6474D8262FB0
                                                                                                                                                                                                                                  SHA1:913E117814A5B4B7283A533F47525C8A0C68FD3C
                                                                                                                                                                                                                                  SHA-256:0A1FDA259EE5EBC779768BBADACC7E1CCAC56484AA6C03F7C1F79647AB79593D
                                                                                                                                                                                                                                  SHA-512:4047A7AD5F248F0B304FEF06C73EA655D603C39B6AC74629A2ADD49A93E74B23F458DC70E8150AD3F5BBF773F2387907B4BB69A95EB945B9FA432CA6B8AB173D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Baku) {. {-9223372036854775808 11964 0 LMT}. {-1441163964 10800 0 +03}. {-405140400 14400 0 +04}. {354916800 18000 1 +04}. {370724400 14400 0 +04}. {386452800 18000 1 +04}. {402260400 14400 0 +04}. {417988800 18000 1 +04}. {433796400 14400 0 +04}. {449611200 18000 1 +04}. {465343200 14400 0 +04}. {481068000 18000 1 +04}. {496792800 14400 0 +04}. {512517600 18000 1 +04}. {528242400 14400 0 +04}. {543967200 18000 1 +04}. {559692000 14400 0 +04}. {575416800 18000 1 +04}. {591141600 14400 0 +04}. {606866400 18000 1 +04}. {622591200 14400 0 +04}. {638316000 18000 1 +04}. {654645600 14400 0 +04}. {670370400 10800 0 +03}. {670374000 14400 1 +03}. {686098800 10800 0 +03}. {701823600 14400 1 +03}. {717548400 14400 0 +04}. {820440000 14400 0 +04}. {828234000 18000 1 +05}. {846378000 14400 0 +04}. {852062400 14400 0 +04}. {859680000 18000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.863210418273511
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKELYOUXGm2OHB+kevXZKmrROpDvFFsQ+8EXVeVSYvC:SlSWB9X52wKELPm2OHxePZ3FO1Rb+UVe
                                                                                                                                                                                                                                  MD5:8291C9916E9D5E5C78DE38257798799D
                                                                                                                                                                                                                                  SHA1:F67A474337CF5FF8460911C7003930455AA0C530
                                                                                                                                                                                                                                  SHA-256:ED9D1C47D50461D312C7314D5C1403703E29EE14E6BAC97625EFB06F38E4942C
                                                                                                                                                                                                                                  SHA-512:9B552812A0001271980F87C270EF4149201403B911826BDF17F66EE1015B9AC859C1B2E7BB4EB6BC56E37CDB24097BF001201C34AD7D4C0C910AE17CFEC36C8B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Bangkok) {. {-9223372036854775808 24124 0 LMT}. {-2840164924 24124 0 BMT}. {-1570084924 25200 0 +07}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2044
                                                                                                                                                                                                                                  Entropy (8bit):3.6106776173203916
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5Mi17A9/IJ4vQayW+dRvV8YzXJIq79Af3AuyqM7FfiC/L7UVtrBju6waUwcTLTTg:9jFRRCfQuiB7TQZ
                                                                                                                                                                                                                                  MD5:DC7A71DAB17C7F4A348DC1EE2FC458C5
                                                                                                                                                                                                                                  SHA1:982FAB93A637D18A049DDBE96B0341736C66561D
                                                                                                                                                                                                                                  SHA-256:52DB3278189AA2380D84A81199A2E7F3B40E9706228D2291C6257FD513D78667
                                                                                                                                                                                                                                  SHA-512:90659D37D2A2E8574A88FD7F222C28D9572A9866FC3459B0CC1760FECBC7C4A0574B224C252877D723B06DD72165C4FE368D5B00DAB662B85D2E0F4CB2A89271
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Barnaul) {. {-9223372036854775808 20100 0 LMT}. {-1579844100 21600 0 +06}. {-1247551200 25200 0 +08}. {354906000 28800 1 +08}. {370713600 25200 0 +07}. {386442000 28800 1 +08}. {402249600 25200 0 +07}. {417978000 28800 1 +08}. {433785600 25200 0 +07}. {449600400 28800 1 +08}. {465332400 25200 0 +07}. {481057200 28800 1 +08}. {496782000 25200 0 +07}. {512506800 28800 1 +08}. {528231600 25200 0 +07}. {543956400 28800 1 +08}. {559681200 25200 0 +07}. {575406000 28800 1 +08}. {591130800 25200 0 +07}. {606855600 28800 1 +08}. {622580400 25200 0 +07}. {638305200 28800 1 +08}. {654634800 25200 0 +07}. {670359600 21600 0 +07}. {670363200 25200 1 +07}. {686088000 21600 0 +06}. {695764800 25200 0 +08}. {701809200 28800 1 +08}. {717534000 25200 0 +07}. {733258800 28800 1 +08}. {748983600 25200 0 +07}. {764708400 28800 1 +08}. {780433200 2
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7754
                                                                                                                                                                                                                                  Entropy (8bit):3.6329631010207892
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:OnQv8iPC28v82K/w1VxDmsCZgV+f7dIWDkLDo1WlqCTpXxcKvjRQZwtPEWRTvS4y:OQjPCL5VxKWC7dIWDkLDoqphsX
                                                                                                                                                                                                                                  MD5:2D3AE4AD36BD5F302F980EB5F1DD0E4A
                                                                                                                                                                                                                                  SHA1:02244056D6D4EC57937D1E187CC65E8FD18F67F0
                                                                                                                                                                                                                                  SHA-256:E9DD371FA47F8EF1BE04109F0FD3EBD9FC5E2B0A12C0630CDD20099C838CBEBB
                                                                                                                                                                                                                                  SHA-512:2E4528254102210B8A9A2263A8A8E72774D40F57C2431C2DD6B1761CD91FB6CEA1FAD23877E1E2D86217609882F3605D7FE477B771A398F91F8D8AD3EAF90BAC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Beirut) {. {-9223372036854775808 8520 0 LMT}. {-2840149320 7200 0 EET}. {-1570413600 10800 1 EEST}. {-1552186800 7200 0 EET}. {-1538359200 10800 1 EEST}. {-1522551600 7200 0 EET}. {-1507514400 10800 1 EEST}. {-1490583600 7200 0 EET}. {-1473645600 10800 1 EEST}. {-1460948400 7200 0 EET}. {-399866400 10800 1 EEST}. {-386650800 7200 0 EET}. {-368330400 10800 1 EEST}. {-355114800 7200 0 EET}. {-336794400 10800 1 EEST}. {-323578800 7200 0 EET}. {-305172000 10800 1 EEST}. {-291956400 7200 0 EET}. {-273636000 10800 1 EEST}. {-260420400 7200 0 EET}. {78012000 10800 1 EEST}. {86734800 7200 0 EET}. {105055200 10800 1 EEST}. {118270800 7200 0 EET}. {136591200 10800 1 EEST}. {149806800 7200 0 EET}. {168127200 10800 1 EEST}. {181342800 7200 0 EET}. {199749600 10800 1 EEST}. {212965200 7200 0 EET}. {231285600 10800 1 EEST}. {244501200 7200 0 EE
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1611
                                                                                                                                                                                                                                  Entropy (8bit):3.653654369590701
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQge4/SsOXEFCMiq90DIgb5j6gMJR/4TJTXSATolS+WSP7VSzlBSkhFSblDSDOQy:5qFqq9iTVrX2ioerAYabcivcnXKh
                                                                                                                                                                                                                                  MD5:1A3A4825B73F11024FD21F94AE85F9D2
                                                                                                                                                                                                                                  SHA1:E63443CC267B43EFEFFD1E3161293217526E7DC8
                                                                                                                                                                                                                                  SHA-256:D8205F34BB8B618E2F8B4EB6E613BE1B5CFBBF3B6CBFAFE868644E1A1648C164
                                                                                                                                                                                                                                  SHA-512:5C766BD6FB6195BEBD7CDF703B7E0A67FBB2BCF98052866AE9ACDC5B90469421508F52C60F22542BBA6ED8CC59B4889F20DB131B183918592139B6D135BC57A2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Bishkek) {. {-9223372036854775808 17904 0 LMT}. {-1441169904 18000 0 +05}. {-1247547600 21600 0 +06}. {354909600 25200 1 +06}. {370717200 21600 0 +06}. {386445600 25200 1 +06}. {402253200 21600 0 +06}. {417981600 25200 1 +06}. {433789200 21600 0 +06}. {449604000 25200 1 +06}. {465336000 21600 0 +06}. {481060800 25200 1 +06}. {496785600 21600 0 +06}. {512510400 25200 1 +06}. {528235200 21600 0 +06}. {543960000 25200 1 +06}. {559684800 21600 0 +06}. {575409600 25200 1 +06}. {591134400 21600 0 +06}. {606859200 25200 1 +06}. {622584000 21600 0 +06}. {638308800 25200 1 +06}. {654638400 21600 0 +06}. {670363200 18000 0 +05}. {670366800 21600 1 +05}. {683586000 18000 0 +05}. {703018800 21600 1 +05}. {717530400 18000 0 +05}. {734468400 21600 1 +05}. {748980000 18000 0 +05}. {765918000 21600 1 +05}. {780429600 18000 0 +05}. {797367600 2
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.792958708451203
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKXeAMMkEXGm2OHCQdvVVvUWUOVFW/FvOVSSC/FiUMWfV1S:SlSWB9X52wK0bm2OHCIvVVXUuW/MVSSV
                                                                                                                                                                                                                                  MD5:95EE0EFC01271C3E3195ADC360F832C7
                                                                                                                                                                                                                                  SHA1:CDFA243F359AC5D2FA22032BF296169C8B2B942A
                                                                                                                                                                                                                                  SHA-256:241C47769C689823961D308B38D8282F6852BC0511E7DC196BF6BF4CFADBE401
                                                                                                                                                                                                                                  SHA-512:11CAE9804EF933A790F5B9B86CC03C133DBD1DB97FAA78F508D681662AAC3714B93166B596F248799FC5B86344B48764865D3371427119999CB02963C98E15C3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Brunei) {. {-9223372036854775808 27580 0 LMT}. {-1383464380 27000 0 +0730}. {-1167636600 28800 0 +08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.721946029615065
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq864DdVAIgN1EF2WFKh0s+WFKvvn:SlSWB9IZaM3ya4DdVAIgo2wKN+wKvv
                                                                                                                                                                                                                                  MD5:A967F010A398CD98871E1FF97F3E48AC
                                                                                                                                                                                                                                  SHA1:6C8C0AF614D6789CD1F9B6243D26FAC1F9B767EF
                                                                                                                                                                                                                                  SHA-256:B07250CD907CA11FE1C94F1DCCC999CECF8E9969F74442A9FCC00FC48EDE468B
                                                                                                                                                                                                                                  SHA-512:67E3207C8A63A5D8A1B7ED1A62D57639D695F9CD83126EB58A70EF076B816EC5C4FDBD23F1F32A4BB6F0F9131D30AF16B56CD92B1C42C240FD886C81BA8940DA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Kolkata)]} {. LoadTimeZoneFile Asia/Kolkata.}.set TZData(:Asia/Calcutta) $TZData(:Asia/Kolkata).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2014
                                                                                                                                                                                                                                  Entropy (8bit):3.6060921590827193
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQyeCXQS6oziDpiKXtyiyzilUBinUijiRziiiaSiYzYWk2HgQiMhNIziPiRikiAF:5c/9InX4n7m84nPIzOtfjQhGTNw
                                                                                                                                                                                                                                  MD5:A3FB98DC18AC53AE13337F3CC1C4CE68
                                                                                                                                                                                                                                  SHA1:F0280D5598AEB6B6851A8C2831D4370E27121B5F
                                                                                                                                                                                                                                  SHA-256:D0A984F2EDB6A5A4E3C3CFA812550782F6B34AD0C79B1DD742712EBA14B7B9FB
                                                                                                                                                                                                                                  SHA-512:A33E2E0EA093BB758539A761B4CF82204699BC35950ACD329DA9205A141469930CAF179E4331DF505408C7C4F97480416DC16C7E93E53B12392509E5A093E562
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Chita) {. {-9223372036854775808 27232 0 LMT}. {-1579419232 28800 0 +08}. {-1247558400 32400 0 +10}. {354898800 36000 1 +10}. {370706400 32400 0 +09}. {386434800 36000 1 +10}. {402242400 32400 0 +09}. {417970800 36000 1 +10}. {433778400 32400 0 +09}. {449593200 36000 1 +10}. {465325200 32400 0 +09}. {481050000 36000 1 +10}. {496774800 32400 0 +09}. {512499600 36000 1 +10}. {528224400 32400 0 +09}. {543949200 36000 1 +10}. {559674000 32400 0 +09}. {575398800 36000 1 +10}. {591123600 32400 0 +09}. {606848400 36000 1 +10}. {622573200 32400 0 +09}. {638298000 36000 1 +10}. {654627600 32400 0 +09}. {670352400 28800 0 +09}. {670356000 32400 1 +09}. {686080800 28800 0 +08}. {695757600 32400 0 +10}. {701802000 36000 1 +10}. {717526800 32400 0 +09}. {733251600 36000 1 +10}. {748976400 32400 0 +09}. {764701200 36000 1 +10}. {780426000 324
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1563
                                                                                                                                                                                                                                  Entropy (8bit):3.6863846285633057
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQtZeCjXN1xJq4tyiIHil++lqivEoziHvqil+fiRBiS/BvWjiY2Vizi6Xi4+k8ih:5tFdXJVHpkbvvWr2sv5kPYxwM3N5
                                                                                                                                                                                                                                  MD5:799F0221A1834C723E6BBA2D00727156
                                                                                                                                                                                                                                  SHA1:569BBC1F20F7157ECF753A8DEB49156B260A96E0
                                                                                                                                                                                                                                  SHA-256:02FF47A619BE154A88530BA8C83F5D52277FA8E8F7941C0D33F89161CE1B5503
                                                                                                                                                                                                                                  SHA-512:535812754A92E251A9C86C20E3032A6B363F77F6839C95DAD6ED18200ACAA3075E602AD626F50B84EB931D1D33BD0E00CA5AE1D1D95DEBECDE57EE9E65A137DF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Choibalsan) {. {-9223372036854775808 27480 0 LMT}. {-2032933080 25200 0 +07}. {252435600 28800 0 +08}. {417974400 36000 0 +09}. {433778400 32400 0 +09}. {449593200 36000 1 +09}. {465314400 32400 0 +09}. {481042800 36000 1 +09}. {496764000 32400 0 +09}. {512492400 36000 1 +09}. {528213600 32400 0 +09}. {543942000 36000 1 +09}. {559663200 32400 0 +09}. {575391600 36000 1 +09}. {591112800 32400 0 +09}. {606841200 36000 1 +09}. {622562400 32400 0 +09}. {638290800 36000 1 +09}. {654616800 32400 0 +09}. {670345200 36000 1 +09}. {686066400 32400 0 +09}. {701794800 36000 1 +09}. {717516000 32400 0 +09}. {733244400 36000 1 +09}. {748965600 32400 0 +09}. {764694000 36000 1 +09}. {780415200 32400 0 +09}. {796143600 36000 1 +09}. {811864800 32400 0 +09}. {828198000 36000 1 +09}. {843919200 32400 0 +09}. {859647600 36000 1 +09}. {875368800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.815975603028152
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8qvwVAIgNtA2WFKh2V7/4WFKdv:SlSWB9IZaM3yMwVAIgE2wKho4wKt
                                                                                                                                                                                                                                  MD5:37D7B7C1E435E2539FDD83D71149DD9A
                                                                                                                                                                                                                                  SHA1:F4ADE88DDF244BD2FF5B23714BF7449A74907E08
                                                                                                                                                                                                                                  SHA-256:78611E8A0EBEBC4CA2A55611FAC1F00F8495CB044B2A6462214494C7D1F5DA6A
                                                                                                                                                                                                                                  SHA-512:E0C57229DC76746C6424606E41E10E97F0F08DD2B00659172DA35F3444BF48B4BC7E2F339A10ECC21628A683E2CB8B4FA5945B8AC68C6BAFEA720AFBB88C90C6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Shanghai)]} {. LoadTimeZoneFile Asia/Shanghai.}.set TZData(:Asia/Chongqing) $TZData(:Asia/Shanghai).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.840543487466552
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8qvwVAIgNtA2WFK7LeL9J4WFKdv:SlSWB9IZaM3yMwVAIgE2wK7LUT4wKt
                                                                                                                                                                                                                                  MD5:6F21100628DD48B2FF4B1F2AF92E05CB
                                                                                                                                                                                                                                  SHA1:B74478D0EC95A577C2A58497692DB293BBD31586
                                                                                                                                                                                                                                  SHA-256:DB2C572E039D1A777FFC66558E2BEE46C52D8FE57401436AE18BB4D5892131CE
                                                                                                                                                                                                                                  SHA-512:2D3C37790B6A764FE4E1B8BD8EDF1D073D711F59CEA3EC5E6003E481898F7285B42A14E904C3D148422244BB083FBA42C6623DF7DA05923F6145EEE3FD259520
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Shanghai)]} {. LoadTimeZoneFile Asia/Shanghai.}.set TZData(:Asia/Chungking) $TZData(:Asia/Shanghai).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):356
                                                                                                                                                                                                                                  Entropy (8bit):4.4006537789533695
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKr+tJm2OHgPZv9tGZjSWV/FSQRpPUrK/F/ND/k5iRVVFSQ9R/U4C/k:MBp52z+mdHgPZvqZj1NjDPh/F/1/Y4vF
                                                                                                                                                                                                                                  MD5:4074FBEF7DD0DF48AD74BDAED3106A75
                                                                                                                                                                                                                                  SHA1:FB1E5190EAF8BF9B64EED49F115E34926C1EAF53
                                                                                                                                                                                                                                  SHA-256:DB6A7EA0DC757706126114BED5E693565938AABFE3DA1670170647CCDE6BE6CD
                                                                                                                                                                                                                                  SHA-512:A469C09FA6A1DA1DB140BFFECB931DBC4B2315A13B82FCA8813C93954598D03818323B7DDE1106D1F1D815ED69523361369AF883CA4818CA562D728F7A88D8A7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Colombo) {. {-9223372036854775808 19164 0 LMT}. {-2840159964 19172 0 MMT}. {-2019705572 19800 0 +0530}. {-883287000 21600 1 +06}. {-862639200 23400 1 +0630}. {-764051400 19800 0 +0530}. {832962600 23400 0 +0630}. {846266400 21600 0 +06}. {1145039400 19800 0 +0530}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):164
                                                                                                                                                                                                                                  Entropy (8bit):4.733855608307331
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8ntdVAIgN6Ko2WFK1S2WFKwu:SlSWB9IZaM3yHtdVAIgMKo2wKM2wKwu
                                                                                                                                                                                                                                  MD5:629FC03B52D24615FB052C84B0F30452
                                                                                                                                                                                                                                  SHA1:80D24B1A70FC568AB9C555BD1CC70C17571F6061
                                                                                                                                                                                                                                  SHA-256:BD3E4EE002AFF8F84E74A6D53E08AF5B5F2CAF2B06C9E70B64B05FC8F0B6CA99
                                                                                                                                                                                                                                  SHA-512:1C912A5F323E84A82D60300F6AC55892F870974D4DEFE0AF0B8F6A87867A176D3F8D66C1A5B11D8560F549D738FFE377DC20EB055182615062D4649BBA011F32
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Dhaka)]} {. LoadTimeZoneFile Asia/Dhaka.}.set TZData(:Asia/Dacca) $TZData(:Asia/Dhaka).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8031
                                                                                                                                                                                                                                  Entropy (8bit):3.629699951300869
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:zY75F5VoNVIkbl3IUQZufk0Eej4YWuM0c5/61a7/VGfV8SbU5J3Mirmgs3LmiK:zI75KN+YlgYE+4YWPB6O4in9
                                                                                                                                                                                                                                  MD5:202E5950F6324878B0E6FD0056D2F186
                                                                                                                                                                                                                                  SHA1:A668D4DC3E73A292728CCE136EFFAC95D5952A81
                                                                                                                                                                                                                                  SHA-256:3BB43B71FF807AA3BF6A7F94680FB8BD586A1471218307A6A7A4CE73A5A3A55E
                                                                                                                                                                                                                                  SHA-512:5F9A7308E9C08267ECB8D502505EF9B32269D62FA490D6BC01F6927CB8D5B40CA17BB0CDFA3EE78D48C7686EAA7FD266666EB80E54125859F86CADFD7366DB6B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Damascus) {. {-9223372036854775808 8712 0 LMT}. {-1577931912 7200 0 EET}. {-1568592000 10800 1 EEST}. {-1554080400 7200 0 EET}. {-1537142400 10800 1 EEST}. {-1522630800 7200 0 EET}. {-1505692800 10800 1 EEST}. {-1491181200 7200 0 EET}. {-1474243200 10800 1 EEST}. {-1459126800 7200 0 EET}. {-242265600 10800 1 EEST}. {-228877200 7200 0 EET}. {-210556800 10800 1 EEST}. {-197427600 7200 0 EET}. {-178934400 10800 1 EEST}. {-165718800 7200 0 EET}. {-147398400 10800 1 EEST}. {-134269200 7200 0 EET}. {-116467200 10800 1 EEST}. {-102646800 7200 0 EET}. {-84326400 10800 1 EEST}. {-71110800 7200 0 EET}. {-52704000 10800 1 EEST}. {-39488400 7200 0 EET}. {-21168000 10800 1 EEST}. {-7952400 7200 0 EET}. {10368000 10800 1 EEST}. {23583600 7200 0 EET}. {41904000 10800 1 EEST}. {55119600 7200 0 EET}. {73526400 10800 1 EEST}. {86742000 7200 0 EET}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):351
                                                                                                                                                                                                                                  Entropy (8bit):4.345019966462698
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKwfTm2OHEmVFnP9vX+H7UlckVVFSQRL/FG/UPy/UiF/ji/UiF/jWKO:MBp52YfTmdHzdP9P+bcvjRQmmF/j2F/8
                                                                                                                                                                                                                                  MD5:F5A6B4C90D50208EF512A728A2A03BB6
                                                                                                                                                                                                                                  SHA1:C9D3C712EDABDFCD1629E72AF363CEB2A0E2334E
                                                                                                                                                                                                                                  SHA-256:42BF62F13C2F808BEFD2601D668AFE5D49EA417FC1AC5391631C20ED7225FF46
                                                                                                                                                                                                                                  SHA-512:64D413D9299436877F287943FF454EB2AFD415D87DE13AACA50E7BD123828D16CFABD679677F36C891024AB53C62695559DAABDECCC127A669C3ECA0F155453B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Dhaka) {. {-9223372036854775808 21700 0 LMT}. {-2524543300 21200 0 HMT}. {-891582800 23400 0 +0630}. {-872058600 19800 0 +0530}. {-862637400 23400 0 +0630}. {-576138600 21600 0 +06}. {1230746400 21600 0 +06}. {1245430800 25200 1 +06}. {1262278800 21600 0 +06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):226
                                                                                                                                                                                                                                  Entropy (8bit):4.536797249025477
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKCXeLm2OHnBGeVmkNvyvScCVUkP1avScCC:MBp52qXEmdHnBvVDVyHCPP8HCC
                                                                                                                                                                                                                                  MD5:54EC6A256F6D636CD98DD48CDF0E48F1
                                                                                                                                                                                                                                  SHA1:571244C3D84A8A6EFFE55C787BFBCE7A6014462C
                                                                                                                                                                                                                                  SHA-256:88D61A495724F72DA6AB20CC997575F27797589C7B80F2C63C27F84BF1EB8D61
                                                                                                                                                                                                                                  SHA-512:EDD67865D3AD3D2F6D1AFFAE35B6B25E2439164E0BEF8E0E819F88F937F896C10EAB513467524DA0A5A2E3D4C78F55EA3F98F25979B8625DFC66801CBBE9301F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Dili) {. {-9223372036854775808 30140 0 LMT}. {-1830414140 28800 0 +08}. {-879152400 32400 0 +09}. {199897200 28800 0 +08}. {969120000 32400 0 +09}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):142
                                                                                                                                                                                                                                  Entropy (8bit):4.927936359970315
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKQiXGm2OHvkdvUQK23NVsRYvC:SlSWB9X52wKQZm2OHvsRVNSQC
                                                                                                                                                                                                                                  MD5:6CC252314EDA586C514C76E6981EEAEE
                                                                                                                                                                                                                                  SHA1:F58C9072FBBA31C735345162F629BB6CAAB9C871
                                                                                                                                                                                                                                  SHA-256:8D7409EBC94A817962C3512E07AFF32838B54B939068129C73EBBEEF8F858ED2
                                                                                                                                                                                                                                  SHA-512:40BC04B25F16247F9F6569A37D28EDCA1D7FB33586482A990A36B5B148BF7598CF5493D38C4D1CBDF664553302E4D6505D80EB7E7B5B9FB5141CB7F39B99A93D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Dubai) {. {-9223372036854775808 13272 0 LMT}. {-1577936472 14400 0 +04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):791
                                                                                                                                                                                                                                  Entropy (8bit):3.8859952964866946
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQJeOJSsOXEFCMiq90DIgb5j6gMJR/4TJTi4GDL:51Fqq9iTVuzL
                                                                                                                                                                                                                                  MD5:316F527821D632517866A6E7F97365B3
                                                                                                                                                                                                                                  SHA1:6F56985AF44E6533778CFB1FC04D206367A6C0BF
                                                                                                                                                                                                                                  SHA-256:5A8FFD24FF0E26C99536EB9D3FB308C28B3491042034B187140039B7A5DF6F1F
                                                                                                                                                                                                                                  SHA-512:7EA1ABD02CD8461DD91576B5BCB46B6E3AE25F94BC7936DC051C0964F4EA2F55C58CB1FA6C3A82334AAAAFCDBD6D6DBEBE33FB1C7C45FBDCA5EC43FD46A970A7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Dushanbe) {. {-9223372036854775808 16512 0 LMT}. {-1441168512 18000 0 +05}. {-1247547600 21600 0 +06}. {354909600 25200 1 +06}. {370717200 21600 0 +06}. {386445600 25200 1 +06}. {402253200 21600 0 +06}. {417981600 25200 1 +06}. {433789200 21600 0 +06}. {449604000 25200 1 +06}. {465336000 21600 0 +06}. {481060800 25200 1 +06}. {496785600 21600 0 +06}. {512510400 25200 1 +06}. {528235200 21600 0 +06}. {543960000 25200 1 +06}. {559684800 21600 0 +06}. {575409600 25200 1 +06}. {591134400 21600 0 +06}. {606859200 25200 1 +06}. {622584000 21600 0 +06}. {638308800 25200 1 +06}. {654638400 21600 0 +06}. {670363200 21600 1 +06}. {684363600 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7341
                                                                                                                                                                                                                                  Entropy (8bit):3.6266031318601386
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:vPByq7VKviW/naKl9pUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtOEA:vPFi//Th2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:997FF37AE5C6E2E13664100C2FBF8E19
                                                                                                                                                                                                                                  SHA1:BF59628212564E50BCC5247C534658C8B7CFF0EE
                                                                                                                                                                                                                                  SHA-256:639F26A411E298948A4FAC560E218ED7079722FB4E4AAF8CE0688A3BE24868AE
                                                                                                                                                                                                                                  SHA-512:41FEF2026A3062ECA62729A555D10F9ABA777CCBE4E907489B74FC91C645E6010ECFABD2ACB4ED652ADF97E0A69935CB2FADA6732744ED3ADA95DD2EB3C08655
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Famagusta) {. {-9223372036854775808 8148 0 LMT}. {-1518920148 7200 0 EET}. {166572000 10800 1 EEST}. {182293200 7200 0 EET}. {200959200 10800 1 EEST}. {213829200 7200 0 EET}. {228866400 10800 1 EEST}. {243982800 7200 0 EET}. {260316000 10800 1 EEST}. {276123600 7200 0 EET}. {291765600 10800 1 EEST}. {307486800 7200 0 EET}. {323820000 10800 1 EEST}. {338936400 7200 0 EET}. {354664800 10800 1 EEST}. {370386000 7200 0 EET}. {386114400 10800 1 EEST}. {401835600 7200 0 EET}. {417564000 10800 1 EEST}. {433285200 7200 0 EET}. {449013600 10800 1 EEST}. {465339600 7200 0 EET}. {481068000 10800 1 EEST}. {496789200 7200 0 EET}. {512517600 10800 1 EEST}. {528238800 7200 0 EET}. {543967200 10800 1 EEST}. {559688400 7200 0 EET}. {575416800 10800 1 EEST}. {591138000 7200 0 EET}. {606866400 10800 1 EEST}. {622587600 7200 0 EET}. {638316000 108
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7974
                                                                                                                                                                                                                                  Entropy (8bit):3.660638074803316
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:uR7CUoVy0FUeLR2S5nfclzdVYi8x6PxGtv2h4WSwLnRPCILXwuiaAXOH4g1iWThA:uRiVy0WetivMKRPCAXwZ6plyk8B
                                                                                                                                                                                                                                  MD5:45C8B6CB180839A1F3D500071D1AFC1D
                                                                                                                                                                                                                                  SHA1:59E900FB2D7BFF44AED578B9BD10AA0530B4F5D1
                                                                                                                                                                                                                                  SHA-256:FA459622B54CD0A5603323EA00CE64D63BBC957EC0BDCC9BE73D48916237619C
                                                                                                                                                                                                                                  SHA-512:5F485299D6DF9EBD620D2AEF7BDE21C7505EAD51467699874408691C644E9E6D8C63DD6061489E924B95672A227B5B9921E4281405981FCBBCA4619F80195AB5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Gaza) {. {-9223372036854775808 8272 0 LMT}. {-2185409872 7200 0 EEST}. {-933645600 10800 1 EEST}. {-857358000 7200 0 EEST}. {-844300800 10800 1 EEST}. {-825822000 7200 0 EEST}. {-812685600 10800 1 EEST}. {-794199600 7200 0 EEST}. {-779853600 10800 1 EEST}. {-762656400 7200 0 EEST}. {-748310400 10800 1 EEST}. {-731127600 7200 0 EEST}. {-682653600 7200 0 EET}. {-399088800 10800 1 EEST}. {-386650800 7200 0 EET}. {-368330400 10800 1 EEST}. {-355114800 7200 0 EET}. {-336790800 10800 1 EEST}. {-323654400 7200 0 EET}. {-305168400 10800 1 EEST}. {-292032000 7200 0 EET}. {-273632400 10800 1 EEST}. {-260496000 7200 0 EET}. {-242096400 10800 1 EEST}. {-228960000 7200 0 EET}. {-210560400 10800 1 EEST}. {-197424000 7200 0 EET}. {-178938000 10800 1 EEST}. {-165801600 7200 0 EET}. {-147402000 10800 1 EEST}. {-134265600 7200 0 EET}. {-115866000 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.814799933523261
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8qvwVAIgNtA2WFKwHp4WFKdv:SlSWB9IZaM3yMwVAIgE2wKi4wKt
                                                                                                                                                                                                                                  MD5:2B286E58F2214F7A28D2A678B905CFA3
                                                                                                                                                                                                                                  SHA1:A76B2D8BA2EA264FE84C5C1ED3A6D3E13288132F
                                                                                                                                                                                                                                  SHA-256:6917C89A78ED54DD0C5C9968E5149D42727A9299723EC1D2EBD531A65AD37227
                                                                                                                                                                                                                                  SHA-512:0022B48003FE9C8722FD1762FFB8E07E731661900FCE40BD6FE82B70F162FF5D32888028519D51682863ADCAC6DD21D35634CA06489FD4B704DA5A8A018BF26F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Shanghai)]} {. LoadTimeZoneFile Asia/Shanghai.}.set TZData(:Asia/Harbin) $TZData(:Asia/Shanghai).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7950
                                                                                                                                                                                                                                  Entropy (8bit):3.6634483349947593
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:JrCUoVy0FUeLR2S5nfclzdVYi8x6PxGtv2h4WFwLnRPCILXwuiaAXOH4g1iWThiD:JyVy0WetivMvRPCAXwZ6plyk8B
                                                                                                                                                                                                                                  MD5:67602731E9D02418D0B1DCBCB9367870
                                                                                                                                                                                                                                  SHA1:13D896B6B8B553879D70BFBA6734AFDFE3A522A4
                                                                                                                                                                                                                                  SHA-256:9D89F879C6F47F05015C8B7D66639AAC8AF2D5A6F733CDA60CFF22EB0EB71221
                                                                                                                                                                                                                                  SHA-512:ECA8EB42144EF4097E606AC57795491248D02C331CE426E7C23D42490F873CD19924F1C2318E2FF1D18E275F3CAD60E9DFBB08B4B8334EA3FF1EE31452B9E167
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Hebron) {. {-9223372036854775808 8423 0 LMT}. {-2185410023 7200 0 EEST}. {-933645600 10800 1 EEST}. {-857358000 7200 0 EEST}. {-844300800 10800 1 EEST}. {-825822000 7200 0 EEST}. {-812685600 10800 1 EEST}. {-794199600 7200 0 EEST}. {-779853600 10800 1 EEST}. {-762656400 7200 0 EEST}. {-748310400 10800 1 EEST}. {-731127600 7200 0 EEST}. {-682653600 7200 0 EET}. {-399088800 10800 1 EEST}. {-386650800 7200 0 EET}. {-368330400 10800 1 EEST}. {-355114800 7200 0 EET}. {-336790800 10800 1 EEST}. {-323654400 7200 0 EET}. {-305168400 10800 1 EEST}. {-292032000 7200 0 EET}. {-273632400 10800 1 EEST}. {-260496000 7200 0 EET}. {-242096400 10800 1 EEST}. {-228960000 7200 0 EET}. {-210560400 10800 1 EEST}. {-197424000 7200 0 EET}. {-178938000 10800 1 EEST}. {-165801600 7200 0 EET}. {-147402000 10800 1 EEST}. {-134265600 7200 0 EET}. {-115866000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):381
                                                                                                                                                                                                                                  Entropy (8bit):4.352557338100764
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKKACm2OHAT1P3XTxYCMVSYv/lTkd+zvScCBcFVtQvMVSYv/vMUEkB5:MBp52SmdHqP3tYZF/Cd+zHCBiVikF/v9
                                                                                                                                                                                                                                  MD5:41EF18FF071B8541A5CA830C131B22D3
                                                                                                                                                                                                                                  SHA1:65E502FD93FE025FD7B358B2953335F4B41BBC68
                                                                                                                                                                                                                                  SHA-256:95525205BC65B8DB626EF5257F6C3A93A4902AB6415C080EE67399B41D9AD7AA
                                                                                                                                                                                                                                  SHA-512:3889199D84CE456CC7231B0A81CCA7F4C976ED13015869BF486078075F24687C588F9FB52E09744ED4763CA71CC869048C588CDD42C2EA195A9B04EB9C18A123
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Ho_Chi_Minh) {. {-9223372036854775808 25600 0 LMT}. {-2004073600 25590 0 PLMT}. {-1851577590 25200 0 +07}. {-852105600 28800 0 +08}. {-782643600 32400 0 +09}. {-767869200 25200 0 +07}. {-718095600 28800 0 +08}. {-457776000 25200 0 +07}. {-315648000 28800 0 +08}. {171820800 25200 0 +07}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2150
                                                                                                                                                                                                                                  Entropy (8bit):3.923186571913929
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQPeCtKkjz1lk/mJURqMJDHxyOPq8vWhV0Z8dX83FdX1BzX4JX/v9YsKP2ieGklq:5tK+Zlim0nltdT1BD45X+iA3tnN7
                                                                                                                                                                                                                                  MD5:BBA59A5886F48DCEC5CEFDB689D36880
                                                                                                                                                                                                                                  SHA1:8207DE6AB5F7EC6077506ED3AE2EEA3AB35C5FAE
                                                                                                                                                                                                                                  SHA-256:F66F0F161B55571CC52167427C050327D4DB98AD58C6589FF908603CD53447F0
                                                                                                                                                                                                                                  SHA-512:D071D97E6773FC22ABCCE3C8BE133E0FDA40C385234FEB23F69C84ABB9042E319D6891BD9CA65F2E0A048E6F374DB91E8880DCD9711A86B79A3A058517A3DBFA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Hong_Kong) {. {-9223372036854775808 27402 0 LMT}. {-2056693002 28800 0 HKT}. {-907389000 32400 1 HKST}. {-891667800 28800 0 HKT}. {-884246400 32400 0 JST}. {-766746000 28800 0 HKT}. {-747981000 32400 1 HKST}. {-728544600 28800 0 HKT}. {-717049800 32400 1 HKST}. {-694503000 28800 0 HKT}. {-683785800 32400 1 HKST}. {-668064600 28800 0 HKT}. {-654755400 32400 1 HKST}. {-636615000 28800 0 HKT}. {-623305800 32400 1 HKST}. {-605165400 28800 0 HKT}. {-591856200 32400 1 HKST}. {-573715800 28800 0 HKT}. {-559801800 32400 1 HKST}. {-542352600 28800 0 HKT}. {-528352200 32400 1 HKST}. {-510211800 28800 0 HKT}. {-498112200 32400 1 HKST}. {-478762200 28800 0 HKT}. {-466662600 32400 1 HKST}. {-446707800 28800 0 HKT}. {-435213000 32400 1 HKST}. {-415258200 28800 0 HKT}. {-403158600 32400 1 HKST}. {-383808600 28800 0 HKT}. {-371709000 32400 1 HKST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1528
                                                                                                                                                                                                                                  Entropy (8bit):3.661748285763298
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQxEecP9NQwOkN/DN9yinNQHhNY0NVgN8wNy7nNA8eZN0vNb7NBN5pNUckNBe/v9:5MjQwJ/pMiNQXYGVy8iy7NA8ev0VbxX3
                                                                                                                                                                                                                                  MD5:6CF9D198D7CC1F0E16DDFE91A6B4A1A5
                                                                                                                                                                                                                                  SHA1:D1DEE309E479271CDC3A306272CF4D94367EC68A
                                                                                                                                                                                                                                  SHA-256:7E189D7937E5B41CD94AB5208E40C645BE678F2A4F4B02EE1305595E5296E3D0
                                                                                                                                                                                                                                  SHA-512:56488F1DD1C694457FC7F8B13550B3D2B3BC737241E311783135115E2BD585FDD083A5146488A121BC02CC1F05EF40C05A88EED1AF391FB9E4653C1F25CC4AF7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Hovd) {. {-9223372036854775808 21996 0 LMT}. {-2032927596 21600 0 +06}. {252439200 25200 0 +07}. {417978000 28800 1 +07}. {433785600 25200 0 +07}. {449600400 28800 1 +07}. {465321600 25200 0 +07}. {481050000 28800 1 +07}. {496771200 25200 0 +07}. {512499600 28800 1 +07}. {528220800 25200 0 +07}. {543949200 28800 1 +07}. {559670400 25200 0 +07}. {575398800 28800 1 +07}. {591120000 25200 0 +07}. {606848400 28800 1 +07}. {622569600 25200 0 +07}. {638298000 28800 1 +07}. {654624000 25200 0 +07}. {670352400 28800 1 +07}. {686073600 25200 0 +07}. {701802000 28800 1 +07}. {717523200 25200 0 +07}. {733251600 28800 1 +07}. {748972800 25200 0 +07}. {764701200 28800 1 +07}. {780422400 25200 0 +07}. {796150800 28800 1 +07}. {811872000 25200 0 +07}. {828205200 28800 1 +07}. {843926400 25200 0 +07}. {859654800 28800 1 +07}. {875376000 25200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2017
                                                                                                                                                                                                                                  Entropy (8bit):3.6386982097761646
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5ykBJaTcSANEWiLwyyzLyonofMQa3go8h8PNhRHbsb0k4xiRhIsJ2sbA:BB656ofU5ARdN8
                                                                                                                                                                                                                                  MD5:E4995DD6F78F859B17952F15DB554ADC
                                                                                                                                                                                                                                  SHA1:19D4957E2A8CC17BCA7F020E4DF411F0E3AC8B49
                                                                                                                                                                                                                                  SHA-256:122FEB27760CC2CD714531CF68E6C77F8505E9CA11A147DDA649E2C98E150494
                                                                                                                                                                                                                                  SHA-512:A36B334E72C9D0854F0DE040EEEBF7B92E537F770D4EEBB1697AB9DD6AB00E678BE58A7CE2514A4667BA2B8760625C22D21AFE3AB80C5B1DBB7C10E91CDDDB3A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Irkutsk) {. {-9223372036854775808 25025 0 LMT}. {-2840165825 25025 0 IMT}. {-1575874625 25200 0 +07}. {-1247554800 28800 0 +09}. {354902400 32400 1 +09}. {370710000 28800 0 +08}. {386438400 32400 1 +09}. {402246000 28800 0 +08}. {417974400 32400 1 +09}. {433782000 28800 0 +08}. {449596800 32400 1 +09}. {465328800 28800 0 +08}. {481053600 32400 1 +09}. {496778400 28800 0 +08}. {512503200 32400 1 +09}. {528228000 28800 0 +08}. {543952800 32400 1 +09}. {559677600 28800 0 +08}. {575402400 32400 1 +09}. {591127200 28800 0 +08}. {606852000 32400 1 +09}. {622576800 28800 0 +08}. {638301600 32400 1 +09}. {654631200 28800 0 +08}. {670356000 25200 0 +08}. {670359600 28800 1 +08}. {686084400 25200 0 +07}. {695761200 28800 0 +09}. {701805600 32400 1 +09}. {717530400 28800 0 +08}. {733255200 32400 1 +09}. {748980000 28800 0 +08}. {764704800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):182
                                                                                                                                                                                                                                  Entropy (8bit):4.853387718159342
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV0XaDvFVAIgoq3XPHt2WFK4HB/8QaqXNn:SlSWB9IZaM3ymQazFVAIgoQPHt2wK4HJ
                                                                                                                                                                                                                                  MD5:7EC8D7D32DC13BE15122D8E26C55F9A2
                                                                                                                                                                                                                                  SHA1:5B07C7161F236DF34B0FA83007ECD75B6435F420
                                                                                                                                                                                                                                  SHA-256:434B8D0E3034656B3E1561615CCA192EFA62942F285CD59338313710900DB6CB
                                                                                                                                                                                                                                  SHA-512:D8F1999AF509871C0A7184CFEFB0A50C174ABDE218330D9CDC784C7599A655AD55F6F2173096EA91EE5700B978B9A94BBFCA41970206E7ADEB804D0EE03B45ED
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Istanbul)]} {. LoadTimeZoneFile Europe/Istanbul.}.set TZData(:Asia/Istanbul) $TZData(:Europe/Istanbul).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):357
                                                                                                                                                                                                                                  Entropy (8bit):4.4086954127843585
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKcr6m2OHATJesaSY4SMNkc5q/MVSSmWSyvScCAdMVSSo1CkDF4mMVt:MBp52E6mdHjkAc5aMxdSyHCQMxoRDF4d
                                                                                                                                                                                                                                  MD5:88C82B18565C27E050074AD02536D257
                                                                                                                                                                                                                                  SHA1:9A150FCD9FAA0E903D70A719D949D00D82F531E3
                                                                                                                                                                                                                                  SHA-256:BC07AE610EF38F63EFF384E0815F6F64E79C61297F1C21469B2C5F19679CEAFB
                                                                                                                                                                                                                                  SHA-512:29152E0359BC0FB8648BC959DE01D0BCCD17EB928AE000FF77958E7F00FF7D65BFD2C740B438E114D53ABA260B7855B2695EF7C0484850A77FFF34F7A0B255CC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Jakarta) {. {-9223372036854775808 25632 0 LMT}. {-3231299232 25632 0 BMT}. {-1451719200 26400 0 +0720}. {-1172906400 27000 0 +0730}. {-876641400 32400 0 +09}. {-766054800 27000 0 +0730}. {-683883000 28800 0 +08}. {-620812800 27000 0 +0730}. {-189415800 25200 0 WIB}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):205
                                                                                                                                                                                                                                  Entropy (8bit):4.7830039894710366
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKcjm2OHG4YVkcfvScCvowkVcrd1CV4zvhL:MBp52omdHNYacfHCvop2BMVkV
                                                                                                                                                                                                                                  MD5:3C073BD9DFD2C4F9BC95C8A94652FF5D
                                                                                                                                                                                                                                  SHA1:F4084CDFC025B3A21092DE18DD8ECAFCA5F0EBBB
                                                                                                                                                                                                                                  SHA-256:82FC06E73477EBB50C894244C91E613BF3551053359798F42F2F2C913730A470
                                                                                                                                                                                                                                  SHA-512:7E79E4425A0D855AAE8DCF5C7196AABE8E75D92CD9B65C61B82B31B29395D4A5F2D8B1E90454037753D03A1BDDE44E8F15D7E999E65C49BE8E8F8A2B2C4EECD0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Jayapura) {. {-9223372036854775808 33768 0 LMT}. {-1172913768 32400 0 +09}. {-799491600 34200 0 +0930}. {-189423000 32400 0 WIT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7690
                                                                                                                                                                                                                                  Entropy (8bit):3.684387169764595
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:GzmnxfFtWR8fKnG/QvW+tCE5nfclzdVYi8x6PxGtv2TiGuyLsbAicBnKqXRGlGrz:0mKivDivbOKWKwX5BrAZp0
                                                                                                                                                                                                                                  MD5:4C37DF27AB1E906CC624A62288847BA8
                                                                                                                                                                                                                                  SHA1:BE690D3958A4A6722ABDF047BF22ACEC8B6D6AFE
                                                                                                                                                                                                                                  SHA-256:F10DF7378FF71EDA45E8B1C007A280BBD4629972D12EAB0C6BA7623E98AAFA17
                                                                                                                                                                                                                                  SHA-512:B14F5FB330078A564796114FA6804EA12CE0AD6B2DF6D871FF6E7B416425B12FFD6B4E8511FCD55609FBCE95C8EDFF1E14B1C8C505F4B5B66F47EA52FD53F307
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Jerusalem) {. {-9223372036854775808 8454 0 LMT}. {-2840149254 8440 0 JMT}. {-1641003640 7200 0 IST}. {-933645600 10800 1 IDT}. {-857358000 7200 0 IST}. {-844300800 10800 1 IDT}. {-825822000 7200 0 IST}. {-812685600 10800 1 IDT}. {-794199600 7200 0 IST}. {-779853600 10800 1 IDT}. {-762656400 7200 0 IST}. {-748310400 10800 1 IDT}. {-731127600 7200 0 IST}. {-681962400 14400 1 IDDT}. {-673243200 10800 1 IDT}. {-667962000 7200 0 IST}. {-652327200 10800 1 IDT}. {-636426000 7200 0 IST}. {-622087200 10800 1 IDT}. {-608947200 7200 0 IST}. {-591847200 10800 1 IDT}. {-572486400 7200 0 IST}. {-558576000 10800 1 IDT}. {-542851200 7200 0 IST}. {-527731200 10800 1 IDT}. {-514425600 7200 0 IST}. {-490845600 10800 1 IDT}. {-482986800 7200 0 IST}. {-459475200 10800 1 IDT}. {-451537200 7200 0 IST}. {-428551200 10800 1 IDT}. {-418262400 7200 0 IST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.804360783547797
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKTwkXGm2OHodFxsYvXgVHURRNVsRYvFFqdj/cXHFOVRWh:SlSWB9X52wKTEm2OHoH+YPgVHURbSQF9
                                                                                                                                                                                                                                  MD5:9A8CCA0B4337CB6FA15BF1A4F01F6C22
                                                                                                                                                                                                                                  SHA1:A4C72FC1EF6EEBDBB5C8C698BCB298DFB5061726
                                                                                                                                                                                                                                  SHA-256:4F266D90C413FA44DFCA5BE13E45C00428C694AC662CB06F2451CC3FF08E080F
                                                                                                                                                                                                                                  SHA-512:E8074AA0D8B15EE33D279C97A01FF69451A99C7711FFD66B3E9B6B6B021DE957A63F6B747C7A63E3F3C1241E0A2687D81E780D6B54228EE6B7EB9040D7F06A60
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Kabul) {. {-9223372036854775808 16608 0 LMT}. {-2524538208 14400 0 +04}. {-788932800 16200 0 +0430}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1989
                                                                                                                                                                                                                                  Entropy (8bit):3.6993158455985338
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ+3e8/HklxL7/Fpd2kNNxLcULBQdHl2yYvpQ62itgUiRrn5d6kGFF6UERWkBUHA:5c/HezFvpchKvW62XPdXJMwT3Lea
                                                                                                                                                                                                                                  MD5:496BD39D36218DF67279DA8DE9C7457B
                                                                                                                                                                                                                                  SHA1:8AE6E5CF7E1E693D11A112B75A0D24A135E94487
                                                                                                                                                                                                                                  SHA-256:6B757333C12F2BFE782258D7E9126ECE0E62696EF9C24B2955A791145D6780E9
                                                                                                                                                                                                                                  SHA-512:BADBF7893825F6C7053A23A7AA11B45A2EDBECC4580695BB6B8E568B7FFE5ED72BF61019F3CB6D7B8E663ACAF099F26E266450EC03F3C6B2F8E34BA0D12D100A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Kamchatka) {. {-9223372036854775808 38076 0 LMT}. {-1487759676 39600 0 +11}. {-1247569200 43200 0 +13}. {354888000 46800 1 +13}. {370695600 43200 0 +12}. {386424000 46800 1 +13}. {402231600 43200 0 +12}. {417960000 46800 1 +13}. {433767600 43200 0 +12}. {449582400 46800 1 +13}. {465314400 43200 0 +12}. {481039200 46800 1 +13}. {496764000 43200 0 +12}. {512488800 46800 1 +13}. {528213600 43200 0 +12}. {543938400 46800 1 +13}. {559663200 43200 0 +12}. {575388000 46800 1 +13}. {591112800 43200 0 +12}. {606837600 46800 1 +13}. {622562400 43200 0 +12}. {638287200 46800 1 +13}. {654616800 43200 0 +12}. {670341600 39600 0 +12}. {670345200 43200 1 +12}. {686070000 39600 0 +11}. {695746800 43200 0 +13}. {701791200 46800 1 +13}. {717516000 43200 0 +12}. {733240800 46800 1 +13}. {748965600 43200 0 +12}. {764690400 46800 1 +13}. {780415200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):441
                                                                                                                                                                                                                                  Entropy (8bit):4.32891547054552
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52SmdH35S6DvjRQ+vjjEn6S7Pictk6a2iW6oNl:cQSe3pjRQ+jjE6S7lTh
                                                                                                                                                                                                                                  MD5:7A7CFCB7273FCAE33F77048F225BBBBD
                                                                                                                                                                                                                                  SHA1:44701B91CBC61FCAC8EEB6E67BCCA0403E9FDD7E
                                                                                                                                                                                                                                  SHA-256:9F8C46E5AC4DF691DDCB13C853660915C94316E73F74DD36AF889D5137F1761B
                                                                                                                                                                                                                                  SHA-512:44D5A0656032D61152C98B92E3ACA88197A73D87E2D0E8853D6A0E430BDF9290D3B718F9E5864840A6FFA59CDC0D4D47BCEE0471F176E62A05C1083CB35BEBB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Karachi) {. {-9223372036854775808 16092 0 LMT}. {-1988166492 19800 0 +0530}. {-862637400 23400 1 +0630}. {-764145000 19800 0 +0530}. {-576135000 18000 0 +05}. {38775600 18000 0 PKT}. {1018119600 21600 1 PKST}. {1033840800 18000 0 PKT}. {1212260400 21600 1 PKST}. {1225476000 18000 0 PKT}. {1239735600 21600 1 PKST}. {1257012000 18000 0 PKT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):169
                                                                                                                                                                                                                                  Entropy (8bit):4.920527043039276
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8s4YkdVAIgNrMvN2WFKu3e2WFKjvn:SlSWB9IZaM3yMGdVAIgWvN2wKulwKjvn
                                                                                                                                                                                                                                  MD5:9A66108527388564A9FBDB87D586105F
                                                                                                                                                                                                                                  SHA1:945E043A3CC45A4654C2D745A48E1D15F80A3CB5
                                                                                                                                                                                                                                  SHA-256:E2965AF4328FB065A82E8A21FF342C29A5942C2EDD304CE1C9087A23A91B65E1
                                                                                                                                                                                                                                  SHA-512:C3985D972AFB27E194CBE117E6CF8C45AA5A1B6504133FF85D52E8024387133D11F9EE7238FF87DC1D96F140B9467E6DB3F99B0B98299E6782A643288ABD3308
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Urumqi)]} {. LoadTimeZoneFile Asia/Urumqi.}.set TZData(:Asia/Kashgar) $TZData(:Asia/Urumqi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.8475287330512495
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKXIi7mFSXGm2OHF+VT5vUQKwMTXvv6QzFrRk8P4VvWVQC:SlSWB9X52wKYgyJm2OH0T5RNMzvSQhR5
                                                                                                                                                                                                                                  MD5:FEFB0E2021110BC9175AC505536BDE12
                                                                                                                                                                                                                                  SHA1:8366110D91C7EA929DB300871DDC70808D458F90
                                                                                                                                                                                                                                  SHA-256:C4E46CE4385C676F5D7AC4B123C42F153F7B3F3E9F434698E8D56E1907A9B7C9
                                                                                                                                                                                                                                  SHA-512:F8F9EE0B8648154B3E3BEF192C58F2415475422BED139F20FD3D3EF253E8137CBB39AB769704AB1F20EE03B398402BC5B4A3E55BE284D1785F347B951FECEF62
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Kathmandu) {. {-9223372036854775808 20476 0 LMT}. {-1577943676 19800 0 +0530}. {504901800 20700 0 +0545}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.786408960928606
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8yIi7VyVAIgN1AIilHt2WFKSiZ1/2WFKXIi7v:SlSWB9IZaM3y7gVyVAIg5M2wKSg1/2wm
                                                                                                                                                                                                                                  MD5:A30FEA461B22B2CB3A67A616E3AE08FD
                                                                                                                                                                                                                                  SHA1:F368B215E15F6F518AEBC92289EE703DCAE849A1
                                                                                                                                                                                                                                  SHA-256:1E2A1569FE432CDA75C64FA55E24CA6F938C1C72C15FBB280D5B04F6C5E9AD69
                                                                                                                                                                                                                                  SHA-512:4F3D0681791C23EF19AFF239D2932D2CE1C991406F6DC8E313C083B5E03D806D26337ED2477700596D9A9F4FB1B7FC4A551F897A2A88CB7253CC7F863E586F03
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Kathmandu)]} {. LoadTimeZoneFile Asia/Kathmandu.}.set TZData(:Asia/Katmandu) $TZData(:Asia/Kathmandu).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2046
                                                                                                                                                                                                                                  Entropy (8bit):3.6162520408317844
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQNobe1I6oziDpiKXtyiyzilUBinUijiRziiiaSiYzYWk2HgQiMhNIziPiRikiA/:5NoV9InX4n7m84nPIzOtVEChbmAPD6
                                                                                                                                                                                                                                  MD5:0AB1CB51373021D2929AD3BB6A6A7B36
                                                                                                                                                                                                                                  SHA1:6A58A13DE2479D7C07DA574A2850DB5479F42106
                                                                                                                                                                                                                                  SHA-256:7C282AFCBC654495AD174C5679C0FDA9C65DED557389648F924E809E337DF6A5
                                                                                                                                                                                                                                  SHA-512:E865073DF7273319ADE90C0520D843C636679ACFF1FEEC4C62B85AB7458393A71EAAE32F507D90863BE4018212B497E41EFC7EA684DF821A0D4FF1A9895FDCD8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Khandyga) {. {-9223372036854775808 32533 0 LMT}. {-1579424533 28800 0 +08}. {-1247558400 32400 0 +10}. {354898800 36000 1 +10}. {370706400 32400 0 +09}. {386434800 36000 1 +10}. {402242400 32400 0 +09}. {417970800 36000 1 +10}. {433778400 32400 0 +09}. {449593200 36000 1 +10}. {465325200 32400 0 +09}. {481050000 36000 1 +10}. {496774800 32400 0 +09}. {512499600 36000 1 +10}. {528224400 32400 0 +09}. {543949200 36000 1 +10}. {559674000 32400 0 +09}. {575398800 36000 1 +10}. {591123600 32400 0 +09}. {606848400 36000 1 +10}. {622573200 32400 0 +09}. {638298000 36000 1 +10}. {654627600 32400 0 +09}. {670352400 28800 0 +09}. {670356000 32400 1 +09}. {686080800 28800 0 +08}. {695757600 32400 0 +10}. {701802000 36000 1 +10}. {717526800 32400 0 +09}. {733251600 36000 1 +10}. {748976400 32400 0 +09}. {764701200 36000 1 +10}. {780426000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):324
                                                                                                                                                                                                                                  Entropy (8bit):4.554598325373998
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKvCm2OHEX3gYLXdUvvVQLpUFGZjSVVFJGTNsR/tckVVFJGTL/FG/+d:MBp523CmdHNYjWXVQtUEZjAJGJs55vJg
                                                                                                                                                                                                                                  MD5:FABB53074E1D767952C664BBA02E8975
                                                                                                                                                                                                                                  SHA1:36D2D438FEEBF585D7A0B546647C08B63A582EA1
                                                                                                                                                                                                                                  SHA-256:DAB02F68D5EEA0DAC6A2BBB7D12930E1B4DA62EBAEC7DE35C0AA55F72CCFF139
                                                                                                                                                                                                                                  SHA-512:E178779CE31F8D16DFEC5F71F228BCB05FDA1939B1BCE204C40B14904682283BDC99F27B662E3995EEEE607D0E8C70BE3CE3DF6EAD355399566CF360D5EC9E70
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Kolkata) {. {-9223372036854775808 21208 0 LMT}. {-3645237208 21200 0 HMT}. {-3155694800 19270 0 MMT}. {-2019705670 19800 0 IST}. {-891581400 23400 1 +0630}. {-872058600 19800 0 IST}. {-862637400 23400 1 +0630}. {-764145000 19800 0 IST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1991
                                                                                                                                                                                                                                  Entropy (8bit):3.6170298534050245
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5Mi17A9/IJ4vQayW+dRvV8YzXJIq79Af3AuyqM7FfiC/LIcy9zU9Muq2PIX/9sC/:hjFRRCfQucXsNN0On
                                                                                                                                                                                                                                  MD5:83333A0E3E9810621A8BADA29B04F256
                                                                                                                                                                                                                                  SHA1:CDC375C93E7F3019562DE7CE1D9EE2776FE7FE9E
                                                                                                                                                                                                                                  SHA-256:00A9E8DDDC4314F7271F7490001ABD29B6F5EAEB9080645911FF5DA8BD7F671C
                                                                                                                                                                                                                                  SHA-512:08913E002C7D3D54F0E09029C70A0F2D18636F6F52B12F10593BECF732F40E180780D4C6127E0A3B321EAF54AF660A48E8C3E29A161B6ED6E0E46C06BBD309D6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Krasnoyarsk) {. {-9223372036854775808 22286 0 LMT}. {-1577513486 21600 0 +06}. {-1247551200 25200 0 +08}. {354906000 28800 1 +08}. {370713600 25200 0 +07}. {386442000 28800 1 +08}. {402249600 25200 0 +07}. {417978000 28800 1 +08}. {433785600 25200 0 +07}. {449600400 28800 1 +08}. {465332400 25200 0 +07}. {481057200 28800 1 +08}. {496782000 25200 0 +07}. {512506800 28800 1 +08}. {528231600 25200 0 +07}. {543956400 28800 1 +08}. {559681200 25200 0 +07}. {575406000 28800 1 +08}. {591130800 25200 0 +07}. {606855600 28800 1 +08}. {622580400 25200 0 +07}. {638305200 28800 1 +08}. {654634800 25200 0 +07}. {670359600 21600 0 +07}. {670363200 25200 1 +07}. {686088000 21600 0 +06}. {695764800 25200 0 +08}. {701809200 28800 1 +08}. {717534000 25200 0 +07}. {733258800 28800 1 +08}. {748983600 25200 0 +07}. {764708400 28800 1 +08}. {7804332
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):362
                                                                                                                                                                                                                                  Entropy (8bit):4.404454529095857
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wK1NLm2OHrPmdXiWOb/MVSYv/1MesF5X8dSMd0dMVSSm8kvScCvCIMY:MBp52PLmdHrPdDTMF/wFZMxcHClMxi
                                                                                                                                                                                                                                  MD5:B5FC8D431304F5C1ADF7D0B237DA5A52
                                                                                                                                                                                                                                  SHA1:79FC3057CD88E4DF71421AD52C34E0127FBD6FDA
                                                                                                                                                                                                                                  SHA-256:138912D754FBA8A1306063CCE897218972A4B0976EDDEC5C8E69A7965B0CD198
                                                                                                                                                                                                                                  SHA-512:27DC64B43958814E1A935D817CCFE7ADE8E6E6A778E27E391683FC491764EB77774A3D4A871C4E83BBA43FF8BA2383CBB8CC2D4F1FEB1AE063735C95651865E9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Kuala_Lumpur) {. {-9223372036854775808 24406 0 LMT}. {-2177477206 24925 0 SMT}. {-2038200925 25200 0 +07}. {-1167634800 26400 1 +0720}. {-1073028000 26400 0 +0720}. {-894180000 27000 0 +0730}. {-879665400 32400 0 +09}. {-767005200 27000 0 +0730}. {378664200 28800 0 +08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):646
                                                                                                                                                                                                                                  Entropy (8bit):3.99554344665026
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52HLKmdHXXUBMxoWFMcDBMxkT9r5N2Xhf7JSX3lzHC3:cQHLKeHUzaMcDBkkN5N2XV7Ja3hi3
                                                                                                                                                                                                                                  MD5:2F27D1377C9EBBACDC260A50C195BDBB
                                                                                                                                                                                                                                  SHA1:397B8714F2C909A8EB88A7A1F4A1AEA0A5B8E80E
                                                                                                                                                                                                                                  SHA-256:519FDD455107270E6F8F3848C214D3D44CC1465B7B3E375318857D4A9093E1C0
                                                                                                                                                                                                                                  SHA-512:E4583E6C3FEB5ADAD41827D8ADCD7DA34CCB92D2B62B9D7C3D59F76719B9EE2FE44697CFD00943D9E2A4DBAEB929C97A1FF520FFF62EB6829C88D71EC8C51993
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Kuching) {. {-9223372036854775808 26480 0 LMT}. {-1383463280 27000 0 +0730}. {-1167636600 28800 0 +08}. {-1082448000 30000 1 +08}. {-1074586800 28800 0 +08}. {-1050825600 30000 1 +08}. {-1042964400 28800 0 +08}. {-1019289600 30000 1 +08}. {-1011428400 28800 0 +08}. {-987753600 30000 1 +08}. {-979892400 28800 0 +08}. {-956217600 30000 1 +08}. {-948356400 28800 0 +08}. {-924595200 30000 1 +08}. {-916734000 28800 0 +08}. {-893059200 30000 1 +08}. {-885198000 28800 0 +08}. {-879667200 32400 0 +09}. {-767005200 28800 0 +08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):168
                                                                                                                                                                                                                                  Entropy (8bit):4.82804794783422
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8t1zVAIgNsM1E2WFKdQWFK81S:SlSWB9IZaM3yN1zVAIgaM1E2wKdQwK8c
                                                                                                                                                                                                                                  MD5:6D6109F6EC1E12881C60EC44AAEB772B
                                                                                                                                                                                                                                  SHA1:B5531BEAC1C07DA57A901D0A48F4E1AC03F07467
                                                                                                                                                                                                                                  SHA-256:67BB9F159C752C744AC6AB26BBC0688CF4FA94C58C23B2B49B871CAA8774FC5D
                                                                                                                                                                                                                                  SHA-512:B0624B9F936E5C1392B7EBB3190D7E97EAE96647AB965BB9BE045D2C3082B1C7E48FF89A7B57FD3475D018574E7294D45B068C555A43AAEDFD65AC5C5C5D0A5B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Riyadh)]} {. LoadTimeZoneFile Asia/Riyadh.}.set TZData(:Asia/Kuwait) $TZData(:Asia/Riyadh).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):164
                                                                                                                                                                                                                                  Entropy (8bit):4.729350272507574
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8PpVAIgNz5YF2WFKf+WFKjn:SlSWB9IZaM3yxVAIgLYF2wKGwKjn
                                                                                                                                                                                                                                  MD5:DB6155900D4556EE7B3089860AD5C4E3
                                                                                                                                                                                                                                  SHA1:708E4AE427C8BAF589509F4330C389EE55C1D514
                                                                                                                                                                                                                                  SHA-256:8264648CF1EA3E352E13482DE2ACE70B97FD37FBB1F28F70011561CFCBF533EA
                                                                                                                                                                                                                                  SHA-512:941D52208FABB634BABCD602CD468F2235199813F4C1C5AB82A453E8C4CE4543C1CE3CBDB9D035DB039CFFDBC94D5D0F9D29363442E2458426BDD52ECDF7C3C5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Macau)]} {. LoadTimeZoneFile Asia/Macau.}.set TZData(:Asia/Macao) $TZData(:Asia/Macau).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2141
                                                                                                                                                                                                                                  Entropy (8bit):3.8815104664173843
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5o89px1D/MG/B/j/gf/d/iM/MW/C/2/Y/yf/9/y/l/v1EG/vFw/veE/K/Z/D/U/h:/p7DD5L2lRkWqOA6fVKdXqGXFwXeECRK
                                                                                                                                                                                                                                  MD5:DC20959BDB02CF86A33CE2C82D4D9853
                                                                                                                                                                                                                                  SHA1:90FC1820FA0E3B1C4BD2158185F95DCD1AA271D6
                                                                                                                                                                                                                                  SHA-256:6263F011537DB5CAF6B09F16D55DADE527A475AEE04F1BA38A75D13E9D125355
                                                                                                                                                                                                                                  SHA-512:8C6D0FA9584595B93A563D60387520CE9B28595C2C3880004275BAE66313A7606379646D27FB5EB91EC8D96D3B23959E2F9E3ABC97C203FD76E1DCC5ABB64374
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Macau) {. {-9223372036854775808 27250 0 LMT}. {-2056692850 28800 0 CST}. {-884509200 32400 0 +09}. {-873280800 36000 1 +09}. {-855918000 32400 0 +09}. {-841744800 36000 1 +09}. {-828529200 32400 0 +10}. {-765363600 28800 0 CT}. {-747046800 32400 1 CDT}. {-733827600 28800 0 CST}. {-716461200 32400 1 CDT}. {-697021200 28800 0 CST}. {-683715600 32400 1 CDT}. {-667990800 28800 0 CST}. {-654771600 32400 1 CDT}. {-636627600 28800 0 CST}. {-623322000 32400 1 CDT}. {-605178000 28800 0 CST}. {-591872400 32400 1 CDT}. {-573642000 28800 0 CST}. {-559818000 32400 1 CDT}. {-541674000 28800 0 CST}. {-528368400 32400 1 CDT}. {-510224400 28800 0 CST}. {-498128400 32400 1 CDT}. {-478774800 28800 0 CST}. {-466678800 32400 1 CDT}. {-446720400 28800 0 CST}. {-435229200 32400 1 CDT}. {-415258200 28800 0 CST}. {-403158600 32400 1 CDT}. {-383808600 2880
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2016
                                                                                                                                                                                                                                  Entropy (8bit):3.6746770806664517
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQmecGdvBOCdwdVdptQvMCTP2rF1gCzlODU9xE305r/CXVWWHs/gSNkna:5tvBHwRw/P2rFGAlODU9PZUEWQgmka
                                                                                                                                                                                                                                  MD5:18E80309362762B7757629B51F28AF99
                                                                                                                                                                                                                                  SHA1:502C70F24251BC062785A9349E6204CB719BF932
                                                                                                                                                                                                                                  SHA-256:6493D629E3CD4DB555A547F942BCCB4FFC7BBF7298FFBF9503F6DE3177ADBAC9
                                                                                                                                                                                                                                  SHA-512:C477E0DCF4E78E57E075FB5CAA45E70D4864EDFC40EAC2DD43D80F71408836E5BD468B15EB34B95020F2DB6CE531D67F076EF8EED4833ADEC1F6D37B2200CC84
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Magadan) {. {-9223372036854775808 36192 0 LMT}. {-1441188192 36000 0 +10}. {-1247565600 39600 0 +12}. {354891600 43200 1 +12}. {370699200 39600 0 +11}. {386427600 43200 1 +12}. {402235200 39600 0 +11}. {417963600 43200 1 +12}. {433771200 39600 0 +11}. {449586000 43200 1 +12}. {465318000 39600 0 +11}. {481042800 43200 1 +12}. {496767600 39600 0 +11}. {512492400 43200 1 +12}. {528217200 39600 0 +11}. {543942000 43200 1 +12}. {559666800 39600 0 +11}. {575391600 43200 1 +12}. {591116400 39600 0 +11}. {606841200 43200 1 +12}. {622566000 39600 0 +11}. {638290800 43200 1 +12}. {654620400 39600 0 +11}. {670345200 36000 0 +11}. {670348800 39600 1 +11}. {686073600 36000 0 +10}. {695750400 39600 0 +12}. {701794800 43200 1 +12}. {717519600 39600 0 +11}. {733244400 43200 1 +12}. {748969200 39600 0 +11}. {764694000 43200 1 +12}. {780418800 3
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):234
                                                                                                                                                                                                                                  Entropy (8bit):4.682322181661182
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKCm2OHUVRYQTLQTvUfkc3gEkNHkH8vScCxWv:MBp526mdHsrTD8cQJl7HCMv
                                                                                                                                                                                                                                  MD5:87D843314195847B6E4117119A1F701C
                                                                                                                                                                                                                                  SHA1:E51DC3A0BF20B09D8745AC682B4869A031A0A515
                                                                                                                                                                                                                                  SHA-256:22046165D40C8A553FE22A28E127514DF469E79581E0746101816A973456029D
                                                                                                                                                                                                                                  SHA-512:D241803442876A59170C1A90ACC66DEAF169CBF9B8CD7DE964BEF02D222B1D07511E241D441C3DA6AE7A7D1AAC1F4EDB5A21655C2923A3807BBFA8630071BCE9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Makassar) {. {-9223372036854775808 28656 0 LMT}. {-1577951856 28656 0 MMT}. {-1172908656 28800 0 +08}. {-880272000 32400 0 +09}. {-766054800 28800 0 WITA}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):406
                                                                                                                                                                                                                                  Entropy (8bit):4.4205762929520755
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52G4JmdHnzZBPE6JwucQzX4rjJbmJtKn:cQG4Je11RbXzXqQ+
                                                                                                                                                                                                                                  MD5:3A833BF91AFE7FABBA98D11F29D84EAA
                                                                                                                                                                                                                                  SHA1:1622BEF54A12DE163B77309A0B7AF1C38AA6324B
                                                                                                                                                                                                                                  SHA-256:665E07B7A01E8A9D04B76B74B2EA0D11BDFC0BE6CA855DFDDBB5F9A6C9A97E90
                                                                                                                                                                                                                                  SHA-512:DFABB558CE2A8B96A976DD3B45B78CECE3633D51EE67F24E5AD59C7CF388538C5560EC133C60C3F0AFE8C68D88B1C05A12608A0408ACECBEEC38A84E3DC972FC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Manila) {. {-9223372036854775808 -57360 0 LMT}. {-3944621040 29040 0 LMT}. {-2229321840 28800 0 PST}. {-1046678400 32400 1 PDT}. {-1038733200 28800 0 PST}. {-873273600 32400 0 JST}. {-794221200 28800 0 PST}. {-496224000 32400 1 PDT}. {-489315600 28800 0 PST}. {259344000 32400 1 PDT}. {275151600 28800 0 PST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):165
                                                                                                                                                                                                                                  Entropy (8bit):4.754394427749078
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8DhVAIgN6Sn62WFKvE+H+WFKQo:SlSWB9IZaM3yjhVAIgMS62wKLewKQo
                                                                                                                                                                                                                                  MD5:5D8EBBC297A2258C352BC80535B7F7F1
                                                                                                                                                                                                                                  SHA1:684CAF480AF5B8A98D9AD1A1ECD4E07434F36875
                                                                                                                                                                                                                                  SHA-256:4709F2DA036EB96FB7B6CC40859BF59F1146FE8D3A7AFE326FBA3B8CB68049CE
                                                                                                                                                                                                                                  SHA-512:FD67E920D3D5FE69AF35535A8BBD2791204C6B63050EFECC0857F24D393712C4BC4660EA0A350D2A4DDA144073413BE013D71D73E6F3638CA30480541F9731FA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Dubai)]} {. LoadTimeZoneFile Asia/Dubai.}.set TZData(:Asia/Muscat) $TZData(:Asia/Dubai).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7368
                                                                                                                                                                                                                                  Entropy (8bit):3.620699686510499
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:EPByq7VKviW/naKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtOEA:EPFi//uh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:21EEEC6314C94D1476C2E79BBACFEB77
                                                                                                                                                                                                                                  SHA1:2C9805CD01C84D446CBDB90B9542CB24CCDE4E39
                                                                                                                                                                                                                                  SHA-256:7AAB1AC67D96287EE468608506868707B28FCD27A8F53128621801DCF0122162
                                                                                                                                                                                                                                  SHA-512:D4B0A0E60B102E10E03CF5BD07C5783E908D5E7079B646177C57C30D67B44C114EFF4DCFC71AF8441D67BD5A351068FBFFD8C5E08F06F1D69946B3EA7D49FC2D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Nicosia) {. {-9223372036854775808 8008 0 LMT}. {-1518920008 7200 0 EET}. {166572000 10800 1 EEST}. {182293200 7200 0 EET}. {200959200 10800 1 EEST}. {213829200 7200 0 EET}. {228866400 10800 1 EEST}. {243982800 7200 0 EET}. {260316000 10800 1 EEST}. {276123600 7200 0 EET}. {291765600 10800 1 EEST}. {307486800 7200 0 EET}. {323820000 10800 1 EEST}. {338936400 7200 0 EET}. {354664800 10800 1 EEST}. {370386000 7200 0 EET}. {386114400 10800 1 EEST}. {401835600 7200 0 EET}. {417564000 10800 1 EEST}. {433285200 7200 0 EET}. {449013600 10800 1 EEST}. {465339600 7200 0 EET}. {481068000 10800 1 EEST}. {496789200 7200 0 EET}. {512517600 10800 1 EEST}. {528238800 7200 0 EET}. {543967200 10800 1 EEST}. {559688400 7200 0 EET}. {575416800 10800 1 EEST}. {591138000 7200 0 EET}. {606866400 10800 1 EEST}. {622587600 7200 0 EET}. {638316000 10800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1992
                                                                                                                                                                                                                                  Entropy (8bit):3.626746433557725
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5qi17A9/IJ4vQayW+dRvV8YzXJIq79Af3AuyqM7FfiC/LIcy9zU9Muq2PIX/9sCP:bjFRRCfQucXsNN0OX
                                                                                                                                                                                                                                  MD5:11B80F2A9B7B090DD146BD97E9DB7D43
                                                                                                                                                                                                                                  SHA1:4A2886799A50D031D79C935261B50363AA27768A
                                                                                                                                                                                                                                  SHA-256:4018CE273BC4D02057F66A4715626F0E4D8C7050391C00BB5AE054B4DA8DE2F8
                                                                                                                                                                                                                                  SHA-512:1F1650C1DBC3A171FF30C7657D7F99963A0C8D63B85460B45DE75AFABECE28F2A51236FB71DFF3EE567CC58E71B88623E4880DEBD18E9E9C9E527CF97D5FE926
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Novokuznetsk) {. {-9223372036854775808 20928 0 LMT}. {-1441259328 21600 0 +06}. {-1247551200 25200 0 +08}. {354906000 28800 1 +08}. {370713600 25200 0 +07}. {386442000 28800 1 +08}. {402249600 25200 0 +07}. {417978000 28800 1 +08}. {433785600 25200 0 +07}. {449600400 28800 1 +08}. {465332400 25200 0 +07}. {481057200 28800 1 +08}. {496782000 25200 0 +07}. {512506800 28800 1 +08}. {528231600 25200 0 +07}. {543956400 28800 1 +08}. {559681200 25200 0 +07}. {575406000 28800 1 +08}. {591130800 25200 0 +07}. {606855600 28800 1 +08}. {622580400 25200 0 +07}. {638305200 28800 1 +08}. {654634800 25200 0 +07}. {670359600 21600 0 +07}. {670363200 25200 1 +07}. {686088000 21600 0 +06}. {695764800 25200 0 +08}. {701809200 28800 1 +08}. {717534000 25200 0 +07}. {733258800 28800 1 +08}. {748983600 25200 0 +07}. {764708400 28800 1 +08}. {780433
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2048
                                                                                                                                                                                                                                  Entropy (8bit):3.623418616375595
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5HNi17A9/IJ4vQayW+dRvV8YzXJIq79Af3AuyqM7F/zTXUVtrBju6waUwcTLTTWF:6jFRRCfQuozB7TQt
                                                                                                                                                                                                                                  MD5:46E5FB7DEB8041BC9A2ADC83728944A7
                                                                                                                                                                                                                                  SHA1:B5826E206EAA3E8789A0F9E4B7511CEBFD1B6764
                                                                                                                                                                                                                                  SHA-256:C241F732B9731FA141B03FF1F990556C9BF14A1B21C9757C7FF75E688908B8A0
                                                                                                                                                                                                                                  SHA-512:42B6BEEE9C15CB59C010013FE0673CB0DF46CD0AC388DF7D57DCCD54482C950F2935F8A8D7DC68CFFD184B698283589134901C9C597970D95C5B608CD160AF70
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Novosibirsk) {. {-9223372036854775808 19900 0 LMT}. {-1579476700 21600 0 +06}. {-1247551200 25200 0 +08}. {354906000 28800 1 +08}. {370713600 25200 0 +07}. {386442000 28800 1 +08}. {402249600 25200 0 +07}. {417978000 28800 1 +08}. {433785600 25200 0 +07}. {449600400 28800 1 +08}. {465332400 25200 0 +07}. {481057200 28800 1 +08}. {496782000 25200 0 +07}. {512506800 28800 1 +08}. {528231600 25200 0 +07}. {543956400 28800 1 +08}. {559681200 25200 0 +07}. {575406000 28800 1 +08}. {591130800 25200 0 +07}. {606855600 28800 1 +08}. {622580400 25200 0 +07}. {638305200 28800 1 +08}. {654634800 25200 0 +07}. {670359600 21600 0 +07}. {670363200 25200 1 +07}. {686088000 21600 0 +06}. {695764800 25200 0 +08}. {701809200 28800 1 +08}. {717534000 25200 0 +07}. {733258800 28800 1 +08}. {738090000 25200 0 +07}. {748987200 21600 0 +06}. {7647120
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1984
                                                                                                                                                                                                                                  Entropy (8bit):3.5988580260925795
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5aQyvONnwqeDinDL+8kSViqS6A+VzTXUVtrBju6waUwcTLTTW59OxJCT:IkHdiq5BzB7TQJ
                                                                                                                                                                                                                                  MD5:54E1F8C11C9CF4BF1DBCABF4AF31B7D4
                                                                                                                                                                                                                                  SHA1:3C428E50A02941B19AF2A2F1EA02763AA2C1A846
                                                                                                                                                                                                                                  SHA-256:5B9E95C813A184C969CC9808E136AD66C1231A55E66D4EE817BD2E85751C4EE9
                                                                                                                                                                                                                                  SHA-512:83DBFCC089AC902609FFFCA8E675430B9BF1EA452626E83173F83317884B6AC2620CE8AA96488ACF13445D9D1D4776EB908232BD8205B8F4F9B034A68864C9A9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Omsk) {. {-9223372036854775808 17610 0 LMT}. {-1582088010 18000 0 +05}. {-1247547600 21600 0 +07}. {354909600 25200 1 +07}. {370717200 21600 0 +06}. {386445600 25200 1 +07}. {402253200 21600 0 +06}. {417981600 25200 1 +07}. {433789200 21600 0 +06}. {449604000 25200 1 +07}. {465336000 21600 0 +06}. {481060800 25200 1 +07}. {496785600 21600 0 +06}. {512510400 25200 1 +07}. {528235200 21600 0 +06}. {543960000 25200 1 +07}. {559684800 21600 0 +06}. {575409600 25200 1 +07}. {591134400 21600 0 +06}. {606859200 25200 1 +07}. {622584000 21600 0 +06}. {638308800 25200 1 +07}. {654638400 21600 0 +06}. {670363200 18000 0 +06}. {670366800 21600 1 +06}. {686091600 18000 0 +05}. {695768400 21600 0 +07}. {701812800 25200 1 +07}. {717537600 21600 0 +06}. {733262400 25200 1 +07}. {748987200 21600 0 +06}. {764712000 25200 1 +07}. {780436800 2160
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1606
                                                                                                                                                                                                                                  Entropy (8bit):3.6164715895962876
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ3eHykSYlS7hhmSQcwqSlhJS9yiIoSBHrSLUSIYdDSVbt8i9E603CRWeZunSbOi:5FkXlkhs7bqIwIoMpqDPiBRBlL
                                                                                                                                                                                                                                  MD5:38914E248C13912E33187496C5AD9691
                                                                                                                                                                                                                                  SHA1:94C3711FC5EED22FE1929F2250208AC53DB175AC
                                                                                                                                                                                                                                  SHA-256:581AF958787971BE487B37C2D2534E58FFA085AFD0D9F0E12E0EEFF03F476E53
                                                                                                                                                                                                                                  SHA-512:8C7F21C8FCE2614181A998774E7038BAC483E502C3C31EDB0F4954E1424A0C16AD7DC5003E9533BB47CA2C06DD027E989BD696B2A74A23F686F74B8C9650BAE6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Oral) {. {-9223372036854775808 12324 0 LMT}. {-1441164324 10800 0 +03}. {-1247540400 18000 0 +05}. {354913200 21600 1 +06}. {370720800 21600 0 +06}. {386445600 18000 0 +05}. {386449200 21600 1 +05}. {402256800 18000 0 +05}. {417985200 21600 1 +05}. {433792800 18000 0 +05}. {449607600 21600 1 +05}. {465339600 18000 0 +05}. {481064400 21600 1 +05}. {496789200 18000 0 +05}. {512514000 21600 1 +05}. {528238800 18000 0 +05}. {543963600 21600 1 +05}. {559688400 18000 0 +05}. {575413200 21600 1 +05}. {591138000 18000 0 +05}. {606862800 14400 0 +04}. {606866400 18000 1 +04}. {622591200 14400 0 +04}. {638316000 18000 1 +04}. {654645600 14400 0 +04}. {670370400 18000 1 +04}. {686095200 14400 0 +04}. {701816400 14400 0 +04}. {701820000 18000 1 +04}. {717544800 14400 0 +04}. {733269600 18000 1 +04}. {748994400 14400 0 +04}. {764719200 1800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.911861786274714
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8VLYO5YFwVAIgN8ELYOAvN2WFKeHKLNM0WFKELYOun:SlSWB9IZaM3y1LewVAIgKELUvN2wKTNp
                                                                                                                                                                                                                                  MD5:754059D3B44B7D60FB3BBFC97782C6CF
                                                                                                                                                                                                                                  SHA1:6AE931805E6A42836D65E4EBC76A58BBFB3DCAF4
                                                                                                                                                                                                                                  SHA-256:2C2DBD952FDA5CC042073B538C240B11C5C8E614DD4A697E1AA4C80E458575D0
                                                                                                                                                                                                                                  SHA-512:B5AA4B51699EEAE0D9F91BBAB5B682BD84537C4E2CCE282613E1FFA1DDBE562CA487FB2F8CD006EE9DBC9EFAEFA587EC9998F0364E5C932CDB42C14319328D46
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Bangkok)]} {. LoadTimeZoneFile Asia/Bangkok.}.set TZData(:Asia/Phnom_Penh) $TZData(:Asia/Bangkok).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):356
                                                                                                                                                                                                                                  Entropy (8bit):4.428640713376822
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKT5wFJm2OHUed9xMkc5k/MVSSmCLkvScCAdMVSSo1CkDF4mMVSSmT+:MBp52L5wFJmdHFxbc5kMxvLkHCQMxoRg
                                                                                                                                                                                                                                  MD5:81C643629BB417E38A5514BBEFEF55C8
                                                                                                                                                                                                                                  SHA1:7D91E7F00A1A0B795EF3FDD1B3DD052EA2F6122C
                                                                                                                                                                                                                                  SHA-256:998DFACE4BEE8A925E88D779D6C9FB9F9010BDB68010A9CCBC0B97BB5C49D452
                                                                                                                                                                                                                                  SHA-512:1291521B74984EC03557C4DC492DB4DD1312626F61612C1F143BA482E2C32CD331647D86507D3B3721D148B2ED3CED6678123BD801DAA6B4F2D9A0C07B90575F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Pontianak) {. {-9223372036854775808 26240 0 LMT}. {-1946186240 26240 0 PMT}. {-1172906240 27000 0 +0730}. {-881220600 32400 0 +09}. {-766054800 27000 0 +0730}. {-683883000 28800 0 +08}. {-620812800 27000 0 +0730}. {-189415800 28800 0 WITA}. {567964800 25200 0 WIB}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):263
                                                                                                                                                                                                                                  Entropy (8bit):4.653238218910832
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wK8cE4Lm2OHnNdRw8vm1T0vGLucjv7:MBp520cEWmdHnNLvjuD
                                                                                                                                                                                                                                  MD5:96754BB7D98975118E86B539D8F917B4
                                                                                                                                                                                                                                  SHA1:5D366D64E08F1E9869EA2E93B5C6C5C0C5E7E3BE
                                                                                                                                                                                                                                  SHA-256:10432381A63B2101A1218D357DA2075885F061F3A60BE00A32EED4DF868E5566
                                                                                                                                                                                                                                  SHA-512:58BFFF63D40CF899304D69468949B806F00F5F2F2BE47040D5704E8C463D7B502725846933749172AF94CCD0AA894E30AD3154CC953D917AC8040B00D331124E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Pyongyang) {. {-9223372036854775808 30180 0 LMT}. {-1948782180 30600 0 KST}. {-1830414600 32400 0 JST}. {-768646800 32400 0 KST}. {1439564400 30600 0 KST}. {1525446000 32400 0 KST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):169
                                                                                                                                                                                                                                  Entropy (8bit):4.800949065138005
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKK3vFSXGm2OHPFV4YvUQKb3VvVsRYvFF5FRVGsWYAvn:SlSWB9X52wKK3vTm2OHoYRcvSQFF5FR4
                                                                                                                                                                                                                                  MD5:E70F65EBF35BE045F43456A67DEBCD34
                                                                                                                                                                                                                                  SHA1:EE5669823D60518D0AAB07A7C539B8089807D589
                                                                                                                                                                                                                                  SHA-256:B8E3F98A20BE938B9B1A6CE1CE4218751393B33E933A8F9278AA3EEECB13D2C6
                                                                                                                                                                                                                                  SHA-512:9B142D27C92C2478ED086668F8E3DC4BD8E9FDA712D8888469816B4795B5DFDD7F5F22D7BA6A31CA4E32483ABE5A5B4C7CEFC91856B09DDF651E58867FC932C9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Qatar) {. {-9223372036854775808 12368 0 LMT}. {-1577935568 14400 0 +04}. {76190400 10800 0 +03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1583
                                                                                                                                                                                                                                  Entropy (8bit):3.64822959139346
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5UXlkhs7bqIwIoMpqDS7oXbPw+bBijbbyzIr1jA:ICOgZbWM
                                                                                                                                                                                                                                  MD5:E79902C294AEFC5A3A3DCFFF4142E54F
                                                                                                                                                                                                                                  SHA1:8F9E8413C8F2D1DCF7DB74BE3AF067CBFEF2E73C
                                                                                                                                                                                                                                  SHA-256:4A254C094E4F5955E33C19E01EF2B8D5B70AC0AD08203FD105F475C8F862F28C
                                                                                                                                                                                                                                  SHA-512:3283248979FC76BE94D705013728FF206A32B8820D475C4DFC0636D2329E8FA5D251EAE5A21D9A9DC30659A6B567E73A7C614D7DA3F60025BFEA617ACE2EE597
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Qyzylorda) {. {-9223372036854775808 15712 0 LMT}. {-1441167712 14400 0 +04}. {-1247544000 18000 0 +05}. {354913200 21600 1 +06}. {370720800 21600 0 +06}. {386445600 18000 0 +05}. {386449200 21600 1 +05}. {402256800 18000 0 +05}. {417985200 21600 1 +05}. {433792800 18000 0 +05}. {449607600 21600 1 +05}. {465339600 18000 0 +05}. {481064400 21600 1 +05}. {496789200 18000 0 +05}. {512514000 21600 1 +05}. {528238800 18000 0 +05}. {543963600 21600 1 +05}. {559688400 18000 0 +05}. {575413200 21600 1 +05}. {591138000 18000 0 +05}. {606862800 21600 1 +05}. {622587600 18000 0 +05}. {638312400 21600 1 +05}. {654642000 18000 0 +05}. {670366800 14400 0 +04}. {670370400 18000 1 +04}. {701812800 18000 0 +05}. {701816400 21600 1 +05}. {717541200 18000 0 +05}. {733266000 21600 1 +05}. {748990800 18000 0 +05}. {764715600 21600 1 +05}. {780440400
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):169
                                                                                                                                                                                                                                  Entropy (8bit):4.761776859195572
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8nvwFVAIgNnEYO62WFK02KQMFfh4WFKsv:SlSWB9IZaM3yHvwFVAIgZ2wK0GEJ4wKO
                                                                                                                                                                                                                                  MD5:6135C39675BB0F7BB94756F2057382CF
                                                                                                                                                                                                                                  SHA1:EB2C51837E721776BED5F3F1F4A014BA29DA0282
                                                                                                                                                                                                                                  SHA-256:E573ADFBB9935B7D0B56FAE699160226BF3416C50EB63D8EFEB1748C4B13BF91
                                                                                                                                                                                                                                  SHA-512:BC1E7C9F1F64FF7D6A50E70E62566F385A923A475E309A321FCC03964350E427A4AEE801A20B3293A289AD67E03C86B59A674F91F34238068DA6C35BBB3B4307
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Yangon)]} {. LoadTimeZoneFile Asia/Yangon.}.set TZData(:Asia/Rangoon) $TZData(:Asia/Yangon).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):142
                                                                                                                                                                                                                                  Entropy (8bit):4.928343799484186
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFK814tXGm2OHFukevSUi9VssWYAvn:SlSWB9X52wK81Hm2OHF7ePi9V1WYAv
                                                                                                                                                                                                                                  MD5:76E7F746F8663772A350A2E2C2F680C7
                                                                                                                                                                                                                                  SHA1:698E3C80122AC7B9E6EF7A45F87898334A1A622E
                                                                                                                                                                                                                                  SHA-256:7D2FAC4F33EE0FA667AF8A2BF8257638A37CE0308038AC02C7B5BE6E1D1E5EDD
                                                                                                                                                                                                                                  SHA-512:9B1C326D3B7C89957176540AB4F856780C57C495A44F80D998A4B0C5A10F358C2F727BF160FB49D17C104B4A8EB15AC5431CCB886AC59A92E56C964D757FA3B0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Riyadh) {. {-9223372036854775808 11212 0 LMT}. {-719636812 10800 0 +03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):183
                                                                                                                                                                                                                                  Entropy (8bit):4.899371908380106
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8I65eVyVAIgN2h659Q2WFKwJ6h4WFK365ev:SlSWB9IZaM3yJAVyVAIgA4s2wKl4wKKK
                                                                                                                                                                                                                                  MD5:A978C9AD6320DA94CB15324CA82C7417
                                                                                                                                                                                                                                  SHA1:585C232F3FB2693C78C7831C1AF1DC25D6824CA7
                                                                                                                                                                                                                                  SHA-256:73E1850BB0827043024EAFA1934190413CB36EA6FE18C90EA86B9DBC1D61EEBF
                                                                                                                                                                                                                                  SHA-512:AE48BFB2A348CA992F2BCD6B1AF7495713B0526C326678309133D3271D90600624C096B4B8678AD7ECD19822E3BB24E27D12680FCA7FAA455D3CE324CE0B88ED
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Ho_Chi_Minh)]} {. LoadTimeZoneFile Asia/Ho_Chi_Minh.}.set TZData(:Asia/Saigon) $TZData(:Asia/Ho_Chi_Minh).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2044
                                                                                                                                                                                                                                  Entropy (8bit):3.636696819312369
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5i1fvBHwRw/P2rFGAlODU9HOUDEChbmAP+:gDtP2rUfDEZDV1ZP+
                                                                                                                                                                                                                                  MD5:265EF8FD8FB07585726D3054289A1C48
                                                                                                                                                                                                                                  SHA1:DDFB1197C7A7455674AA085A6B8089124EB47689
                                                                                                                                                                                                                                  SHA-256:4CCF3795EF0EF42AA09A9225370E8E1537B53A0231363077DAC385F397208669
                                                                                                                                                                                                                                  SHA-512:1ACE8C173E87530FCC809814DEA779CB09ED8A277DB3B0519E57727AD3A93F3AFAFAF0F80419A8B6A8FAC1B30600716169BEAE397E34E6BE1A18D0E31DB69B3F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Sakhalin) {. {-9223372036854775808 34248 0 LMT}. {-2031039048 32400 0 +09}. {-768560400 39600 0 +12}. {354891600 43200 1 +12}. {370699200 39600 0 +11}. {386427600 43200 1 +12}. {402235200 39600 0 +11}. {417963600 43200 1 +12}. {433771200 39600 0 +11}. {449586000 43200 1 +12}. {465318000 39600 0 +11}. {481042800 43200 1 +12}. {496767600 39600 0 +11}. {512492400 43200 1 +12}. {528217200 39600 0 +11}. {543942000 43200 1 +12}. {559666800 39600 0 +11}. {575391600 43200 1 +12}. {591116400 39600 0 +11}. {606841200 43200 1 +12}. {622566000 39600 0 +11}. {638290800 43200 1 +12}. {654620400 39600 0 +11}. {670345200 36000 0 +11}. {670348800 39600 1 +11}. {686073600 36000 0 +10}. {695750400 39600 0 +12}. {701794800 43200 1 +12}. {717519600 39600 0 +11}. {733244400 43200 1 +12}. {748969200 39600 0 +11}. {764694000 43200 1 +12}. {780418800 3
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):848
                                                                                                                                                                                                                                  Entropy (8bit):3.8621003155318263
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQtleA7NSYlS7hhmSQcwqSlhJS9yiIoSBHrSLUSIYdDS7/S5c3oSATo6SSYL:5hXlkhs7bqIwIoMpqDS7oXjSpL
                                                                                                                                                                                                                                  MD5:6E54D9946AC13DD77FDB8EA9C4FBD989
                                                                                                                                                                                                                                  SHA1:EF0A4BFD84EC369CB9581D830F20193D73187C0B
                                                                                                                                                                                                                                  SHA-256:28A76A0EAF55EEC9FE7BEFF3785FDEF8C3D93AAAA2E15EE37D861E73418AC9E4
                                                                                                                                                                                                                                  SHA-512:15522A5B85DCD54DC0143A38799A870268D74C8A26FED44D50A55C536D3738905597AE4F3F2AB767DE73A7EDBAE8FBF467A6014E2001FA03924C3F39E0361F27
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Samarkand) {. {-9223372036854775808 16073 0 LMT}. {-1441168073 14400 0 +04}. {-1247544000 18000 0 +05}. {354913200 21600 1 +06}. {370720800 21600 0 +06}. {386445600 18000 0 +05}. {386449200 21600 1 +05}. {402256800 18000 0 +05}. {417985200 21600 1 +05}. {433792800 18000 0 +05}. {449607600 21600 1 +05}. {465339600 18000 0 +05}. {481064400 21600 1 +05}. {496789200 18000 0 +05}. {512514000 21600 1 +05}. {528238800 18000 0 +05}. {543963600 21600 1 +05}. {559688400 18000 0 +05}. {575413200 21600 1 +05}. {591138000 18000 0 +05}. {606862800 21600 1 +05}. {622587600 18000 0 +05}. {638312400 21600 1 +05}. {654642000 18000 0 +05}. {670366800 21600 1 +05}. {686091600 18000 0 +05}. {694206000 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):719
                                                                                                                                                                                                                                  Entropy (8bit):4.129493275264732
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp525mdHjauvWz4aqceOcrIt04CaI8/HUYVfXzQD:cQ5edvWzJnJGIt047I8/Hp/zQD
                                                                                                                                                                                                                                  MD5:7F24687F220D3B7F3C08A1F09F86BAEF
                                                                                                                                                                                                                                  SHA1:2D96019AE5137935F7A43FCFD229645D656E21AF
                                                                                                                                                                                                                                  SHA-256:8DBBFEEDD583DBE60E88E381D511B72DDD7AE93FEB64A2F97D6CDBF6B92A0775
                                                                                                                                                                                                                                  SHA-512:BFD955BA4A284D91542D15CAE849C162D1470167D65365FF93B117D7B4361DB314ABEF5448CF5BA382002726D472FA74C3B9DD5B43CD539395FDC8241E4A0248
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Seoul) {. {-9223372036854775808 30472 0 LMT}. {-1948782472 30600 0 KST}. {-1830414600 32400 0 JST}. {-767350800 32400 0 KST}. {-498128400 30600 0 KST}. {-462702600 34200 1 KDT}. {-451733400 30600 0 KST}. {-429784200 34200 1 KDT}. {-418296600 30600 0 KST}. {-399544200 34200 1 KDT}. {-387451800 30600 0 KST}. {-368094600 34200 1 KDT}. {-356002200 30600 0 KST}. {-336645000 34200 1 KDT}. {-324552600 30600 0 KST}. {-305195400 34200 1 KDT}. {-293103000 30600 0 KST}. {-264933000 32400 0 KST}. {547578000 36000 1 KDT}. {560883600 32400 0 KST}. {579027600 36000 1 KDT}. {592333200 32400 0 KST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):887
                                                                                                                                                                                                                                  Entropy (8bit):4.102844989906348
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ8emvZMwq/Zkq/fYFq/J2Lzq/9mBq/Qq/LPq/Rq/HTq/Pjq/rzq/c2q/uq/4u:5YvZMT/d/fYc/JWG/M4/z/W/o/G/PW/f
                                                                                                                                                                                                                                  MD5:D3D88F264E5E44BAA890C19A4C87A24D
                                                                                                                                                                                                                                  SHA1:BA2E3F8D69D1092CE925D40FE31BEABA0DC22905
                                                                                                                                                                                                                                  SHA-256:90B585115252C37625B6BCDE14708AAE003E2D6F3408D8A9034ABB6FFFD66490
                                                                                                                                                                                                                                  SHA-512:14485EEC4C77DA6D7DD813A84F3F5B0DE17AE06C23FBCDB20727376C62D675ED675893B8B9A4DAAA00C21B7550F83593780CA538DB05B4ADDD4604FBCD3B0E51
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Shanghai) {. {-9223372036854775808 29143 0 LMT}. {-2177481943 28800 0 CST}. {-933667200 32400 1 CDT}. {-922093200 28800 0 CST}. {-908870400 32400 1 CDT}. {-888829200 28800 0 CST}. {-881049600 32400 1 CDT}. {-767869200 28800 0 CST}. {-745833600 32400 1 CDT}. {-733827600 28800 0 CST}. {-716889600 32400 1 CDT}. {-699613200 28800 0 CST}. {-683884800 32400 1 CDT}. {-670669200 28800 0 CST}. {-652348800 32400 1 CDT}. {-650016000 28800 0 CST}. {515527200 32400 1 CDT}. {527014800 28800 0 CST}. {545162400 32400 1 CDT}. {558464400 28800 0 CST}. {577216800 32400 1 CDT}. {589914000 28800 0 CST}. {608666400 32400 1 CDT}. {621968400 28800 0 CST}. {640116000 32400 1 CDT}. {653418000 28800 0 CST}. {671565600 32400 1 CDT}. {684867600 28800 0 CST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):359
                                                                                                                                                                                                                                  Entropy (8bit):4.370799489849578
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKfbdJm2OHxdPmIWOb/MVSYv/1MesF5X8dSMd0dMVSSm8kvScCvCIMY:MBp52nbdJmdHDPxDTMF/wFZMxcHClMxi
                                                                                                                                                                                                                                  MD5:DFABB80419B69BE34B2FCD475CFDFE22
                                                                                                                                                                                                                                  SHA1:2CF4F330E00397020328BCE28449B9F63E17067D
                                                                                                                                                                                                                                  SHA-256:B251FBDB0DB4ACBB3855063C32681A5F32E609FA3AA0DDC43225D056D07CB2D3
                                                                                                                                                                                                                                  SHA-512:EB362B7D0C5A4F1C605A8F2533A5CCAFCFA1F4D3B0F48C417CEA8C492834FE36822A75C726659786CBD4D5A544376D806E6BA8E952607997FBDDAF84E343B353
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Singapore) {. {-9223372036854775808 24925 0 LMT}. {-2177477725 24925 0 SMT}. {-2038200925 25200 0 +07}. {-1167634800 26400 1 +0720}. {-1073028000 26400 0 +0720}. {-894180000 27000 0 +0730}. {-879665400 32400 0 +09}. {-767005200 27000 0 +0730}. {378664200 28800 0 +08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1993
                                                                                                                                                                                                                                  Entropy (8bit):3.7026922613316886
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQHOedtdvBOCdwdVdptQvMCTP2rF1gCzlODU9xE305r/CXVWWHs/gSNknK:5HxvBHwRw/P2rFGAlODU9PZUEWQgmkK
                                                                                                                                                                                                                                  MD5:0F445767A84A429787070F7CCFB4D35B
                                                                                                                                                                                                                                  SHA1:B524665DAC57E53A6D9A5386B5AEAAE52BD405A5
                                                                                                                                                                                                                                  SHA-256:07F4857391E114D4B958C02B8FF72BEBCED72AA730F4F4B09F68F57349473503
                                                                                                                                                                                                                                  SHA-512:8FE2AC4C1DCA60E597633377EF1F1C38EE027B7893DB77BA912F294B9B791B6762E62E87DAC17171B15629DD45BD7960D25ADAE96827DAB63FAA80E0956A8C80
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Srednekolymsk) {. {-9223372036854775808 36892 0 LMT}. {-1441188892 36000 0 +10}. {-1247565600 39600 0 +12}. {354891600 43200 1 +12}. {370699200 39600 0 +11}. {386427600 43200 1 +12}. {402235200 39600 0 +11}. {417963600 43200 1 +12}. {433771200 39600 0 +11}. {449586000 43200 1 +12}. {465318000 39600 0 +11}. {481042800 43200 1 +12}. {496767600 39600 0 +11}. {512492400 43200 1 +12}. {528217200 39600 0 +11}. {543942000 43200 1 +12}. {559666800 39600 0 +11}. {575391600 43200 1 +12}. {591116400 39600 0 +11}. {606841200 43200 1 +12}. {622566000 39600 0 +11}. {638290800 43200 1 +12}. {654620400 39600 0 +11}. {670345200 36000 0 +11}. {670348800 39600 1 +11}. {686073600 36000 0 +10}. {695750400 39600 0 +12}. {701794800 43200 1 +12}. {717519600 39600 0 +11}. {733244400 43200 1 +12}. {748969200 39600 0 +11}. {764694000 43200 1 +12}. {78041
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1298
                                                                                                                                                                                                                                  Entropy (8bit):3.983254382416919
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQXbe9Z+zuzq/9mBq/Qq/LPq/wO3q/uq/PC9q/hq/Rq/Gq/fq/Aq/Vtyq/fQH+zp:5XwoKG/M4/z/W/Ta/1/V/Y/o/d/y/D/t
                                                                                                                                                                                                                                  MD5:16CF8E32D5B2933CE5A0F2F90B8090BA
                                                                                                                                                                                                                                  SHA1:F899656FE3FDDD5F63B18D4800F909CD2DA6A151
                                                                                                                                                                                                                                  SHA-256:E098A0A94ED53EC471841CDF6995AEF1F3A2699EDC143FF5DBDA7CB0AFD3FD6C
                                                                                                                                                                                                                                  SHA-512:4856AC8AE2BB0C8856A87C5E46AD478E697AACB46B8679870FD581706802772D333FEA5D1D840BDDB1EAB3B4FDD46883CFD2EC4017F9E5C06CAF2A24539FA808
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Taipei) {. {-9223372036854775808 29160 0 LMT}. {-2335248360 28800 0 CST}. {-1017820800 32400 0 JST}. {-766224000 28800 0 CST}. {-745833600 32400 1 CDT}. {-733827600 28800 0 CST}. {-716889600 32400 1 CDT}. {-699613200 28800 0 CST}. {-683884800 32400 1 CDT}. {-670669200 28800 0 CST}. {-652348800 32400 1 CDT}. {-639133200 28800 0 CST}. {-620812800 32400 1 CDT}. {-607597200 28800 0 CST}. {-589276800 32400 1 CDT}. {-576061200 28800 0 CST}. {-562924800 32400 1 CDT}. {-541760400 28800 0 CST}. {-528710400 32400 1 CDT}. {-510224400 28800 0 CST}. {-497174400 32400 1 CDT}. {-478688400 28800 0 CST}. {-465638400 32400 1 CDT}. {-449830800 28800 0 CST}. {-434016000 32400 1 CDT}. {-418208400 28800 0 CST}. {-402480000 32400 1 CDT}. {-386672400 28800 0 CST}. {-370944000 32400 1 CDT}. {-355136400 28800 0 CST}. {-339408000 32400 1 CDT}. {-323600400 2
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):847
                                                                                                                                                                                                                                  Entropy (8bit):3.8433853520749905
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQZeQlNRSsOXEFCMiq90DIgb5j6gMJR/4TJTXSATo6SSYL:5HpFqq9iTVrXjSpL
                                                                                                                                                                                                                                  MD5:24587E02A79D02973DE32E4CDACBE84C
                                                                                                                                                                                                                                  SHA1:41B8CA1CAE10A9340359317EC8DD16C8637C0F1A
                                                                                                                                                                                                                                  SHA-256:46C2D8E86BACFDB8280862AD9E28F7A0867740726EF21D08138C9F9A900CC1E9
                                                                                                                                                                                                                                  SHA-512:07C939DCD5AB0DA3D3667D0D56421C6B40598C6DAB9641664E0ABB2CE4CC4562B10853C88DB51FBA5D1ED733E86193E88CE8984130FFF83955BD9335A59CF031
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Tashkent) {. {-9223372036854775808 16631 0 LMT}. {-1441168631 18000 0 +05}. {-1247547600 21600 0 +06}. {354909600 25200 1 +06}. {370717200 21600 0 +06}. {386445600 25200 1 +06}. {402253200 21600 0 +06}. {417981600 25200 1 +06}. {433789200 21600 0 +06}. {449604000 25200 1 +06}. {465336000 21600 0 +06}. {481060800 25200 1 +06}. {496785600 21600 0 +06}. {512510400 25200 1 +06}. {528235200 21600 0 +06}. {543960000 25200 1 +06}. {559684800 21600 0 +06}. {575409600 25200 1 +06}. {591134400 21600 0 +06}. {606859200 25200 1 +06}. {622584000 21600 0 +06}. {638308800 25200 1 +06}. {654638400 21600 0 +06}. {670363200 18000 0 +05}. {670366800 21600 1 +05}. {686091600 18000 0 +05}. {694206000 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1669
                                                                                                                                                                                                                                  Entropy (8bit):3.588597734517364
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQyGeHLQqpkb/cXXn8UDu5u8WmFeb/RLc9qENkw/ybt8i9E60339UyYU7s9UU7UT:5+YTVOZmF7N76eHj2QqzM
                                                                                                                                                                                                                                  MD5:EEA5CEEDA499381B331676CF2D3B1189
                                                                                                                                                                                                                                  SHA1:BC1D3871CC170F0BCBAE567C0D934CC131A7E410
                                                                                                                                                                                                                                  SHA-256:260F3F9A9209170AC02961E881F02AA6D6C720BAACC29756CF1CC730FACCF662
                                                                                                                                                                                                                                  SHA-512:0E8FF6B4EF0E102152B20D3C819F2673B6426B3D56DF42F89F44EB4467D0CA45F3D49B6564DA6FCB88BDB1887AF39382766F75FE3A3977CFB4408E06C6D1C062
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Tbilisi) {. {-9223372036854775808 10751 0 LMT}. {-2840151551 10751 0 TBMT}. {-1441162751 10800 0 +03}. {-405140400 14400 0 +04}. {354916800 18000 1 +04}. {370724400 14400 0 +04}. {386452800 18000 1 +04}. {402260400 14400 0 +04}. {417988800 18000 1 +04}. {433796400 14400 0 +04}. {449611200 18000 1 +04}. {465343200 14400 0 +04}. {481068000 18000 1 +04}. {496792800 14400 0 +04}. {512517600 18000 1 +04}. {528242400 14400 0 +04}. {543967200 18000 1 +04}. {559692000 14400 0 +04}. {575416800 18000 1 +04}. {591141600 14400 0 +04}. {606866400 18000 1 +04}. {622591200 14400 0 +04}. {638316000 18000 1 +04}. {654645600 14400 0 +04}. {670370400 10800 0 +03}. {670374000 14400 1 +03}. {686098800 10800 0 +03}. {694213200 10800 0 +03}. {701816400 14400 1 +03}. {717537600 10800 0 +03}. {733266000 14400 1 +03}. {748987200 10800 0 +03}. {764715600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7021
                                                                                                                                                                                                                                  Entropy (8bit):3.4346704245463338
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:BboVQCKYJ4cRvxoIDCMcuzf8mmU6gjilpM1Bdy6XaqYx7u0kLBT8U2nTEA4n8t/s:exqcFOIDCMcMrPqpIB8f9ZkF0EIk
                                                                                                                                                                                                                                  MD5:E179D37382F44D866D495F5D38FD5D88
                                                                                                                                                                                                                                  SHA1:35C5BFFE89795786B7ED0BB3B7822666D6BFCB5B
                                                                                                                                                                                                                                  SHA-256:41F1DBB61094C00E2424E22780930258BC99A71D182E7A181065B0A1A57306F1
                                                                                                                                                                                                                                  SHA-512:AF1A4AB0BD690F038EBC3AA5CB2CAEE575E639B4504E3BEBC8E1DE85081C780744CBAD5871D62D4F028314D165B4D71E9B3D0B68019FE9D1E49D702101602431
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Tehran) {. {-9223372036854775808 12344 0 LMT}. {-1704165944 12344 0 TMT}. {-757394744 12600 0 +0330}. {247177800 14400 0 +04}. {259272000 18000 1 +04}. {277758000 14400 0 +04}. {283982400 12600 0 +0330}. {290809800 16200 1 +0330}. {306531000 12600 0 +0330}. {322432200 16200 1 +0330}. {338499000 12600 0 +0330}. {673216200 16200 1 +0330}. {685481400 12600 0 +0330}. {701209800 16200 1 +0330}. {717103800 12600 0 +0330}. {732745800 16200 1 +0330}. {748639800 12600 0 +0330}. {764281800 16200 1 +0330}. {780175800 12600 0 +0330}. {795817800 16200 1 +0330}. {811711800 12600 0 +0330}. {827353800 16200 1 +0330}. {843247800 12600 0 +0330}. {858976200 16200 1 +0330}. {874870200 12600 0 +0330}. {890512200 16200 1 +0330}. {906406200 12600 0 +0330}. {922048200 16200 1 +0330}. {937942200 12600 0 +0330}. {953584200 16200 1 +0330}. {969478200 12600 0 +
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.82789113675599
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq85zFFwVAIgN0AzFzt2WFK+TT52WFKYzFp:SlSWB9IZaM3yZbwVAIgCAb2wKsswKY7
                                                                                                                                                                                                                                  MD5:D044282CC9B9F531D8136612B4AA938D
                                                                                                                                                                                                                                  SHA1:5FD01E48BFFC2B54BBA48926EFD2137A91B57E0F
                                                                                                                                                                                                                                  SHA-256:FE57D86184A7F4A64F3555DE3F4463531A86BB18F124534F17B09FAB825F83B4
                                                                                                                                                                                                                                  SHA-512:DBBA54D68F33E51D51E816D79D83B61490BD31262DFF6037C0834BADA48CBC02F4281203D7212EDF6D96F7FF1EF3843299698BF0DFE10B5F1383AA504594505A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Jerusalem)]} {. LoadTimeZoneFile Asia/Jerusalem.}.set TZData(:Asia/Tel_Aviv) $TZData(:Asia/Jerusalem).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):171
                                                                                                                                                                                                                                  Entropy (8bit):4.858169634371472
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8kNZ4pVAIgNqFNzO62WFK9Z752WFKvNZvn:SlSWB9IZaM3ykZ4pVAIgc3K62wKf12wc
                                                                                                                                                                                                                                  MD5:B678D97B4E6E6112299746833C06C70B
                                                                                                                                                                                                                                  SHA1:A49BD45DB59BDD3B7BF9159699272389E8EF77AC
                                                                                                                                                                                                                                  SHA-256:6AEAE87CAD7FE358A5A1BABE6C0244A3F89403FC64C5AA19E1FFDEDCEB6CF57B
                                                                                                                                                                                                                                  SHA-512:BEA10EAE5941E027D8FE9E5D5C03FAE5DCFEF7603088E71CA7CCD0461851E175AE1CC7592DFBEC63F91D840E4E0AA04B54549EB71303666E6EA16AFFF6EDA058
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Thimphu)]} {. LoadTimeZoneFile Asia/Thimphu.}.set TZData(:Asia/Thimbu) $TZData(:Asia/Thimphu).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.838482422690701
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKvNZLXGm2OHEQUTFnvSVaJKuc/v6QzFtV9gmZVFSTL:SlSWB9X52wKVZCm2OHEfnjKuc/SQnV9y
                                                                                                                                                                                                                                  MD5:A52B235D91207E823482EEC1EE8C6433
                                                                                                                                                                                                                                  SHA1:84826EAC8043739256E34D828D6BE8E17172A8F8
                                                                                                                                                                                                                                  SHA-256:21CE1FAEDD45DED62E78D6DB24F47ED9DEC5642E4A4D7ADDF85B33F8AB82D8CA
                                                                                                                                                                                                                                  SHA-512:08E8C68BF6BE5E876A59130C207D4911732EBA0F4E72603213A0AD0CC5DA8EF6AC6389AF8A0781F01B0E72CA030C9A47C46CC0FB422F5C0104A7365D818A4EB9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Thimphu) {. {-9223372036854775808 21516 0 LMT}. {-706341516 19800 0 +0530}. {560025000 21600 0 +06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):374
                                                                                                                                                                                                                                  Entropy (8bit):4.405484223376936
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKvm2OHOx5PvYvmoZsOXzvmof67zd6avmoFc87e+zvmT0TgvmL:MBp52XmdHOx5PAbZ3zbi7xtbFD7e+zou
                                                                                                                                                                                                                                  MD5:4549B66A26A96C10DB196B8957BB6127
                                                                                                                                                                                                                                  SHA1:B2B96699AE70CA47F2B180B9AEF8FB9864AE98A1
                                                                                                                                                                                                                                  SHA-256:EC533BBE242CE6A521BAED1D37E0DD0247A37FE8D36D25205520B93CF51E4595
                                                                                                                                                                                                                                  SHA-512:A6C147DF80BB6D41877AD99673C49FF6AD5C1C03B587D71A70C8F7BD8D321817D9E99BFAE11F7F7C27C1A7563C9A101B6C3E65D962B3524C95113A807720ED4E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Tokyo) {. {-9223372036854775808 33539 0 LMT}. {-2587712400 32400 0 JST}. {-683802000 36000 1 JDT}. {-672310800 32400 0 JST}. {-654771600 36000 1 JDT}. {-640861200 32400 0 JST}. {-620298000 36000 1 JDT}. {-609411600 32400 0 JST}. {-588848400 36000 1 JDT}. {-577962000 32400 0 JST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2043
                                                                                                                                                                                                                                  Entropy (8bit):3.6031458640952554
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:539i17A9/IJ4vQayW+dRvV8YzXJIq79Af3AuyqM7FfiC/LIcy9zU9Muq2PIX/9se:ijFRRCfQucXsQk7TQy
                                                                                                                                                                                                                                  MD5:436E5AA70DD662E337E0144558EA277B
                                                                                                                                                                                                                                  SHA1:E268AAD83CE3CC32CB23647E961509EBB4C8AA2C
                                                                                                                                                                                                                                  SHA-256:9917B2A1BFAAD1378B90879C92F157BD7912A4072BE21A2A4CB366A38F310D3B
                                                                                                                                                                                                                                  SHA-512:C714CFBB58170E2291A78AD4F725613049BC9D52DB9F8685803E8F7E181D7E0C2AAF7E603D29243D2E5F4F1D8A3B0272559E7CBCB51736A8115A44E6D56FA7CC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Tomsk) {. {-9223372036854775808 20391 0 LMT}. {-1578807591 21600 0 +06}. {-1247551200 25200 0 +08}. {354906000 28800 1 +08}. {370713600 25200 0 +07}. {386442000 28800 1 +08}. {402249600 25200 0 +07}. {417978000 28800 1 +08}. {433785600 25200 0 +07}. {449600400 28800 1 +08}. {465332400 25200 0 +07}. {481057200 28800 1 +08}. {496782000 25200 0 +07}. {512506800 28800 1 +08}. {528231600 25200 0 +07}. {543956400 28800 1 +08}. {559681200 25200 0 +07}. {575406000 28800 1 +08}. {591130800 25200 0 +07}. {606855600 28800 1 +08}. {622580400 25200 0 +07}. {638305200 28800 1 +08}. {654634800 25200 0 +07}. {670359600 21600 0 +07}. {670363200 25200 1 +07}. {686088000 21600 0 +06}. {695764800 25200 0 +08}. {701809200 28800 1 +08}. {717534000 25200 0 +07}. {733258800 28800 1 +08}. {748983600 25200 0 +07}. {764708400 28800 1 +08}. {780433200 252
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.8489855608543575
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8pYFwVAIgNzB0L2WFKPQOrFJ4WFKvn:SlSWB9IZaM3yWFwVAIg8L2wKPQOrFJ4H
                                                                                                                                                                                                                                  MD5:AF91CF42CFBA12F55AF3E6D26A71946D
                                                                                                                                                                                                                                  SHA1:673AC77D4E5B6ED7CE8AE67975372462F6AF870B
                                                                                                                                                                                                                                  SHA-256:D9BCAE393D4B9EE5F308FA0C26A7A6BCE716E77DB056E75A3B39B33A227760C8
                                                                                                                                                                                                                                  SHA-512:1FD61EA39FF08428486E07AF4404CEA67ACCCB600F11BA74B340A4F663EB8221BC7BF84AE677566F7DDEC0CB42F1946614CD11A9CD7824E0D6CAA804DF0EF514
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Makassar)]} {. LoadTimeZoneFile Asia/Makassar.}.set TZData(:Asia/Ujung_Pandang) $TZData(:Asia/Makassar).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1535
                                                                                                                                                                                                                                  Entropy (8bit):3.6833061173791726
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQlTer9uN1xJSIA+SN16zSacGjSvtHpS9xZzS1ZjSnZS3owShjS+5MzSDZmSA/SN:569YXoIA9N0+acGuRIvc1Zun43oDhu+x
                                                                                                                                                                                                                                  MD5:9C497C3C57F4FEE50C6BF35D0A3A7E5F
                                                                                                                                                                                                                                  SHA1:FAFB3456CADE6AD6FFBADC699AB882FAE2591739
                                                                                                                                                                                                                                  SHA-256:19855D4B0EEF8CD85D502262DF7B7F15B069B1A4D169FAB0F20F803C598C1D83
                                                                                                                                                                                                                                  SHA-512:255CDF3333789771240A37CECBEB87EEAAE4561616A7066C935B67B8CA930F026F68A82315083190B175C54FBB4B2DB0126F25FDDD6C09DC374E09833225DFB8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Ulaanbaatar) {. {-9223372036854775808 25652 0 LMT}. {-2032931252 25200 0 +07}. {252435600 28800 0 +08}. {417974400 32400 1 +08}. {433782000 28800 0 +08}. {449596800 32400 1 +08}. {465318000 28800 0 +08}. {481046400 32400 1 +08}. {496767600 28800 0 +08}. {512496000 32400 1 +08}. {528217200 28800 0 +08}. {543945600 32400 1 +08}. {559666800 28800 0 +08}. {575395200 32400 1 +08}. {591116400 28800 0 +08}. {606844800 32400 1 +08}. {622566000 28800 0 +08}. {638294400 32400 1 +08}. {654620400 28800 0 +08}. {670348800 32400 1 +08}. {686070000 28800 0 +08}. {701798400 32400 1 +08}. {717519600 28800 0 +08}. {733248000 32400 1 +08}. {748969200 28800 0 +08}. {764697600 32400 1 +08}. {780418800 28800 0 +08}. {796147200 32400 1 +08}. {811868400 28800 0 +08}. {828201600 32400 1 +08}. {843922800 28800 0 +08}. {859651200 32400 1 +08}. {875372400
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):187
                                                                                                                                                                                                                                  Entropy (8bit):4.675919405724711
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8TcXHVAIgNrfcXKxL2WFKhrMEBQWFKucXu:SlSWB9IZaM3yIVAIg7xL2wKhrMEewKI
                                                                                                                                                                                                                                  MD5:73C6A7BC088A3CD92CAC2F8B019994A0
                                                                                                                                                                                                                                  SHA1:74D5DCE1100F6C97DFCFAD5EFC310196F03ABED5
                                                                                                                                                                                                                                  SHA-256:8F075ACF5FF86E5CDE63E178F7FCB692C209B6023C80157A2ABF6826AE63C6C3
                                                                                                                                                                                                                                  SHA-512:4EAD916D2251CF3A9B336448B467282C251EE5D98299334F365711CCA8CAF9CA83600503A3346AEC9DFA9E9AF064BA6DEF570BABCC48AE5EB954DBF574A769B2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Ulaanbaatar)]} {. LoadTimeZoneFile Asia/Ulaanbaatar.}.set TZData(:Asia/Ulan_Bator) $TZData(:Asia/Ulaanbaatar).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):143
                                                                                                                                                                                                                                  Entropy (8bit):4.962709386113539
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52WFKjmcXGm2OHEVPvUWA0GVFSTL:SlSWB9X52wKjmTm2OHEVPXA0CUn
                                                                                                                                                                                                                                  MD5:6E79B04FC6FE96C90277593719BECD36
                                                                                                                                                                                                                                  SHA1:81798A9F349A7DEAF9218A21B8C2D8A3E641E9B7
                                                                                                                                                                                                                                  SHA-256:A73686D7BF4EE44DC7BBD1CAAF2D212D7D12478F1521BF5A628EDBEA79B99725
                                                                                                                                                                                                                                  SHA-512:F6781EDA72F4B62FE128332AC2B6BDDFFF6E94DF79914C467C2A30BBE05ABE005B23C0F8A5682095FA874CB3787BD499DBBA8F1644515B6914180A68C9AB6066
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Urumqi) {. {-9223372036854775808 21020 0 LMT}. {-1325483420 21600 0 +06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1987
                                                                                                                                                                                                                                  Entropy (8bit):3.684365782602096
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQueIlfR30vBOCdwdVdptQvMCTP2rF1gCzlODU9xE305r/CXVWWHs/gSNknhT:5YJkvBHwRw/P2rFGAlODU9PZUEWQgmkl
                                                                                                                                                                                                                                  MD5:F648B8CDF0F44BF2733AD480D91602C2
                                                                                                                                                                                                                                  SHA1:FCDB62F1D2781836AAAFF1C1B651E91A8E79A901
                                                                                                                                                                                                                                  SHA-256:C94B072DDB28C27AAA936D27D5A2F1400E47E8BBFCB3EF370BF2C7252E69FB98
                                                                                                                                                                                                                                  SHA-512:39E793B707C2EEF99BAE8E926A1C8CAF4A1989F71842C348A5819CC4BE3D6DC81D2781BF20CB95631EC532A345B7CD41BA88505B301CA7928E676F55252C6DDD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Ust-Nera) {. {-9223372036854775808 34374 0 LMT}. {-1579426374 28800 0 +08}. {354898800 43200 0 +12}. {370699200 39600 0 +11}. {386427600 43200 1 +12}. {402235200 39600 0 +11}. {417963600 43200 1 +12}. {433771200 39600 0 +11}. {449586000 43200 1 +12}. {465318000 39600 0 +11}. {481042800 43200 1 +12}. {496767600 39600 0 +11}. {512492400 43200 1 +12}. {528217200 39600 0 +11}. {543942000 43200 1 +12}. {559666800 39600 0 +11}. {575391600 43200 1 +12}. {591116400 39600 0 +11}. {606841200 43200 1 +12}. {622566000 39600 0 +11}. {638290800 43200 1 +12}. {654620400 39600 0 +11}. {670345200 36000 0 +11}. {670348800 39600 1 +11}. {686073600 36000 0 +10}. {695750400 39600 0 +12}. {701794800 43200 1 +12}. {717519600 39600 0 +11}. {733244400 43200 1 +12}. {748969200 39600 0 +11}. {764694000 43200 1 +12}. {780418800 39600 0 +11}. {796143600 43
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.808435832735883
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8VLYO5YFwVAIgN8ELYOAvN2WFKgTjEHp4WFKELYOun:SlSWB9IZaM3y1LewVAIgKELUvN2wKgsI
                                                                                                                                                                                                                                  MD5:6372DA942647071A0514AEBF0AFEB7C7
                                                                                                                                                                                                                                  SHA1:C9FB6B05DA246224D5EB016035AB905657B9D3FA
                                                                                                                                                                                                                                  SHA-256:7B1A3F36E9A12B850DC06595AAE6294FAEAC98AD933B3327B866E83C0E9A1999
                                                                                                                                                                                                                                  SHA-512:DC7D8753AD0D6908CA8765623EC1C4E4717833D183435957BB43E7ADB8A0D078F87319408F4C1D284CFB24BE010141B3254A36EF50C5DDCC59D7DEE5B3E33B7F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Bangkok)]} {. LoadTimeZoneFile Asia/Bangkok.}.set TZData(:Asia/Vientiane) $TZData(:Asia/Bangkok).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1991
                                                                                                                                                                                                                                  Entropy (8bit):3.617868789838068
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQ6EeBGZKFyW3bEH6i4bfwRpiTQNuTHDMOFOnJfioEkfhbZUAPQ:56aZWf3bw6HfavuLoOUDEChbmAPQ
                                                                                                                                                                                                                                  MD5:589D58D0819C274BD76648B290E3B6A7
                                                                                                                                                                                                                                  SHA1:8EF67425A86E1663263C380B81C878EFEE107261
                                                                                                                                                                                                                                  SHA-256:F7CA7543A15D0EA7380552E9CA4506E1527D5A0C9081B21A6A6CAEAD51085293
                                                                                                                                                                                                                                  SHA-512:38A4264039866E82CC2CCAF52FF1AB3384A72AD9F2FF0060FC49B3D2C09CB072700F28F2CA3A0850B3E5BAB62F6AA6031ECAB2EAB09EB08833D8CD778B338BDD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Vladivostok) {. {-9223372036854775808 31651 0 LMT}. {-1487321251 32400 0 +09}. {-1247562000 36000 0 +11}. {354895200 39600 1 +11}. {370702800 36000 0 +10}. {386431200 39600 1 +11}. {402238800 36000 0 +10}. {417967200 39600 1 +11}. {433774800 36000 0 +10}. {449589600 39600 1 +11}. {465321600 36000 0 +10}. {481046400 39600 1 +11}. {496771200 36000 0 +10}. {512496000 39600 1 +11}. {528220800 36000 0 +10}. {543945600 39600 1 +11}. {559670400 36000 0 +10}. {575395200 39600 1 +11}. {591120000 36000 0 +10}. {606844800 39600 1 +11}. {622569600 36000 0 +10}. {638294400 39600 1 +11}. {654624000 36000 0 +10}. {670348800 32400 0 +10}. {670352400 36000 1 +10}. {686077200 32400 0 +09}. {695754000 36000 0 +11}. {701798400 39600 1 +11}. {717523200 36000 0 +10}. {733248000 39600 1 +11}. {748972800 36000 0 +10}. {764697600 39600 1 +11}. {7804224
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1987
                                                                                                                                                                                                                                  Entropy (8bit):3.6163895181017764
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQVe7Ox4ER6oziDpiKXtyiyzilUBinUijiRziiiaSiYzYWk2HgQiMhNIziPiRikL:5Q+9InX4n7m84nPIzOtfjQhGT+
                                                                                                                                                                                                                                  MD5:29C007E4E3E0015DBF39D78DF39CB790
                                                                                                                                                                                                                                  SHA1:C3311ED4D7774A7DC14E0436D0B90C88ADD9BDA5
                                                                                                                                                                                                                                  SHA-256:C2DD93EEAFC3E2FD6CCE0EED0633C40D8BF34331760D23A75ADCEA1719A11AE6
                                                                                                                                                                                                                                  SHA-512:24609B8C01F3420CC19CA8F5AC78867DCAD1DD1A09A4B1C5356F90F0041BBCA322BC0C64D5DE4F565331674CFE15B7BF66AF6B69ACE9D18765A91B044962F781
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Yakutsk) {. {-9223372036854775808 31138 0 LMT}. {-1579423138 28800 0 +08}. {-1247558400 32400 0 +10}. {354898800 36000 1 +10}. {370706400 32400 0 +09}. {386434800 36000 1 +10}. {402242400 32400 0 +09}. {417970800 36000 1 +10}. {433778400 32400 0 +09}. {449593200 36000 1 +10}. {465325200 32400 0 +09}. {481050000 36000 1 +10}. {496774800 32400 0 +09}. {512499600 36000 1 +10}. {528224400 32400 0 +09}. {543949200 36000 1 +10}. {559674000 32400 0 +09}. {575398800 36000 1 +10}. {591123600 32400 0 +09}. {606848400 36000 1 +10}. {622573200 32400 0 +09}. {638298000 36000 1 +10}. {654627600 32400 0 +09}. {670352400 28800 0 +09}. {670356000 32400 1 +09}. {686080800 28800 0 +08}. {695757600 32400 0 +10}. {701802000 36000 1 +10}. {717526800 32400 0 +09}. {733251600 36000 1 +10}. {748976400 32400 0 +09}. {764701200 36000 1 +10}. {780426000 3
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):235
                                                                                                                                                                                                                                  Entropy (8bit):4.635396864572362
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52wKsCm2OHGVQPZN6FCm+UlDVkvScChY/s5Uq:MBp52zmdHGuPZNAkHCpr
                                                                                                                                                                                                                                  MD5:12B1D08ED6DFAB647D8F1D1371D771F6
                                                                                                                                                                                                                                  SHA1:2AC1CE6E85533D6B99A8E9725F43A867833B956E
                                                                                                                                                                                                                                  SHA-256:DCC9323EF236D2E3B6DAA296EB14B9208754FCD449D2351067201BCEC15381A2
                                                                                                                                                                                                                                  SHA-512:C563B6A3F1B21B5FFD0F092CAF6344D5A6D74F5AC03DA44DCA6FB1B4BC0D321C6E0E8F315248D41C0D1D0FFD35F8DE31D96FBD4AE1CFE15DA52E40EE3FF7F8E3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Yangon) {. {-9223372036854775808 23087 0 LMT}. {-2840163887 23087 0 RMT}. {-1577946287 23400 0 +0630}. {-873268200 32400 0 +09}. {-778410000 23400 0 +0630}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2023
                                                                                                                                                                                                                                  Entropy (8bit):3.6129679767742124
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:5iKkhr7YqXZIoLybDNUoXKXmpsuNjcgy8TmQ28N7Wdw+5vDT7L:w2xd8kCdf
                                                                                                                                                                                                                                  MD5:9C578B55160C4CDE22E0CD3AE449AA89
                                                                                                                                                                                                                                  SHA1:DAEB24B867A835AA97E7E6A67C1AD4278015D6BB
                                                                                                                                                                                                                                  SHA-256:924E60D3C57F296CDEA175D4E970FF3C68A92ADBBBA23EF37B76D7AD5D41DCE9
                                                                                                                                                                                                                                  SHA-512:E3F2798038F897DF5D1D112F294BFD4E3FDBFCF4D568C4038C85289F84E0844010A6C88659C4B9D94720DBB680F2628CECEB17E6C6D0DFC231E6DCBA75068458
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Yekaterinburg) {. {-9223372036854775808 14553 0 LMT}. {-1688270553 13505 0 PMT}. {-1592610305 14400 0 +04}. {-1247544000 18000 0 +06}. {354913200 21600 1 +06}. {370720800 18000 0 +05}. {386449200 21600 1 +06}. {402256800 18000 0 +05}. {417985200 21600 1 +06}. {433792800 18000 0 +05}. {449607600 21600 1 +06}. {465339600 18000 0 +05}. {481064400 21600 1 +06}. {496789200 18000 0 +05}. {512514000 21600 1 +06}. {528238800 18000 0 +05}. {543963600 21600 1 +06}. {559688400 18000 0 +05}. {575413200 21600 1 +06}. {591138000 18000 0 +05}. {606862800 21600 1 +06}. {622587600 18000 0 +05}. {638312400 21600 1 +06}. {654642000 18000 0 +05}. {670366800 14400 0 +05}. {670370400 18000 1 +05}. {686095200 14400 0 +04}. {695772000 18000 0 +06}. {701816400 21600 1 +06}. {717541200 18000 0 +05}. {733266000 21600 1 +06}. {748990800 18000 0 +05}. {764
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1959
                                                                                                                                                                                                                                  Entropy (8bit):3.554930605948629
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQO4LeuVrqpkb/cXXn8UDu5u8WmFeb/RLc9qENkw/ybt8i9E60339UyuUgUU2heQ:5x79TVOZmF7N76eHvdSB4tJFFWmvN
                                                                                                                                                                                                                                  MD5:013DD03BE28257101FC72E3294709AC6
                                                                                                                                                                                                                                  SHA1:2EBBB3DA858B1BBC0C3CDFCBED3A4BAA0D6CE1B2
                                                                                                                                                                                                                                  SHA-256:15CBC98425C074D9D5D1B107483BF68C75C318C240C7CDBDA390F8D102D76D53
                                                                                                                                                                                                                                  SHA-512:10A651C82E6D5386FDC1FC95EF15F1CB0A4D8850A2324E7D62F63E1D3FBA87812045FFCF1DF013D7A3E90BBF514A4C5B2B23C547905737193B369644986D6A42
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Asia/Yerevan) {. {-9223372036854775808 10680 0 LMT}. {-1441162680 10800 0 +03}. {-405140400 14400 0 +04}. {354916800 18000 1 +04}. {370724400 14400 0 +04}. {386452800 18000 1 +04}. {402260400 14400 0 +04}. {417988800 18000 1 +04}. {433796400 14400 0 +04}. {449611200 18000 1 +04}. {465343200 14400 0 +04}. {481068000 18000 1 +04}. {496792800 14400 0 +04}. {512517600 18000 1 +04}. {528242400 14400 0 +04}. {543967200 18000 1 +04}. {559692000 14400 0 +04}. {575416800 18000 1 +04}. {591141600 14400 0 +04}. {606866400 18000 1 +04}. {622591200 14400 0 +04}. {638316000 18000 1 +04}. {654645600 14400 0 +04}. {670370400 10800 0 +03}. {670374000 14400 1 +03}. {686098800 10800 0 +03}. {701823600 14400 1 +03}. {717548400 10800 0 +03}. {733273200 14400 1 +03}. {748998000 10800 0 +03}. {764722800 14400 1 +03}. {780447600 10800 0 +03}. {796172400 14
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9474
                                                                                                                                                                                                                                  Entropy (8bit):3.4598088631836625
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Mw7Jfsud5vCGy0luUDHaXZgsN/FWVFjHv0:Mwdf/d5vCGy0luZN9WVFjHv0
                                                                                                                                                                                                                                  MD5:E9C33EAACFD20C021CE94292068CC1D8
                                                                                                                                                                                                                                  SHA1:9F8C0A4E07C33349C6ACDB0564771AEB11098B9D
                                                                                                                                                                                                                                  SHA-256:8E2B427733BF8DBCE5171DC57F0892F0987CF1BD7941DA40048CB53B86B23E0D
                                                                                                                                                                                                                                  SHA-512:8C77CF236855C51E03911A8203A2E81FC728C21A904B4962EA18F5FD39B00174D8A365FC0CA42E4EDE12DA84DD6445CFBB1B3E922189EB6B13AF6BC802E2B405
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Azores) {. {-9223372036854775808 -6160 0 LMT}. {-2713904240 -6872 0 HMT}. {-1830376800 -7200 0 -02}. {-1689548400 -3600 1 -01}. {-1677794400 -7200 0 -02}. {-1667430000 -3600 1 -01}. {-1647730800 -7200 0 -02}. {-1635807600 -3600 1 -01}. {-1616194800 -7200 0 -02}. {-1604358000 -3600 1 -01}. {-1584658800 -7200 0 -02}. {-1572735600 -3600 1 -01}. {-1553036400 -7200 0 -02}. {-1541199600 -3600 1 -01}. {-1521500400 -7200 0 -02}. {-1442444400 -3600 1 -01}. {-1426806000 -7200 0 -02}. {-1379286000 -3600 1 -01}. {-1364770800 -7200 0 -02}. {-1348441200 -3600 1 -01}. {-1333321200 -7200 0 -02}. {-1316386800 -3600 1 -01}. {-1301266800 -7200 0 -02}. {-1284332400 -3600 1 -01}. {-1269817200 -7200 0 -02}. {-1221433200 -3600 1 -01}. {-1206918000 -7200 0 -02}. {-1191193200 -3600 1 -01}. {-1175468400 -7200 0 -02}. {-1127689200 -3600 1 -01}. {-111196440
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7684
                                                                                                                                                                                                                                  Entropy (8bit):3.7376923223964162
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:UdPvxrPGgFEUlpde9pXbO53oVmM7IEc2fVGYu2yeB/T/eleWmBk81kS/kV6kef4E:lJv
                                                                                                                                                                                                                                  MD5:E55A91A96E1DC267AAEFAF27866F0A90
                                                                                                                                                                                                                                  SHA1:A3E8DB332114397F4F487256E9168E73784D3637
                                                                                                                                                                                                                                  SHA-256:A2EB47B25B3A389907DD242C86288073B0694B030B244CCF90421C0B510267BD
                                                                                                                                                                                                                                  SHA-512:9A8140365D76F1A83A98A35593638F2C047B3D2B1E9D0F6ACB2B321EBDB9CC5B6C8CCD3C110B127A12DCDB7D9ED16A8F7DB7DA7A8B4587486D060FACCA23F993
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Bermuda) {. {-9223372036854775808 -15558 0 LMT}. {-1262281242 -14400 0 AST}. {136360800 -10800 0 ADT}. {152082000 -14400 0 AST}. {167810400 -10800 1 ADT}. {183531600 -14400 0 AST}. {189316800 -14400 0 AST}. {199260000 -10800 1 ADT}. {215586000 -14400 0 AST}. {230709600 -10800 1 ADT}. {247035600 -14400 0 AST}. {262764000 -10800 1 ADT}. {278485200 -14400 0 AST}. {294213600 -10800 1 ADT}. {309934800 -14400 0 AST}. {325663200 -10800 1 ADT}. {341384400 -14400 0 AST}. {357112800 -10800 1 ADT}. {372834000 -14400 0 AST}. {388562400 -10800 1 ADT}. {404888400 -14400 0 AST}. {420012000 -10800 1 ADT}. {436338000 -14400 0 AST}. {452066400 -10800 1 ADT}. {467787600 -14400 0 AST}. {483516000 -10800 1 ADT}. {499237200 -14400 0 AST}. {514965600 -10800 1 ADT}. {530686800 -14400 0 AST}. {544600800 -10800 1 ADT}. {562136400 -14400 0 AST}. {576050
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6609
                                                                                                                                                                                                                                  Entropy (8bit):3.7165368441152715
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:KXu/30NSfAewvtj544IrvfMS4pBs6nLUxZlJFXmA3SG7iL8malvkUEYo4Q:KX5IMj544IrvfMsbxZTH7qwQ
                                                                                                                                                                                                                                  MD5:230C7B4BB6D64818889E573ADBE97E35
                                                                                                                                                                                                                                  SHA1:97E6D43C3F9446C9A224DAF69F31CA55721BFC59
                                                                                                                                                                                                                                  SHA-256:6CDA69514774093B7219BB079077322F5C783DBAD137F89181E8434D8BD2A6CF
                                                                                                                                                                                                                                  SHA-512:A17246BC44C1FDC971304E0D2E8F721E254880FB725F1AACCA05645FFE82F2AF3791234F02824E357CBDD51D529C882E21B8712735C32420074F3B75813DE27C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Canary) {. {-9223372036854775808 -3696 0 LMT}. {-1509663504 -3600 0 -01}. {-733874400 0 0 WET}. {323827200 3600 1 WEST}. {338950800 0 0 WET}. {354675600 3600 1 WEST}. {370400400 0 0 WET}. {386125200 3600 1 WEST}. {401850000 0 0 WET}. {417574800 3600 1 WEST}. {433299600 0 0 WET}. {449024400 3600 1 WEST}. {465354000 0 0 WET}. {481078800 3600 1 WEST}. {496803600 0 0 WET}. {512528400 3600 1 WEST}. {528253200 0 0 WET}. {543978000 3600 1 WEST}. {559702800 0 0 WET}. {575427600 3600 1 WEST}. {591152400 0 0 WET}. {606877200 3600 1 WEST}. {622602000 0 0 WET}. {638326800 3600 1 WEST}. {654656400 0 0 WET}. {670381200 3600 1 WEST}. {686106000 0 0 WET}. {701830800 3600 1 WEST}. {717555600 0 0 WET}. {733280400 3600 1 WEST}. {749005200 0 0 WET}. {764730000 3600 1 WEST}. {780454800 0 0 WET}. {796179600 3600 1 WEST}. {811904400 0 0 WET
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):237
                                                                                                                                                                                                                                  Entropy (8bit):4.579111187402317
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X52RQ7Sm2OHDVJlvQV2FlRo/FFuykVvQV2FR+nmY:MBp5267SmdHDVwiHoGyLiomY
                                                                                                                                                                                                                                  MD5:51BE50511F1FA17A6AF9D4AE892FAFDA
                                                                                                                                                                                                                                  SHA1:2491743E429AAE5DF70CC3E791DC9875E30F152D
                                                                                                                                                                                                                                  SHA-256:E444B51A4511F83D616E816B770A60088EA94B9286112F47331122F44119541D
                                                                                                                                                                                                                                  SHA-512:A509146E25174D9938AF13B78CF052E45F50A61B834C276607B281EF7B81C6696A793A3769B355C8C804A74F37ADDEBBCDC2A69E3B938EB5A2A9742BE135A4A7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Cape_Verde) {. {-9223372036854775808 -5644 0 LMT}. {-1830376800 -7200 0 -02}. {-862610400 -3600 1 -01}. {-764118000 -7200 0 -02}. {186120000 -3600 0 -01}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.655846706649014
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqLG4E2wFVAIgvMG4EeL2RQqG4EZrB/4RQqG4Ei:SlSWB9IZaM3yCwFVAIgvgL2RQ1rB/4R/
                                                                                                                                                                                                                                  MD5:08C5EE09B8BE16C5E974BA8070D448EA
                                                                                                                                                                                                                                  SHA1:D171C194F6D61A891D3390FF6492AEFB0F67646A
                                                                                                                                                                                                                                  SHA-256:7C6A6BCF5AAEAB1BB57482DF1BBC934D367390782F6D8C5783DBBBE663169A9B
                                                                                                                                                                                                                                  SHA-512:E885F3C30DBE178F88464ED505BA1B838848E6BB15C0D27733932CD0634174D9645C5098686E183CC93CB46DE7EB0DBF2EB64CB77A50FC337E2581E25107C9A6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Atlantic/Faroe)]} {. LoadTimeZoneFile Atlantic/Faroe.}.set TZData(:Atlantic/Faeroe) $TZData(:Atlantic/Faroe).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6551
                                                                                                                                                                                                                                  Entropy (8bit):3.7148806034051316
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:9bd30NSfAewvtj544IrvfMS4pBs6nLUxZlJFXmA3SG7iL8malvkUEYo4Q:8IMj544IrvfMsbxZTH7qwQ
                                                                                                                                                                                                                                  MD5:918E1825106C5C73B203B718918311DC
                                                                                                                                                                                                                                  SHA1:7C31B3521B396FE6BE7162BAECC4CFB4740F622B
                                                                                                                                                                                                                                  SHA-256:B648E691D8F3417B77EFB6D6C2F5052B3C4EAF8B5354E018EE2E9BD26F867B71
                                                                                                                                                                                                                                  SHA-512:5B1B5FE82A13127E3C63C8FB0A8CBD45A7277EF29720B937BB3174E8301830018755416D604F3551622E2E4D365D35E4EE1DF39B587A73E43AE0C68D1996B771
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Faroe) {. {-9223372036854775808 -1624 0 LMT}. {-1955748776 0 0 WET}. {347155200 0 0 WET}. {354675600 3600 1 WEST}. {370400400 0 0 WET}. {386125200 3600 1 WEST}. {401850000 0 0 WET}. {417574800 3600 1 WEST}. {433299600 0 0 WET}. {449024400 3600 1 WEST}. {465354000 0 0 WET}. {481078800 3600 1 WEST}. {496803600 0 0 WET}. {512528400 3600 1 WEST}. {528253200 0 0 WET}. {543978000 3600 1 WEST}. {559702800 0 0 WET}. {575427600 3600 1 WEST}. {591152400 0 0 WET}. {606877200 3600 1 WEST}. {622602000 0 0 WET}. {638326800 3600 1 WEST}. {654656400 0 0 WET}. {670381200 3600 1 WEST}. {686106000 0 0 WET}. {701830800 3600 1 WEST}. {717555600 0 0 WET}. {733280400 3600 1 WEST}. {749005200 0 0 WET}. {764730000 3600 1 WEST}. {780454800 0 0 WET}. {796179600 3600 1 WEST}. {811904400 0 0 WET}. {828234000 3600 1 WEST}. {846378000 0 0 WET}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.92967249261586
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVyWJooedVAIgoqxWJ0YF2RQqG0EHEcAg/h8QasWJ/n:SlSWB9IZaM3ymSDdVAIgo2Q2RQaK8H
                                                                                                                                                                                                                                  MD5:AD9B5217497DBC1CE598573B85F3C056
                                                                                                                                                                                                                                  SHA1:60984544F5BBD4A5B2B8F43741D66A573A2CF1DC
                                                                                                                                                                                                                                  SHA-256:BE291E952254B6F0C95C2E2497BE12410D7F1E36D0D1035B3A9BC65D0EDCB65F
                                                                                                                                                                                                                                  SHA-512:F5D47008495425C386EBAB426195393168E402726405CF23826571E548A3CEFABBA51D87D637C0724FF2CC4F1276D81EACF14D0F9CFC7CBFCC025EEFA0960278
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Oslo)]} {. LoadTimeZoneFile Europe/Oslo.}.set TZData(:Atlantic/Jan_Mayen) $TZData(:Europe/Oslo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9307
                                                                                                                                                                                                                                  Entropy (8bit):3.715509739111961
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:jZqAUb1iF0Rf0IMj544IrvfMsbxZTH7qwQ:jZqAUb1iF0RffMUM8xZTH7qwQ
                                                                                                                                                                                                                                  MD5:5D2EAAA0D116DD1C7965FCB229678FB4
                                                                                                                                                                                                                                  SHA1:DA59652A8E57DE9FAF02ED6EB9D863CD34642E6C
                                                                                                                                                                                                                                  SHA-256:8AAF754C1F9AABEA185808F21B864B02815D24451DB38BE8629DA4C57141E8F5
                                                                                                                                                                                                                                  SHA-512:E561B09A53CEC764B0B2B2544E774577553F6DFEFB80AEC04698C2B0FBEBBC7F03E11C31627654346752B4F85BB3EF669397162599F3ED6B8B8D286521447361
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Madeira) {. {-9223372036854775808 -4056 0 LMT}. {-2713906344 -4056 0 FMT}. {-1830380400 -3600 0 -01}. {-1689552000 0 1 +00}. {-1677798000 -3600 0 -01}. {-1667433600 0 1 +00}. {-1647734400 -3600 0 -01}. {-1635811200 0 1 +00}. {-1616198400 -3600 0 -01}. {-1604361600 0 1 +00}. {-1584662400 -3600 0 -01}. {-1572739200 0 1 +00}. {-1553040000 -3600 0 -01}. {-1541203200 0 1 +00}. {-1521504000 -3600 0 -01}. {-1442448000 0 1 +00}. {-1426809600 -3600 0 -01}. {-1379289600 0 1 +00}. {-1364774400 -3600 0 -01}. {-1348444800 0 1 +00}. {-1333324800 -3600 0 -01}. {-1316390400 0 1 +00}. {-1301270400 -3600 0 -01}. {-1284336000 0 1 +00}. {-1269820800 -3600 0 -01}. {-1221436800 0 1 +00}. {-1206921600 -3600 0 -01}. {-1191196800 0 1 +00}. {-1175472000 -3600 0 -01}. {-1127692800 0 1 +00}. {-1111968000 -3600 0 -01}. {-1096848000 0 1 +00}. {-10805184
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1962
                                                                                                                                                                                                                                  Entropy (8bit):3.623004596418002
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cQleDGC/2qdDW4saQCwjoDWFGKRJYHL/Tc7PjEWlyvKekkdoUOCOfNOaRqOjo/Kj:5r2cd5fmYEfAfYaRDjys/
                                                                                                                                                                                                                                  MD5:0E3020348755C67F6A48F4C3F0F4E51D
                                                                                                                                                                                                                                  SHA1:FBA44F3DEBC47274A1C9CC4AE5A5F9B363157BF1
                                                                                                                                                                                                                                  SHA-256:83566E49A37703E11CF0884558BE3DD8827BD79409D04C5D053BCA69D666CEC8
                                                                                                                                                                                                                                  SHA-512:97F78A8C98B03705188B6F4D622F3B88D7C85B2FF1578DA24C4CD85C163FB05DBD908413B5F355F001755705F22943B1DA6C2A58A902751787238110D2A81F95
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Reykjavik) {. {-9223372036854775808 -5280 0 LMT}. {-1956609120 -3600 0 -01}. {-1668211200 0 1 -01}. {-1647212400 -3600 0 -01}. {-1636675200 0 1 -01}. {-1613430000 -3600 0 -01}. {-1605139200 0 1 -01}. {-1581894000 -3600 0 -01}. {-1539561600 0 1 -01}. {-1531350000 -3600 0 -01}. {-968025600 0 1 -01}. {-952293600 -3600 0 -01}. {-942008400 0 1 -01}. {-920239200 -3600 0 -01}. {-909957600 0 1 -01}. {-888789600 -3600 0 -01}. {-877903200 0 1 -01}. {-857944800 -3600 0 -01}. {-846453600 0 1 -01}. {-826495200 -3600 0 -01}. {-815004000 0 1 -01}. {-795045600 -3600 0 -01}. {-783554400 0 1 -01}. {-762991200 -3600 0 -01}. {-752104800 0 1 -01}. {-731541600 -3600 0 -01}. {-717631200 0 1 -01}. {-700092000 -3600 0 -01}. {-686181600 0 1 -01}. {-668642400 -3600 0 -01}. {-654732000 0 1 -01}. {-636588000 -3600 0 -01}. {-623282400 0 1 -01}. {-605
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):154
                                                                                                                                                                                                                                  Entropy (8bit):4.967019958156088
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx52RQqGtlN62/EUXGm2OHXT14YvXhFvdQVIK:SlSWB9X52RQrlo2Mbm2OHXqYPTFQV7
                                                                                                                                                                                                                                  MD5:421C0110145FB8288B08133DD1409E75
                                                                                                                                                                                                                                  SHA1:CD2D62E739FF1715268B6DFB2C523ED3C76B7A90
                                                                                                                                                                                                                                  SHA-256:4B78F3E086B2A8B4366362AB5CEF2DF6A28E2B0EA8279C0FE9414E974BBC2E08
                                                                                                                                                                                                                                  SHA-512:3B20413C6E15A846B3CC730EBCD77D8AA170ECC262E160BB996AA79173F30D42588352C38EA1B44539A62D77B2BC8418A3C4B7507997AF4F15FBD647BF567A88
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/South_Georgia) {. {-9223372036854775808 -8768 0 LMT}. {-2524512832 -7200 0 -02}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.831929124818878
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqss1kvFVAIgNGE4Rvt2RQqGt4r+DcsP:SlSWB9IZaM3y7sYFVAIgNT4tt2RQr4rC
                                                                                                                                                                                                                                  MD5:8F4668F0D79577139B59A80D714E45A5
                                                                                                                                                                                                                                  SHA1:BCD79EDCCB687A2E74794B8CFDE99A7FEC294811
                                                                                                                                                                                                                                  SHA-256:C78C4E980A378B781ED6D2EA72ABAEF8FFED186538DEB18B61D94B575734FC6A
                                                                                                                                                                                                                                  SHA-512:08D1472377229BC76A496259344263993791B4DF3F83D94F798779249A5CAE15F6B4341A665387780EA8B1278E9D5FFBCA1BCDE06B3E54750E32078FA482ABD6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Abidjan)]} {. LoadTimeZoneFile Africa/Abidjan.}.set TZData(:Atlantic/St_Helena) $TZData(:Africa/Abidjan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2181
                                                                                                                                                                                                                                  Entropy (8bit):3.570822154620431
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:50wIS1SbSRxS5Sh/ScoOG2S+SZSgSsSs/SYS6SDSF3SLShS7KXS6SkSGSn/S+7SG:PIEg8CCcOFVOfjl/nxw6cmrXlXdgj7E6
                                                                                                                                                                                                                                  MD5:747D86EC0B020967D989E3D6C4DD273F
                                                                                                                                                                                                                                  SHA1:567F9E398FEDF58D68F73EB16CE33F8483B44ECE
                                                                                                                                                                                                                                  SHA-256:F88641114EC11D4129EEFE59CCD587AAD9C1898C3AFEE8A7CB85962312637640
                                                                                                                                                                                                                                  SHA-512:B7A97E1DCC9E52A0565B50C8865A955924AFED08C21BC1DCCF73A3327C98D0A98706C03913A4872BD24DD2167B2170A6134CA177B20305DEF23D72ADDD668FB0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Atlantic/Stanley) {. {-9223372036854775808 -13884 0 LMT}. {-2524507716 -13884 0 SMT}. {-1824235716 -14400 0 -04}. {-1018209600 -10800 1 -04}. {-1003093200 -14400 0 -04}. {-986760000 -10800 1 -04}. {-971643600 -14400 0 -04}. {-954705600 -10800 1 -04}. {-939589200 -14400 0 -04}. {-923256000 -10800 1 -04}. {-908139600 -14400 0 -04}. {-891806400 -10800 1 -04}. {-876690000 -14400 0 -04}. {-860356800 -10800 1 -04}. {420606000 -7200 0 -03}. {433303200 -7200 1 -03}. {452052000 -10800 0 -03}. {464151600 -7200 1 -03}. {483501600 -10800 0 -03}. {495597600 -14400 0 -04}. {495604800 -10800 1 -04}. {514350000 -14400 0 -04}. {527054400 -10800 1 -04}. {545799600 -14400 0 -04}. {558504000 -10800 1 -04}. {577249200 -14400 0 -04}. {589953600 -10800 1 -04}. {608698800 -14400 0 -04}. {621403200 -10800 1 -04}. {640753200 -14400 0 -04}. {652852800 -10800 1 -04}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.813373101386862
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq/xJjLHVAIgoXjLSt2QWCCjpMFBx/h4QWCCjLu:SlSWB9IZaM3yI9HVAIgmo2DCeMFB/4D2
                                                                                                                                                                                                                                  MD5:F48AD4B81CD3034F6E5D3CA1B5A8BDD4
                                                                                                                                                                                                                                  SHA1:676FE3F50E3E132C1FD185A1EE1D8C830763204F
                                                                                                                                                                                                                                  SHA-256:553D7DA9A2EDBD933E8920573AE6BCBAA00302817939046CF257CAEACEC19FAD
                                                                                                                                                                                                                                  SHA-512:36A4E2286FBEF2F4ED4B9CD1A71136E227FEF4B693F9F43649B790E859221EE470679A7E3C283770DA5CB0113A1C8C1F99480E7020328FFE3E9C870798B092F5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Sydney)]} {. LoadTimeZoneFile Australia/Sydney.}.set TZData(:Australia/ACT) $TZData(:Australia/Sydney).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8099
                                                                                                                                                                                                                                  Entropy (8bit):3.812665609163787
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:JPtFF+Wc4CNphbQbPzpRtYac1w6N5HxnLmPaod/gWFXht/c+u8dRYaaiqcdtXHVf:JP5+zNMdYacv5HhLmPajSXz5HV5x
                                                                                                                                                                                                                                  MD5:4E73BDB571DBF2625E14E38B84C122B4
                                                                                                                                                                                                                                  SHA1:B9D7B7D2855D102800B53FB304633F5BC961A8D0
                                                                                                                                                                                                                                  SHA-256:9138DF8A3DE8BE4099C9C14917B5C5FD7EB14751ACCD66950E0FDB686555FFD6
                                                                                                                                                                                                                                  SHA-512:CF9AB3E9A7C1A76BCC113828ABAF88FE83AAF5CAD7BD181201E06A0CF43E30BA8817AAA88AB3F0F14F459599D91F63ECE851F095154050263C5AD08B2275B4C7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Adelaide) {. {-9223372036854775808 33260 0 LMT}. {-2364110060 32400 0 ACST}. {-2230189200 34200 0 ACST}. {-1672565340 37800 1 ACDT}. {-1665390600 34200 0 ACST}. {-883639800 37800 1 ACDT}. {-876126600 34200 0 ACST}. {-860398200 37800 1 ACDT}. {-844677000 34200 0 ACST}. {-828343800 37800 1 ACDT}. {-813227400 34200 0 ACST}. {31501800 34200 0 ACST}. {57688200 37800 1 ACDT}. {67969800 34200 0 ACST}. {89137800 37800 1 ACDT}. {100024200 34200 0 ACST}. {120587400 37800 1 ACDT}. {131473800 34200 0 ACST}. {152037000 37800 1 ACDT}. {162923400 34200 0 ACST}. {183486600 37800 1 ACDT}. {194977800 34200 0 ACST}. {215541000 37800 1 ACDT}. {226427400 34200 0 ACST}. {246990600 37800 1 ACDT}. {257877000 34200 0 ACST}. {278440200 37800 1 ACDT}. {289326600 34200 0 ACST}. {309889800 37800 1 ACDT}. {320776200 34200 0 ACST}. {341339400 37800 1 ACDT}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):651
                                                                                                                                                                                                                                  Entropy (8bit):4.265580091557009
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52nmdHLOYPv+tCdd8xdsWz9ag5J4UVdKcWWC:cQne6skVk
                                                                                                                                                                                                                                  MD5:296B4B78CEE05805E5EE53B4D5F7284F
                                                                                                                                                                                                                                  SHA1:DDB5B448E99F278C633B2DBD5A816C4DE28DC726
                                                                                                                                                                                                                                  SHA-256:2580C3EEEC029572A1FF629E393F64E326DEDAA96015641165813718A8891C4D
                                                                                                                                                                                                                                  SHA-512:9DE71000BB8AC48A82D83399BD707B661B50882EEBFE2A7E58A81A2F6C04B1F711DAE3AA09A77A9EE265FB633B8883D2C01867AF96F8BE5137119E4FB447DF8C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Brisbane) {. {-9223372036854775808 36728 0 LMT}. {-2366791928 36000 0 AEST}. {-1672567140 39600 1 AEDT}. {-1665392400 36000 0 AEST}. {-883641600 39600 1 AEDT}. {-876128400 36000 0 AEST}. {-860400000 39600 1 AEDT}. {-844678800 36000 0 AEST}. {-828345600 39600 1 AEDT}. {-813229200 36000 0 AEST}. {31500000 36000 0 AEST}. {57686400 39600 1 AEDT}. {67968000 36000 0 AEST}. {625593600 39600 1 AEDT}. {636480000 36000 0 AEST}. {657043200 39600 1 AEDT}. {667929600 36000 0 AEST}. {688492800 39600 1 AEDT}. {699379200 36000 0 AEST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8162
                                                                                                                                                                                                                                  Entropy (8bit):3.820479465698825
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:EkxtFF+Wc4Yphbhd1zCRtYac1w6N5HxnLmPaod/gWFXht/c+u8dRYaaiqcdtXHVf:Ekx5+X5sYacv5HhLmPajSXz5HV5x
                                                                                                                                                                                                                                  MD5:B4AF947B4737537DF09A039D1E500FB8
                                                                                                                                                                                                                                  SHA1:CCC0DC52D586BFAA7A0E70C80709231B4BB93C54
                                                                                                                                                                                                                                  SHA-256:80BBD6D25D4E4EFA234EAD3CB4EB801DC576D1348B9A3E1B58F729FEB688196D
                                                                                                                                                                                                                                  SHA-512:3B27C36FA3034CB371DD07C992B3A5B1357FC7A892C35910DA139C7DA560DDC0AA1E95966438776F75397E7219A7DA0AD4AD6FB922B5E0BE2828D3534488BFD0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Broken_Hill) {. {-9223372036854775808 33948 0 LMT}. {-2364110748 36000 0 AEST}. {-2314951200 32400 0 ACST}. {-2230189200 34200 0 ACST}. {-1672565340 37800 1 ACDT}. {-1665390600 34200 0 ACST}. {-883639800 37800 1 ACDT}. {-876126600 34200 0 ACST}. {-860398200 37800 1 ACDT}. {-844677000 34200 0 ACST}. {-828343800 37800 1 ACDT}. {-813227400 34200 0 ACST}. {31501800 34200 0 ACST}. {57688200 37800 1 ACDT}. {67969800 34200 0 ACST}. {89137800 37800 1 ACDT}. {100024200 34200 0 ACST}. {120587400 37800 1 ACDT}. {131473800 34200 0 ACST}. {152037000 37800 1 ACDT}. {162923400 34200 0 ACST}. {183486600 37800 1 ACDT}. {194977800 34200 0 ACST}. {215541000 37800 1 ACDT}. {226427400 34200 0 ACST}. {246990600 37800 1 ACDT}. {257877000 34200 0 ACST}. {278440200 37800 1 ACDT}. {289326600 34200 0 ACST}. {309889800 37800 1 ACDT}. {320776200 34200 0 ACS
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                  Entropy (8bit):4.80238049701662
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq/xJjLHVAIgoXjLSt2QWCCjnSV1+QWCCjLu:SlSWB9IZaM3yI9HVAIgmo2DCcq+DCyu
                                                                                                                                                                                                                                  MD5:16F9CFC4C5B9D5F9F9DB9346CECE4393
                                                                                                                                                                                                                                  SHA1:ED1ED7BA73EB287D2C8807C4F8EF3EFA516F5A68
                                                                                                                                                                                                                                  SHA-256:853A159B8503B9E8F42BBCE60496722D0A334FD79F30448BAD651F18BA388055
                                                                                                                                                                                                                                  SHA-512:9572CCB1BC499BADA72B5FE533B56156DB9EB0DEDFD4AE4397AD60F2A8AF5991F7B1B06A1B8D14C73832543AF8C12F5B16A9A80D093BF0C7ED6E38FF8B66E197
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Sydney)]} {. LoadTimeZoneFile Australia/Sydney.}.set TZData(:Australia/Canberra) $TZData(:Australia/Sydney).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8097
                                                                                                                                                                                                                                  Entropy (8bit):3.7668602204696375
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:GJiG+HuKIyymp8tLhbVXd33cZF7bLaE9DTtM/m7eeYWlQOZIeVUF:GJqXytLhbVXdnPQler
                                                                                                                                                                                                                                  MD5:7E0D1435E11C9AE84EF1A863D1D90C61
                                                                                                                                                                                                                                  SHA1:CE76A3D902221F0EF9D8C25EB2D46A63D0D09D0B
                                                                                                                                                                                                                                  SHA-256:3C0B35627729316A391C5A0BEE3A0E353A0BAEAD5E49CE7827E53D0F49FD6723
                                                                                                                                                                                                                                  SHA-512:D262294AC611396633184147B0F6656290BF97A298D6F7EC025E1D88AAC5343363744FD1CB849CDE84F3C1B2CF860CFA7CA43453ADBF68B0903DA1361F0DCD69
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Currie) {. {-9223372036854775808 34528 0 LMT}. {-2345794528 36000 0 AEST}. {-1680508800 39600 1 AEDT}. {-1669892400 39600 0 AEDT}. {-1665392400 36000 0 AEST}. {-883641600 39600 1 AEDT}. {-876128400 36000 0 AEST}. {-860400000 39600 1 AEDT}. {-844678800 36000 0 AEST}. {-828345600 39600 1 AEDT}. {-813229200 36000 0 AEST}. {47138400 36000 0 AEST}. {57686400 39600 1 AEDT}. {67968000 36000 0 AEST}. {89136000 39600 1 AEDT}. {100022400 36000 0 AEST}. {120585600 39600 1 AEDT}. {131472000 36000 0 AEST}. {152035200 39600 1 AEDT}. {162921600 36000 0 AEST}. {183484800 39600 1 AEDT}. {194976000 36000 0 AEST}. {215539200 39600 1 AEDT}. {226425600 36000 0 AEST}. {246988800 39600 1 AEDT}. {257875200 36000 0 AEST}. {278438400 39600 1 AEDT}. {289324800 36000 0 AEST}. {309888000 39600 1 AEDT}. {320774400 36000 0 AEST}. {341337600 39600 1 AEDT}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):422
                                                                                                                                                                                                                                  Entropy (8bit):4.4678452003570435
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52umdHPPZUj/sVdFFtf/FFAXFFwFFgh:cQuenZq/sVd/tH/AX/w/C
                                                                                                                                                                                                                                  MD5:FC9689FEF4223726207271E2EAAE6548
                                                                                                                                                                                                                                  SHA1:26D0B4FC2AD943FCAC90F179F7DF6C18EE12EBB8
                                                                                                                                                                                                                                  SHA-256:C556C796CCD3C63D9F694535287DC42BB63140C8ED39D31FDA0DA6E94D660A1C
                                                                                                                                                                                                                                  SHA-512:7898C0DE77297FBAA6AAF9D15CB9765DAF63ED4761BA181D0D1A590A6F19A6B7F6E94564A80EB691ED2D89C96D68449BF57816E4093E5011B93D30C3E1624D60
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Darwin) {. {-9223372036854775808 31400 0 LMT}. {-2364108200 32400 0 ACST}. {-2230189200 34200 0 ACST}. {-1672565340 37800 1 ACDT}. {-1665390600 34200 0 ACST}. {-883639800 37800 1 ACDT}. {-876126600 34200 0 ACST}. {-860398200 37800 1 ACDT}. {-844677000 34200 0 ACST}. {-828343800 37800 1 ACDT}. {-813227400 34200 0 ACST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):734
                                                                                                                                                                                                                                  Entropy (8bit):4.049000512576295
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp527JmdHvOYPV2oV2NF2AUV2ikUF2XV2ouwF2aUF2giV2XHVKF2qV2sF2jV2oA:cQ7JemssNLdUpouw5o5X0mszo4Ui/MXu
                                                                                                                                                                                                                                  MD5:F997E4624049132CEC09AC77FBA839E3
                                                                                                                                                                                                                                  SHA1:7BD0097EF75621646CE1969A61596F7FA2E75188
                                                                                                                                                                                                                                  SHA-256:C3E63F8BC7739A23C21DE71425EDDA7927C31D00BC9E23D3A265C93885248991
                                                                                                                                                                                                                                  SHA-512:B50EDBBA11D1B8FC7DF13A9DBDE9314E1694E36F2CB810C0160406406161CC8FD52BDBFD13D10EEABE2859FA7AEBC35EBF9AB826EB92BBF26D92EEDD15633649
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Eucla) {. {-9223372036854775808 30928 0 LMT}. {-2337928528 31500 0 +0945}. {-1672562640 35100 1 +0945}. {-1665387900 31500 0 +0945}. {-883637100 35100 1 +0945}. {-876123900 31500 0 +0945}. {-860395500 35100 1 +0945}. {-844674300 31500 0 +0945}. {-836473500 35100 0 +0945}. {152039700 35100 1 +0945}. {162926100 31500 0 +0945}. {436295700 35100 1 +0945}. {447182100 31500 0 +0945}. {690311700 35100 1 +0945}. {699383700 31500 0 +0945}. {1165079700 35100 1 +0945}. {1174756500 31500 0 +0945}. {1193505300 35100 1 +0945}. {1206810900 31500 0 +0945}. {1224954900 35100 1 +0945}. {1238260500 31500 0 +0945}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8325
                                                                                                                                                                                                                                  Entropy (8bit):3.767204262183229
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:8xKiG+HuKIyymp8tLhbVXd33cZF7bLaE9DTtM/m7eeYWlQOZIeVUF:8xKqXytLhbVXdnPQler
                                                                                                                                                                                                                                  MD5:67AF9A2B827308DD9F7ABEC9441C3250
                                                                                                                                                                                                                                  SHA1:CD87DD4181B41E66EFEA9C7311D5B7191F41EA3A
                                                                                                                                                                                                                                  SHA-256:814BD785B5ACDE9D2F4FC6E592E919BA0FE1C3499AFC1071B7FA02608B6032AB
                                                                                                                                                                                                                                  SHA-512:BC6B8CE215B3B4AC358EB989FB1BB5C6AD61B39B7BBD36AAA924A2352E823C029131E79DA927FEEBDD5CF759FDE527F39089C93B0826995D37052362BEAE09F6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Hobart) {. {-9223372036854775808 35356 0 LMT}. {-2345795356 36000 0 AEST}. {-1680508800 39600 1 AEDT}. {-1669892400 39600 0 AEDT}. {-1665392400 36000 0 AEST}. {-883641600 39600 1 AEDT}. {-876128400 36000 0 AEST}. {-860400000 39600 1 AEDT}. {-844678800 36000 0 AEST}. {-828345600 39600 1 AEDT}. {-813229200 36000 0 AEST}. {-94730400 36000 0 AEST}. {-71136000 39600 1 AEDT}. {-55411200 36000 0 AEST}. {-37267200 39600 1 AEDT}. {-25776000 36000 0 AEST}. {-5817600 39600 1 AEDT}. {5673600 36000 0 AEST}. {25632000 39600 1 AEDT}. {37728000 36000 0 AEST}. {57686400 39600 1 AEDT}. {67968000 36000 0 AEST}. {89136000 39600 1 AEDT}. {100022400 36000 0 AEST}. {120585600 39600 1 AEDT}. {131472000 36000 0 AEST}. {152035200 39600 1 AEDT}. {162921600 36000 0 AEST}. {183484800 39600 1 AEDT}. {194976000 36000 0 AEST}. {215539200 39600 1 AEDT}. {226
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):194
                                                                                                                                                                                                                                  Entropy (8bit):4.865814837459796
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3yIoGEowFVAIgjG/L2DCkx/2DCPGT:MBaIMje0QL2a7
                                                                                                                                                                                                                                  MD5:1221FC8932CA3DCA431304AF660840F0
                                                                                                                                                                                                                                  SHA1:5E023E37D98EA1321B10D36A79B26DF1A017F9D5
                                                                                                                                                                                                                                  SHA-256:EB8FDBCFDE9E2A2AA829E784D402966F61A5BF6F2034E0CB06A24FACB5B87874
                                                                                                                                                                                                                                  SHA-512:EB19FE74DC13456D0F9F1EDC9C444793A4011D3B65ADF6C7E7A405504079EB3A0C27F69DDA662F797FE363948E93833422F5DC3C1891AA7D414B062BE4DD3887
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Lord_Howe)]} {. LoadTimeZoneFile Australia/Lord_Howe.}.set TZData(:Australia/LHI) $TZData(:Australia/Lord_Howe).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):796
                                                                                                                                                                                                                                  Entropy (8bit):4.1890768067004
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52gCmdHVP/+tCdd8xdsWz9ag5J4UVdKcWW3ty/yJATUJrRxC:cQgCeRUVfl7w
                                                                                                                                                                                                                                  MD5:08E88B2169BC76172E40515F9DA2C147
                                                                                                                                                                                                                                  SHA1:5C03B7C9748E63C2B437C97F8ED923A9F3E374E7
                                                                                                                                                                                                                                  SHA-256:9E3558C8514E97274D9F938E9841C5E3355E738BBD55BCB17FA27FF0E0276AEA
                                                                                                                                                                                                                                  SHA-512:39E10639C97DE82428818B9C5D059BA853A17113351BAEE2512806AC3066EDDF0294859519AFBE425E0D1315B1A090F84C08CEFEDCE2A3D3A38EEF782234D8C4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Lindeman) {. {-9223372036854775808 35756 0 LMT}. {-2366790956 36000 0 AEST}. {-1672567140 39600 1 AEDT}. {-1665392400 36000 0 AEST}. {-883641600 39600 1 AEDT}. {-876128400 36000 0 AEST}. {-860400000 39600 1 AEDT}. {-844678800 36000 0 AEST}. {-828345600 39600 1 AEDT}. {-813229200 36000 0 AEST}. {31500000 36000 0 AEST}. {57686400 39600 1 AEDT}. {67968000 36000 0 AEST}. {625593600 39600 1 AEDT}. {636480000 36000 0 AEST}. {657043200 39600 1 AEDT}. {667929600 36000 0 AEST}. {688492800 39600 1 AEDT}. {699379200 36000 0 AEST}. {709912800 36000 0 AEST}. {719942400 39600 1 AEDT}. {731433600 36000 0 AEST}. {751996800 39600 1 AEDT}. {762883200 36000 0 AEST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7519
                                                                                                                                                                                                                                  Entropy (8bit):3.4688530726187112
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:zVjDVP0Izj1cdhsARcuhb4F3LbSZYt2U/gTpxxM3a6Z/nEgAmQso4QgDD:zv3qrcuhb4FbbCegi
                                                                                                                                                                                                                                  MD5:169FF1BE6B6407E853AAF9F6E9A9A047
                                                                                                                                                                                                                                  SHA1:C573582B8EF897D3AE5CA0FB089BE31F6ED076EB
                                                                                                                                                                                                                                  SHA-256:3C7C5CF7300957F73E9249FC8BF282F7CEE262849DD5D326F476E1AE8A7B8DD5
                                                                                                                                                                                                                                  SHA-512:BD8315022E8B190976FCED98252FCA0C248D857AC5045D741F6902871F0E3C158B248628DF9BA124A38AE878398F8BEA614254400F329D01F60EE50666AEE118
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Lord_Howe) {. {-9223372036854775808 38180 0 LMT}. {-2364114980 36000 0 AEST}. {352216800 37800 0 +1030}. {372785400 41400 1 +1030}. {384273000 37800 0 +1030}. {404839800 41400 1 +1030}. {415722600 37800 0 +1030}. {436289400 41400 1 +1030}. {447172200 37800 0 +1030}. {467739000 41400 1 +1030}. {478621800 37800 0 +1030}. {488984400 37800 0 +1030}. {499188600 39600 1 +1030}. {511282800 37800 0 +1030}. {530033400 39600 1 +1030}. {542732400 37800 0 +1030}. {562087800 39600 1 +1030}. {574786800 37800 0 +1030}. {594142200 39600 1 +1030}. {606236400 37800 0 +1030}. {625591800 39600 1 +1030}. {636476400 37800 0 +1030}. {657041400 39600 1 +1030}. {667926000 37800 0 +1030}. {688491000 39600 1 +1030}. {699375600 37800 0 +1030}. {719940600 39600 1 +1030}. {731430000 37800 0 +1030}. {751995000 39600 1 +1030}. {762879600 37800 0 +1030}. {78344
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8069
                                                                                                                                                                                                                                  Entropy (8bit):3.769669933493392
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:sriG+vi8GyddsYtLhbVXd33cZF7bLaE9DTtM/m7eeYWlQOZIeVUF:sr/2tLhbVXdnPQler
                                                                                                                                                                                                                                  MD5:E38FDAF8D9A9B1D6F2B1A8E10B9886F4
                                                                                                                                                                                                                                  SHA1:6188BD62E94194DB469BE93224A396D08A986D4D
                                                                                                                                                                                                                                  SHA-256:399F727CB39D90520AD6AE78A8963F918A490A813BC4FF2D94A37B0315F52D99
                                                                                                                                                                                                                                  SHA-512:79FDCFF5066636C3218751C8B2B658C6B7A6864264DCC28B47843EAEFDD5564AC5E4B7A66E3D1B0D25DB86D6C6ED55D1599F1FE2C169085A8769E037E0E954BE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Melbourne) {. {-9223372036854775808 34792 0 LMT}. {-2364111592 36000 0 AEST}. {-1672567140 39600 1 AEDT}. {-1665392400 36000 0 AEST}. {-883641600 39600 1 AEDT}. {-876128400 36000 0 AEST}. {-860400000 39600 1 AEDT}. {-844678800 36000 0 AEST}. {-828345600 39600 1 AEDT}. {-813229200 36000 0 AEST}. {31500000 36000 0 AEST}. {57686400 39600 1 AEDT}. {67968000 36000 0 AEST}. {89136000 39600 1 AEDT}. {100022400 36000 0 AEST}. {120585600 39600 1 AEDT}. {131472000 36000 0 AEST}. {152035200 39600 1 AEDT}. {162921600 36000 0 AEST}. {183484800 39600 1 AEDT}. {194976000 36000 0 AEST}. {215539200 39600 1 AEDT}. {226425600 36000 0 AEST}. {246988800 39600 1 AEDT}. {257875200 36000 0 AEST}. {278438400 39600 1 AEDT}. {289324800 36000 0 AEST}. {309888000 39600 1 AEDT}. {320774400 36000 0 AEST}. {341337600 39600 1 AEDT}. {352224000 36000 0 AEST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.8456659038249
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq/xJjLHVAIgoXjLSt2QWCCjREeQWCCjLu:SlSWB9IZaM3yI9HVAIgmo2DC5eDCyu
                                                                                                                                                                                                                                  MD5:AE3539C49047BE3F8ABAD1AC670975F1
                                                                                                                                                                                                                                  SHA1:62CD5C3DB618B9FE5630B197AB3A9729B565CA41
                                                                                                                                                                                                                                  SHA-256:938A557C069B8E0BE8F52D721119CBA9A694F62CF8A7A11D68FD230CC231E17C
                                                                                                                                                                                                                                  SHA-512:6F143B50C1EEC1D77F87DD5B0FFCF6625800E247400AA58361748BFEA0626E2CDA9C3FD2A4C269B3218D28FF1FB8533F4F6741F6B2C5E83F9C84A5882C86716B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Sydney)]} {. LoadTimeZoneFile Australia/Sydney.}.set TZData(:Australia/NSW) $TZData(:Australia/Sydney).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):187
                                                                                                                                                                                                                                  Entropy (8bit):4.780732237583773
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq/xJjboFVAIgoXjbhvN2QWCCjsrQWCCjb/:SlSWB9IZaM3yIiFVAIgg2DCZrDCy
                                                                                                                                                                                                                                  MD5:70EF2A87B4538500CFADB63B62DDCBC6
                                                                                                                                                                                                                                  SHA1:8D737E6E8D37323D3B41AD419F1CA9B5991E2E99
                                                                                                                                                                                                                                  SHA-256:59B67F2C7C62C5F9A93767898BA1B51315D2AC271075FAFC1A24313BB673FF27
                                                                                                                                                                                                                                  SHA-512:E148FC32894A7138D1547910CBD590891120CE5FB533D1348243539C35CE2994DC9F3E7B6A952BF871882C8D6ECA47E13E08AF59AB52A55F790508F2DB9B0EB6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Darwin)]} {. LoadTimeZoneFile Australia/Darwin.}.set TZData(:Australia/North) $TZData(:Australia/Darwin).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):714
                                                                                                                                                                                                                                  Entropy (8bit):4.257489685002088
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp52wmdHCBdPmzKfkzm2z75izhNhaP0YqozBqmjj4zl5fV59Bhg8lfU:cQweCBpYd7IzrhaMYR8mP4znhf9U
                                                                                                                                                                                                                                  MD5:B354B9525896FDED8769CF5140E76FFF
                                                                                                                                                                                                                                  SHA1:8494E182E3803F2A6369261B4B4EAC184458ECC4
                                                                                                                                                                                                                                  SHA-256:C14CAAD41E99709ABF50BD7F5B1DAFE630CA494602166F527DBDA7C134017FB0
                                                                                                                                                                                                                                  SHA-512:717081F29FBACEE2722399DD627045B710C14CF6021E4F818B1768AF972061232412876872F113C468446D79A366D7FFD2E852563DC44A483761D78C7A16F74A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Perth) {. {-9223372036854775808 27804 0 LMT}. {-2337925404 28800 0 AWST}. {-1672559940 32400 1 AWDT}. {-1665385200 28800 0 AWST}. {-883634400 32400 1 AWDT}. {-876121200 28800 0 AWST}. {-860392800 32400 1 AWDT}. {-844671600 28800 0 AWST}. {-836470800 32400 0 AWST}. {152042400 32400 1 AWDT}. {162928800 28800 0 AWST}. {436298400 32400 1 AWDT}. {447184800 28800 0 AWST}. {690314400 32400 1 AWDT}. {699386400 28800 0 AWST}. {1165082400 32400 1 AWDT}. {1174759200 28800 0 AWST}. {1193508000 32400 1 AWDT}. {1206813600 28800 0 AWST}. {1224957600 32400 1 AWDT}. {1238263200 28800 0 AWST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):198
                                                                                                                                                                                                                                  Entropy (8bit):4.75392731256171
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3yIaWhvFVAIgPWzCxL2DCoRWJvFBx+DC7W6:MBaIMjoTL2rOvFey
                                                                                                                                                                                                                                  MD5:D12C6F15F8BFCA19FA402DAE16FC9529
                                                                                                                                                                                                                                  SHA1:0869E6D11681D74CC3301F4538D98A225BE7C2E1
                                                                                                                                                                                                                                  SHA-256:77EA0243A11D187C995CE8D83370C6682BC39D2C39809892A48251123FF19A1E
                                                                                                                                                                                                                                  SHA-512:A98D1AF1FC3E849CCF9E9CC090D3C65B7104C164762F88B6048EA2802F17D635C2E66BE2661338C1DD604B550A267678245DE867451A1412C4C06411A21BE3A9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Brisbane)]} {. LoadTimeZoneFile Australia/Brisbane.}.set TZData(:Australia/Queensland) $TZData(:Australia/Brisbane).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):193
                                                                                                                                                                                                                                  Entropy (8bit):4.701653352722385
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3yIDRpGvFVAIgSRFL2DCa7QDCuRpv:MBaIMjdp5YFL23QHpv
                                                                                                                                                                                                                                  MD5:23671880AC24D35F231E2FCECC1A5E3A
                                                                                                                                                                                                                                  SHA1:5EE2EFD5ADE268B5114EB02FDA77F4C5F507F3CB
                                                                                                                                                                                                                                  SHA-256:9823032FFEB0BFCE50B6261A848FE0C07267E0846E9F7487AE812CEECB286446
                                                                                                                                                                                                                                  SHA-512:E303C7DE927E7BAA10EE072D5308FEE6C4E9B2D69DDD8EF014ED60574E0855EE803FE19A7CB31587E62CAE894C087D47A91A130213A24FCCD152736D82F55AB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Adelaide)]} {. LoadTimeZoneFile Australia/Adelaide.}.set TZData(:Australia/South) $TZData(:Australia/Adelaide).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8066
                                                                                                                                                                                                                                  Entropy (8bit):3.763781985138297
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:GZCiG+CiRyddsYtLhbVXd33cZF7bLaE9DTtM/m7eeYWlQOZIeVUF:GZCm2tLhbVXdnPQler
                                                                                                                                                                                                                                  MD5:B3498EEA194DDF38C732269A47050CAA
                                                                                                                                                                                                                                  SHA1:C32B703AA1FA34D890D151300A2B21E0FA8F55D3
                                                                                                                                                                                                                                  SHA-256:0EE9BE0F0D6EC0CE10DEA1BE7A9F494C74B747418E966B85EC1FFB15F6F22A4F
                                                                                                                                                                                                                                  SHA-512:A9419B797B1518AAEEE27A1796D0D024847F7A61D26238F1643EBD6131A6B36007FBABD9E766C3D4ED61B006FD31FC4555CB54B8681E7DBDEC26B38144D64BC9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Australia/Sydney) {. {-9223372036854775808 36292 0 LMT}. {-2364113092 36000 0 AEST}. {-1672567140 39600 1 AEDT}. {-1665392400 36000 0 AEST}. {-883641600 39600 1 AEDT}. {-876128400 36000 0 AEST}. {-860400000 39600 1 AEDT}. {-844678800 36000 0 AEST}. {-828345600 39600 1 AEDT}. {-813229200 36000 0 AEST}. {31500000 36000 0 AEST}. {57686400 39600 1 AEDT}. {67968000 36000 0 AEST}. {89136000 39600 1 AEDT}. {100022400 36000 0 AEST}. {120585600 39600 1 AEDT}. {131472000 36000 0 AEST}. {152035200 39600 1 AEDT}. {162921600 36000 0 AEST}. {183484800 39600 1 AEDT}. {194976000 36000 0 AEST}. {215539200 39600 1 AEDT}. {226425600 36000 0 AEST}. {246988800 39600 1 AEDT}. {257875200 36000 0 AEST}. {278438400 39600 1 AEDT}. {289324800 36000 0 AEST}. {309888000 39600 1 AEDT}. {320774400 36000 0 AEST}. {341337600 39600 1 AEDT}. {352224000 36000 0 AEST}. {3
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                  Entropy (8bit):4.7264864039237215
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq/xJjKD4YFedVAIgoXjKgVAt2QWCCjiiieQWCCjKDvn:SlSWB9IZaM3yI4DVyVAIgxkAt2DC3ne0
                                                                                                                                                                                                                                  MD5:C7C9CDC9EC855D2F0C23673FA0BAFFB6
                                                                                                                                                                                                                                  SHA1:4C79E1C17F418CEE4BE8F638F34201EE843D8E28
                                                                                                                                                                                                                                  SHA-256:014B3D71CE6BD77AD653047CF185EA03C870D78196A236693D7610FED7F30B6F
                                                                                                                                                                                                                                  SHA-512:79AE11CE076BFB87C0AAD35E9AF6E760FC592F1D086EB78E6DF88744F502ED4248853A0EAD72ADA8EA9583161925802EE5E46E3AA8CE8CF873852C26B4FDC05B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Hobart)]} {. LoadTimeZoneFile Australia/Hobart.}.set TZData(:Australia/Tasmania) $TZData(:Australia/Hobart).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):199
                                                                                                                                                                                                                                  Entropy (8bit):4.7697171393457936
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3yIvFfkvFVAIgoFFL2DCzyQDCMFB:MBaIMj9fHaFL2xQzB
                                                                                                                                                                                                                                  MD5:BD2EA272B8DF472E29B7DD0506287E92
                                                                                                                                                                                                                                  SHA1:55BF3A3B6398F9FF1DB3A46998A4EFF44F6F325C
                                                                                                                                                                                                                                  SHA-256:EE35DF8BBCD6A99A5550F67F265044529BD7AF6A83087DD73CA0BE1EE5C8BF51
                                                                                                                                                                                                                                  SHA-512:82B18D2C9BA7113C2714DC79A87101FFB0C36E5520D61ADEAB8A31AD219E51A6402A6C8A8FD7120A330FE8847FF8F083397A1BF5889B73484FBAA6F99497DE48
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Melbourne)]} {. LoadTimeZoneFile Australia/Melbourne.}.set TZData(:Australia/Victoria) $TZData(:Australia/Melbourne).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):183
                                                                                                                                                                                                                                  Entropy (8bit):4.781808870279912
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq/xJjXFedVAIgoXjbOAt2QWCCjH0QWCCj5:SlSWB9IZaM3yIYVAIg9At2DC00DCa
                                                                                                                                                                                                                                  MD5:9E0EF0058DDA86016547F2BFE421DE74
                                                                                                                                                                                                                                  SHA1:5DB6AEAC6B0A42FEAE28BB1A45679BC235F4E5BF
                                                                                                                                                                                                                                  SHA-256:FC952BE48F11362981CDC8859F9C634312E5805F2F1513159F25AEFCE664867C
                                                                                                                                                                                                                                  SHA-512:C60E5A63378F8424CE8D862A575DFE138646D5E88C6A34562A77BEC4B34EA3ED3085424E2130E610197164C7E88805DC6CDE46416EB45DC256F387F632F48CA7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Perth)]} {. LoadTimeZoneFile Australia/Perth.}.set TZData(:Australia/West) $TZData(:Australia/Perth).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):207
                                                                                                                                                                                                                                  Entropy (8bit):4.871861105493913
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3yIcKCFVAIgJKfF2DCkuM0DC9Kl:MBaIMjcKCQJKt2kVSKl
                                                                                                                                                                                                                                  MD5:5C3CED24741704A0A7019FA66AC0C0A1
                                                                                                                                                                                                                                  SHA1:88C7AF3B22ED01ED99784C3FAB4F5112AA4659F3
                                                                                                                                                                                                                                  SHA-256:71A56C71CC30A46950B1B4D4FBB12CB1CBAA24267F994A0F223AE879F1BB6EEC
                                                                                                                                                                                                                                  SHA-512:771A7AC5D03DD7099F565D6E926F7B97E8A7BA3795339D3FD78F7C465005B55388D8CC30A62978042C354254E1BA5467D0832C0D29497E33D6EF1DA217528806
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Australia/Broken_Hill)]} {. LoadTimeZoneFile Australia/Broken_Hill.}.set TZData(:Australia/Yancowinna) $TZData(:Australia/Broken_Hill).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):189
                                                                                                                                                                                                                                  Entropy (8bit):4.84045343046357
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0sMhS4edVAIg20sMhStQ1bNW1h4IAcGEsMhSA:SlSWB9IZaM3y7thtedVAIgpthKQxWh4y
                                                                                                                                                                                                                                  MD5:DF4D752BEEAF40F081C03B4572E9D858
                                                                                                                                                                                                                                  SHA1:A83B5E4C3A9EB0CF43263AFF65DB374353F65595
                                                                                                                                                                                                                                  SHA-256:1B1AD73D3FE403AA1F939F05F613F6A3F39A8BA49543992D836CD6ED14B92F2C
                                                                                                                                                                                                                                  SHA-512:1F96F1D8AACD6D37AC13295B345E761204DAE6AA1DF4894A11E00857CCB7247FA7BEBD22407EA5D13193E2945EB1F4210E32669069F157F1459B26643A67F445
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Rio_Branco)]} {. LoadTimeZoneFile America/Rio_Branco.}.set TZData(:Brazil/Acre) $TZData(:America/Rio_Branco).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.826795532956443
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0wKy4oedVAIg20wK+F1bIAJl0IAcGEwKyvn:SlSWB9IZaM3y7/rDdVAIgp/mxIAE90/8
                                                                                                                                                                                                                                  MD5:86B9E49F604AD5DBC4EC6BA735A513C7
                                                                                                                                                                                                                                  SHA1:BE3AB32339DF9830D4F445CCF883D79DDBA8708E
                                                                                                                                                                                                                                  SHA-256:628A9AE97682B98145588E356948996EAE18528E34A1428A6B2765CCAA7A8A1F
                                                                                                                                                                                                                                  SHA-512:EE312624EC0193C599B2BDBFA57CC4EA7C68890955E0D888149172DF8F2095C553BFBB80BF76C1B8F3232F3A5863A519FF59976BBAEA622C64737890D159AA22
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Noronha)]} {. LoadTimeZoneFile America/Noronha.}.set TZData(:Brazil/DeNoronha) $TZData(:America/Noronha).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):186
                                                                                                                                                                                                                                  Entropy (8bit):4.9019570219911275
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0tQJXvedVAIg20tQJX1bJHIAcGEtQJXv:SlSWB9IZaM3y7tIGdVAIgptExR90tIv
                                                                                                                                                                                                                                  MD5:FBF6B9E8B9C93B1B9E484D88EF208F38
                                                                                                                                                                                                                                  SHA1:44004E19A485B70E003687CB1057B8A2421D1BF0
                                                                                                                                                                                                                                  SHA-256:C89E831C4A0525C3CEFF17072843386369096C08878A4412FB208EF5D3F156D8
                                                                                                                                                                                                                                  SHA-512:4E518FC4CED0C756FF45E0EDE72F6503C4B3AE72E785651DE261D3F261D43F914721EFCEAB272398BC145E41827F35D46DE4E022EAF413D95F64E8B3BD752002
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Sao_Paulo)]} {. LoadTimeZoneFile America/Sao_Paulo.}.set TZData(:Brazil/East) $TZData(:America/Sao_Paulo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.853909262702622
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0znQZFwFVAIg20znQoCxL1bbAWVIAcGEznQb:SlSWB9IZaM3y7zn+wFVAIgpznzCxLxnJ
                                                                                                                                                                                                                                  MD5:116F0F146B004D476B6B86EC0EE2D54D
                                                                                                                                                                                                                                  SHA1:1F39A84EF3DFF676A844174D9045BE388D3BA8C0
                                                                                                                                                                                                                                  SHA-256:F24B9ED1FAFA98CD7807FFFEF4BACA1BCE1655ABD70EB69D46478732FA0DA573
                                                                                                                                                                                                                                  SHA-512:23BD7EC1B5ADB465A204AAA35024EE917F8D6C3136C4EA973D8B18B586282C4806329CEBE0EDBF9E13D0032063C8082EC0D84A049F1217C856943A4DDC4900D0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Manaus)]} {. LoadTimeZoneFile America/Manaus.}.set TZData(:Brazil/West) $TZData(:America/Manaus).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7471
                                                                                                                                                                                                                                  Entropy (8bit):3.710275786382764
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:ht6CvDGwdSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQlth:PSTRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:AE72690EF7063F0B9F640096204E2ECE
                                                                                                                                                                                                                                  SHA1:4F815B51DA9BCA97DFF71D191B74D0190890F946
                                                                                                                                                                                                                                  SHA-256:BB2C5E587EE9F9BF85C1D0B6F57197985663D4DFF0FED13233953C1807A1F11C
                                                                                                                                                                                                                                  SHA-512:F7F0911251BC7191754AF0BA2C455E825BF16EA9202A740DC1E07317B1D74CDAF680E161155CC1BD5E862DCEE2A58101F419D8B5E0E24C4BA7134999D9B55C48
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:CET) {. {-9223372036854775808 3600 0 CET}. {-1693706400 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-938905200 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-781052400 7200 1 CEST}. {-766623600 3600 0 CET}. {228877200 7200 1 CEST}. {243997200 3600 0 CET}. {260326800 7200 1 CEST}. {276051600 3600 0 CET}. {291776400 7200 1 CEST}. {307501200 3600 0 CET}. {323830800 7200 1 CEST}. {338950800 3600 0 CET}. {354675600 7200 1 CEST}. {370400400 3600 0 CET}. {386125200 7200 1 CEST}. {401850000 3600 0 CET}. {417574800 7200 1 CEST}. {433299600 3600 0 CET}. {449024400 7200 1 CEST}. {465354000 3600 0 CET}. {481078800 7200 1 CEST}. {496803600 3600 0 CET
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8227
                                                                                                                                                                                                                                  Entropy (8bit):3.723597525146651
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:KxrIOdXkqbfkeTzZSJw5/9/yuvQ+hcrD57X0N41+IestuNEbYkzbXwDTIRqfhXbo:KxrIOdXkqbfNTzZSJw5/9/yuvQ6crD5r
                                                                                                                                                                                                                                  MD5:B5AC3FA83585957217CA04384171F0FF
                                                                                                                                                                                                                                  SHA1:827FF1FBDADDDE3754453E680B4E719A50499AE6
                                                                                                                                                                                                                                  SHA-256:17CBE2F211973F827E0D5F9F2B4365951164BC06DA065F6F38F45CB064B29457
                                                                                                                                                                                                                                  SHA-512:A56485813C47758F988A250FFA97E2DBD7A69DDD16034E9EF2834AF895E8A374EEB4DA3F36E6AD80285AC10F84543ECF5840670805082E238F822F85D635651F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:CST6CDT) {. {-9223372036854775808 -21600 0 CST}. {-1633276800 -18000 1 CDT}. {-1615136400 -21600 0 CST}. {-1601827200 -18000 1 CDT}. {-1583686800 -21600 0 CST}. {-880214400 -18000 1 CWT}. {-769395600 -18000 1 CPT}. {-765392400 -21600 0 CST}. {-84384000 -18000 1 CDT}. {-68662800 -21600 0 CST}. {-52934400 -18000 1 CDT}. {-37213200 -21600 0 CST}. {-21484800 -18000 1 CDT}. {-5763600 -21600 0 CST}. {9964800 -18000 1 CDT}. {25686000 -21600 0 CST}. {41414400 -18000 1 CDT}. {57740400 -21600 0 CST}. {73468800 -18000 1 CDT}. {89190000 -21600 0 CST}. {104918400 -18000 1 CDT}. {120639600 -21600 0 CST}. {126691200 -18000 1 CDT}. {152089200 -21600 0 CST}. {162374400 -18000 1 CDT}. {183538800 -21600 0 CST}. {199267200 -18000 1 CDT}. {215593200 -21600 0 CST}. {230716800 -18000 1 CDT}. {247042800 -21600 0 CST}. {262771200 -18000 1 CDT}. {278492400 -216
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.754307292225081
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx02NEO4FVAIg202NEtYF0nalGe2IAcGE2NEOv:SlSWB9IZaM3y7UEO4FVAIgpUEqF0af2b
                                                                                                                                                                                                                                  MD5:B0E220B9CD16038AAF3EA21D60064B62
                                                                                                                                                                                                                                  SHA1:333410CB7D4F96EF836CDC8097A1DCE34A2B961A
                                                                                                                                                                                                                                  SHA-256:6F71D7ED827C9EF6E758A44D2A998673E1225EB8005AD557A1713F5894833F92
                                                                                                                                                                                                                                  SHA-512:F879F60E36C739280E8FC255D2792BB24BCA90A265F8F90B5FB85630D5A58CE4FDBD24EA5594924375C3CD31DBC6D49C06CBFA43C52D0B9A1E9D799914A164F7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Halifax)]} {. LoadTimeZoneFile America/Halifax.}.set TZData(:Canada/Atlantic) $TZData(:America/Halifax).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):186
                                                                                                                                                                                                                                  Entropy (8bit):4.814426408072182
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0po4FVAIg20peRL0nPQox/h4IAcGEpov:SlSWB9IZaM3y7phFVAIgppOL0d490py
                                                                                                                                                                                                                                  MD5:8374E381BC8235B11B7C5CA215FA112C
                                                                                                                                                                                                                                  SHA1:181298556253D634B09D72BD925C4DBB92055A06
                                                                                                                                                                                                                                  SHA-256:1B87273B264A3243D2025B1CFC05B0797CBC4AA95D3319EEE2BEF8A09FDA8CAD
                                                                                                                                                                                                                                  SHA-512:12800E49B8094843F66454E270B4BE154B053E5FB453C83269AF7C27B965071C88B02AF7BB404E7F5A07277DB45E58D1C5240B377FC06172087BB29749C7543B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Winnipeg)]} {. LoadTimeZoneFile America/Winnipeg.}.set TZData(:Canada/Central) $TZData(:America/Winnipeg).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                  Entropy (8bit):4.860347334610986
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0sAzE5YyVAIg20sAzEvYvW60nbP2/8S64IAcGEsAz1:SlSWB9IZaM3y7hzipVAIgphzGCW60L5X
                                                                                                                                                                                                                                  MD5:F5CB42BC029315088FAD03C9235FFB51
                                                                                                                                                                                                                                  SHA1:7773ECE0B85D66E4FA207A26EE4395F38BAC4068
                                                                                                                                                                                                                                  SHA-256:AF04A4558E31C9864B92FE3403011F7A2FBD837E1314A7BB5AF552D5AED06457
                                                                                                                                                                                                                                  SHA-512:0533B9D98834866FAA3C6E67A6F61A8A22C2BFDBA8C5336388C0894FBA550611C9112515F17E20E7B3508EC2318D58EA7CA814EC10C3451954C3CC169EDA0F8C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Regina)]} {. LoadTimeZoneFile America/Regina.}.set TZData(:Canada/East-Saskatchewan) $TZData(:America/Regina).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):183
                                                                                                                                                                                                                                  Entropy (8bit):4.7067203041014185
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0qMKLRXIVAIg20qMKLRI60nbHboxp4IAcGEqMKLRXv:SlSWB9IZaM3y7RQ+VAIgpRQ+60Dboxp2
                                                                                                                                                                                                                                  MD5:22453AC70F84F34868B442E0A7BDC20A
                                                                                                                                                                                                                                  SHA1:730049FF6953E186C197601B27AB850305961FD0
                                                                                                                                                                                                                                  SHA-256:545B992E943A32210F768CB86DEF3203BE956EE03A3B1BC0D55A5CD18A4F064D
                                                                                                                                                                                                                                  SHA-512:91FE33FAD3954019F632A771BCBD9FF3FDCCDA1F51DD25E0E5808A724F2D9B905E5E2DEE32D415BEA9A9ADB74186D83548584414BB130DF1A166D49373AC7BEF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Toronto)]} {. LoadTimeZoneFile America/Toronto.}.set TZData(:Canada/Eastern) $TZData(:America/Toronto).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):187
                                                                                                                                                                                                                                  Entropy (8bit):4.768148288986999
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx07nKL5zFVAIg207nKLKN0nNYLo/4IAcGE7nKLun:SlSWB9IZaM3y77GzFVAIgp7DN0W8/49s
                                                                                                                                                                                                                                  MD5:5E0D3D1A7E9F800210BB3E02DFF2ECD3
                                                                                                                                                                                                                                  SHA1:F2471795A9314A292DEAA3F3B94145D3DE5A2792
                                                                                                                                                                                                                                  SHA-256:A8B3A4D53AA1CC73312E80951A9E9CEA162F4F51DA29B897FEB58B2DF3431821
                                                                                                                                                                                                                                  SHA-512:F80C7CDFE20E5FAD9E4BA457446F067ACE0C3F4659761E3B4A2422D3456CDE92C20589954DE5E0DC64619E3B6AB3A55AE0E0E783F8EFB24D74A5F6DFBF5ABB16
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Edmonton)]} {. LoadTimeZoneFile America/Edmonton.}.set TZData(:Canada/Mountain) $TZData(:America/Edmonton).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):191
                                                                                                                                                                                                                                  Entropy (8bit):4.953647576523321
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0tVZMYFwFVAIg20tVZoYvxL0nJBJi6FBx/2IAcGEt3:SlSWB9IZaM3y7tgYmFVAIgptMqL0xdB7
                                                                                                                                                                                                                                  MD5:3A4E193C8624AE282739867B22B7270A
                                                                                                                                                                                                                                  SHA1:AC93EEDA7E8AB7E40834FFBA83BAE5D803CB7162
                                                                                                                                                                                                                                  SHA-256:70EF849809F72741FA4F37C04C102A8C6733639E905B4E7F554F1D94737BF26B
                                                                                                                                                                                                                                  SHA-512:BE2AACEE2A6F74520F4F1C0CCBBB750ED6C7375D4368023BAB419184F8F717D52981106C03F487B24A943907E60784136C0E5F8C1D5B3D1C67C20E23A4F412B3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/St_Johns)]} {. LoadTimeZoneFile America/St_Johns.}.set TZData(:Canada/Newfoundland) $TZData(:America/St_Johns).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):189
                                                                                                                                                                                                                                  Entropy (8bit):4.839589386398345
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0oELSTAWFwVAIg20oELSTAQO0L0nie2IAcGEoELSTH:SlSWB9IZaM3y7ZLgXwVAIgpZLgJJL0Nu
                                                                                                                                                                                                                                  MD5:6AA0FCE594E991D6772C04E137C7BE00
                                                                                                                                                                                                                                  SHA1:6C53EE6FEBEC2BD5271DD80D40146247E779CB7B
                                                                                                                                                                                                                                  SHA-256:D2858621DA914C3F853E399F0819BA05BDE68848E78F59695B84B2B83C1FDD2A
                                                                                                                                                                                                                                  SHA-512:7B354BB9370BB61EB0E801A1477815865FDE51E6EA43BF166A6B1EED127488CC25106DEE1C6C5DC1EF3E13E9819451E10AFBC0E189D3D3CDE8AFFA4334C77CA3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Vancouver)]} {. LoadTimeZoneFile America/Vancouver.}.set TZData(:Canada/Pacific) $TZData(:America/Vancouver).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.83938055689947
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0sAzE5YyVAIg20sAzEvYvW60nogS64IAcGEsAzEun:SlSWB9IZaM3y7hzipVAIgphzGCW60Hd9
                                                                                                                                                                                                                                  MD5:927FD3986F83A60C217A3006F65A3B0A
                                                                                                                                                                                                                                  SHA1:022D118024BFC5AE0922A1385288C3E4B41903DB
                                                                                                                                                                                                                                  SHA-256:BB457E954DB625A8606DD0F372DA9BFFAA01F774B4B82A2B1CEE2E969C15ABC3
                                                                                                                                                                                                                                  SHA-512:3EA932FA5416A9C817977F9D31C8A15C937A453B4D6A6409A7966E76D66A685C91F1117C82BEBEBA2AF5516556DA2BDEC898AD718C78FB8B690F31692174DA6C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Regina)]} {. LoadTimeZoneFile America/Regina.}.set TZData(:Canada/Saskatchewan) $TZData(:America/Regina).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                  Entropy (8bit):4.841592909599599
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0peR2pVkvFVAIg20peR2zxL0nTOK8x/h4IAcGEpeRu:SlSWB9IZaM3y7peR2fkvFVAIgppeR2FF
                                                                                                                                                                                                                                  MD5:9F2A7F0D8492F67F764F647638533C3F
                                                                                                                                                                                                                                  SHA1:3785DACD1645E0630649E411DC834E8A4FB7F40B
                                                                                                                                                                                                                                  SHA-256:F2A81B7E95D49CEC3C8952463B727129B4DC43D58ADC64BB7CAB642D3D191039
                                                                                                                                                                                                                                  SHA-512:0133870BB96851ECD486D55FD10EB4BCB1678772C1BFFADE85FC5644AC8445CDB4C6284BEFFED197E9386C9C6EF74F5F718F2CB43C4C7B8E65FE413C8EC51CD0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Whitehorse)]} {. LoadTimeZoneFile America/Whitehorse.}.set TZData(:Canada/Yukon) $TZData(:America/Whitehorse).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):189
                                                                                                                                                                                                                                  Entropy (8bit):4.762021566751952
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0tfEJ5YyVAIg20tfEJvYvWAt0dKLRMyREGH/h4IAcB:SlSWB9IZaM3y7tfEJHVAIgptfEJAvN0+
                                                                                                                                                                                                                                  MD5:B2BDB6C027FF34D624EA8B992E5F41AB
                                                                                                                                                                                                                                  SHA1:425AB0D603C3F5810047A7DC8FD28FDF306CC2DB
                                                                                                                                                                                                                                  SHA-256:F2E3C1E88C5D165E1D38B0D2766D64AA4D2E6996DF1BE58DADC9C4FC4F503A2E
                                                                                                                                                                                                                                  SHA-512:6E5A8DC6F5D5F0218C37EE719441EBDC7EDED3708F8705A98AEF7E256C8DC5D82F4BF82C529282E01D8E6E669C4F843B143730AD9D8BBF43BCC98ECB65B52C9B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Santiago)]} {. LoadTimeZoneFile America/Santiago.}.set TZData(:Chile/Continental) $TZData(:America/Santiago).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.758503564906338
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG7ZAJpVAIgObT7ZA6xL0bxOdBx/nUDH7ZAen:SlSWB9IZaM3ycJA3VAIgObJA6xL04dB4
                                                                                                                                                                                                                                  MD5:E9DF5E3D9E5E242A1B9C73D8F35C9911
                                                                                                                                                                                                                                  SHA1:9905EF3C1847CFF8156EC745779FCF0D920199B7
                                                                                                                                                                                                                                  SHA-256:AA305BEC168C0A5C8494B81114D69C61A0D3CF748995AF5CCC3E2591AC78C90C
                                                                                                                                                                                                                                  SHA-512:7707AC84D5C305F40A1713F1CBBED8A223553A5F989281CCDB278F0BD0D408E6FC9396D9FA0CCC82168248A30362D2D4B27EDEF36D9A3D70E286A5B668686FDE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Easter)]} {. LoadTimeZoneFile Pacific/Easter.}.set TZData(:Chile/EasterIsland) $TZData(:Pacific/Easter).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):170
                                                                                                                                                                                                                                  Entropy (8bit):4.8073098952422395
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx02TEMVFwVAIg202TEKN0lIAcGE2TEMv:SlSWB9IZaM3y76EHVAIgp6EKN0l906Eu
                                                                                                                                                                                                                                  MD5:BA8EE8511A2013E791A3C50369488588
                                                                                                                                                                                                                                  SHA1:03BF30F56FB604480A9F5ECD8FB13E3CF82F4524
                                                                                                                                                                                                                                  SHA-256:2F9DFE275B62EFBCD5F72D6A13C6BB9AFD2F67FDDD8843013D128D55373CD677
                                                                                                                                                                                                                                  SHA-512:29C9E9F4B9679AFD688A90A605CFC1D7B86514C4966E2196A4A5D48D4F1CF16775DFBDF1C9793C3BDAA13B6986765531B2E11398EFE5662EEDA7B37110697832
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Havana)]} {. LoadTimeZoneFile America/Havana.}.set TZData(:Cuba) $TZData(:America/Havana).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7189
                                                                                                                                                                                                                                  Entropy (8bit):3.6040923024580884
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:WB8kMKVCy+Hk+PVqVaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lf:AroXPzh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:9AE4C7EC014649393D354B02DF00F8B9
                                                                                                                                                                                                                                  SHA1:D82195DEF49CFFEAB3791EA70E6D1BB8BC113155
                                                                                                                                                                                                                                  SHA-256:4CB6582052BE7784DD08CE7FD97ACC56234F07BCF80B69E57111A8F88454908E
                                                                                                                                                                                                                                  SHA-512:6F0C138AF98A4D4A1028487C29267088BD4C0EC9E7C1DB9818FA31A61C9584B67B3F5909C6E6FDB0F7183629E892A77BA97654D39FCE7DDEF6908F8146B7BE72
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:EET) {. {-9223372036854775808 7200 0 EET}. {228877200 10800 1 EEST}. {243997200 7200 0 EET}. {260326800 10800 1 EEST}. {276051600 7200 0 EET}. {291776400 10800 1 EEST}. {307501200 7200 0 EET}. {323830800 10800 1 EEST}. {338950800 7200 0 EET}. {354675600 10800 1 EEST}. {370400400 7200 0 EET}. {386125200 10800 1 EEST}. {401850000 7200 0 EET}. {417574800 10800 1 EEST}. {433299600 7200 0 EET}. {449024400 10800 1 EEST}. {465354000 7200 0 EET}. {481078800 10800 1 EEST}. {496803600 7200 0 EET}. {512528400 10800 1 EEST}. {528253200 7200 0 EET}. {543978000 10800 1 EEST}. {559702800 7200 0 EET}. {575427600 10800 1 EEST}. {591152400 7200 0 EET}. {606877200 10800 1 EEST}. {622602000 7200 0 EET}. {638326800 10800 1 EEST}. {654656400 7200 0 EET}. {670381200 10800 1 EEST}. {686106000 7200 0 EET}. {701830800 10800 1 EEST}. {717555600 7200 0 EET}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):106
                                                                                                                                                                                                                                  Entropy (8bit):4.879680803636454
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yLWkXGm2OHLVvain:SlSWB9X5y2m2OHLViin
                                                                                                                                                                                                                                  MD5:33221E0807873CC5E16A55BF4450B6D4
                                                                                                                                                                                                                                  SHA1:A01FD9D1B8E554EE7A25473C2FBECA3B08B7FD02
                                                                                                                                                                                                                                  SHA-256:5AA7D9865554BCE546F1846935C5F68C9CA806B29B6A45765BA55E09B14363E4
                                                                                                                                                                                                                                  SHA-512:54A33B239BBFCFC645409FBC8D9DDBFCAE56067FA0427D0BE5F49CB32EB8EEC8E43FC22CE1C083FDC17DD8591BE9DB28A2D5006AFA473F10FB17EF2CE7AED305
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:EST) {. {-9223372036854775808 -18000 0 EST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8227
                                                                                                                                                                                                                                  Entropy (8bit):3.723178863172678
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:W4UwdaC3Xm8sHRwvOTFhP5S+ijFnRaJeaX1eyDt:Cwdrn+qvOTFhPI1jFIL
                                                                                                                                                                                                                                  MD5:1A7BDED5B0BADD36F76E1971562B3D3B
                                                                                                                                                                                                                                  SHA1:CF5BB82484C4522B178E25D14A42B3DBE02D987D
                                                                                                                                                                                                                                  SHA-256:AFD2F12E50370610EA61BA9DD3838129785DFDEE1EBCC4E37621B54A4CF2AE3F
                                                                                                                                                                                                                                  SHA-512:4803A906E2C18A2792BF812B8D26C936C71D8A9DD9E87F7DA06630978FCB5DE1094CD20458D37973AA9967D51B97F94A5785B7B15F807E526C13D018688F16D9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:EST5EDT) {. {-9223372036854775808 -18000 0 EST}. {-1633280400 -14400 1 EDT}. {-1615140000 -18000 0 EST}. {-1601830800 -14400 1 EDT}. {-1583690400 -18000 0 EST}. {-880218000 -14400 1 EWT}. {-769395600 -14400 1 EPT}. {-765396000 -18000 0 EST}. {-84387600 -14400 1 EDT}. {-68666400 -18000 0 EST}. {-52938000 -14400 1 EDT}. {-37216800 -18000 0 EST}. {-21488400 -14400 1 EDT}. {-5767200 -18000 0 EST}. {9961200 -14400 1 EDT}. {25682400 -18000 0 EST}. {41410800 -14400 1 EDT}. {57736800 -18000 0 EST}. {73465200 -14400 1 EDT}. {89186400 -18000 0 EST}. {104914800 -14400 1 EDT}. {120636000 -18000 0 EST}. {126687600 -14400 1 EDT}. {152085600 -18000 0 EST}. {162370800 -14400 1 EDT}. {183535200 -18000 0 EST}. {199263600 -14400 1 EDT}. {215589600 -18000 0 EST}. {230713200 -14400 1 EDT}. {247039200 -18000 0 EST}. {262767600 -14400 1 EDT}. {278488800 -180
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):165
                                                                                                                                                                                                                                  Entropy (8bit):4.812476042768195
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsPHVyVAIgNGE7JW6yCh0DcPHv:SlSWB9IZaM3y7AVAIgNTFW6yg0DY
                                                                                                                                                                                                                                  MD5:3708D7ED7044DE74B8BE5EBD7314371B
                                                                                                                                                                                                                                  SHA1:5DDC75C6204D1A2A59C8441A8CAF609404472895
                                                                                                                                                                                                                                  SHA-256:07F4B09FA0A1D0BA63E17AD682CAD9535592B372815AB8FD4884ACD92EC3D434
                                                                                                                                                                                                                                  SHA-512:A8761601CD9B601E0CE8AC35B6C7F02A56B07DC8DE31DEB99F60CB3013DEAD900C74702031B5F5F9C2738BA48A8420603D46C3AE0E0C87D40B9D9D44CE0EAE81
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Cairo)]} {. LoadTimeZoneFile Africa/Cairo.}.set TZData(:Egypt) $TZData(:Africa/Cairo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):167
                                                                                                                                                                                                                                  Entropy (8bit):4.85316662399069
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV5QH+owFVAIgoq6QH7W6yMQs/h8QanQHpn:SlSWB9IZaM3ymnQeowFVAIgonQbNyM/R
                                                                                                                                                                                                                                  MD5:AA0DEB998177EB5208C4D207D46ECCE3
                                                                                                                                                                                                                                  SHA1:DD8C7CE874EE12DD77F467B74A9C8FC74C7045FF
                                                                                                                                                                                                                                  SHA-256:16A42F07DE5233599866ECC1CBB1FC4CD4483AC64E286387A0EED1AFF919717D
                                                                                                                                                                                                                                  SHA-512:D93A66A62304D1732412CAAAB2F86CE5BCD07D07C1315714D81754827D5EFD30E36D06C0DC3CF4A8C86B750D7D6A144D609D05E241FADC7FF78D3DD2044E4CBB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Dublin)]} {. LoadTimeZoneFile Europe/Dublin.}.set TZData(:Eire) $TZData(:Europe/Dublin).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):105
                                                                                                                                                                                                                                  Entropy (8bit):4.883978227144926
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDMWkXGm2OHvDd:SlSWB9X5yRQCm2OHB
                                                                                                                                                                                                                                  MD5:94CDB0947C94E40D59CB9E56DB1FA435
                                                                                                                                                                                                                                  SHA1:B73907DAC08787D3859093E8F09828229EBAA6FD
                                                                                                                                                                                                                                  SHA-256:17AF31BD69C0048A0787BA588AD8641F1DC000A8C7AEC66386B0D9F80417ABBF
                                                                                                                                                                                                                                  SHA-512:5F47A2864F9036F3FD61FC65ED4969330DD2A1AC237CB2BD8E972DDFED75120D8D377D5C84060015DCFC163D03F384DC56DC8C6F29E65528C04F1FDA8BBC688E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT) {. {-9223372036854775808 0 0 GMT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):154
                                                                                                                                                                                                                                  Entropy (8bit):4.862090278972909
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtyRDOm7/8RDMvn:SlSWB9IZaM3yF4FVAIgJtyRSw8RQvn
                                                                                                                                                                                                                                  MD5:4AC2027A430A7343B74393C7FE1D6285
                                                                                                                                                                                                                                  SHA1:C675A91954EC82EB67E1B7FA4B0C0ED11AAF83DA
                                                                                                                                                                                                                                  SHA-256:01EEF5F81290DBA38366D8BEADAD156AAC40D049DBFA5B4D0E6A6A8641D798D1
                                                                                                                                                                                                                                  SHA-512:61943A348C4D133B0730EAA264A15EF37E0BBE2F767D87574801EAAA9A457DA48D854308B6ABADA21D33F4D498EB748BCB66964EB14BB8DC1367F77A803BA520
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:Etc/GMT+0) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.936955816757987
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOvedSXGm2OH1VOY:SlSWB9X5yRSvwJm2OH1VOY
                                                                                                                                                                                                                                  MD5:B8D9D5AF8CE887722F92207393F93481
                                                                                                                                                                                                                                  SHA1:3F33F97F96AE9C30A616B8A84888B032A3E1A59A
                                                                                                                                                                                                                                  SHA-256:049ABD0DCEC9C4128FF6F5BBB1F1D64F53AB7E4A1BD07D0650B0B67D1F581C64
                                                                                                                                                                                                                                  SHA-512:7A10D28DA75FCBF5AF43FEECB91801E97CB161A6909E9463A2F1218323EE3B4ECA10E11438D20E876B6EF912E21D26264FFBD04C75D702D2386A4E959EB5FFAC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+1) {. {-9223372036854775808 -3600 0 -01}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):113
                                                                                                                                                                                                                                  Entropy (8bit):4.92045957745591
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOgFkXGm2OH1VYU8Cn:SlSWB9X5yRS0m2OH1VYQn
                                                                                                                                                                                                                                  MD5:33022DF11BC5459AA1DD968CEF24EA03
                                                                                                                                                                                                                                  SHA1:45DE6AD3B142C1768B410C047DFD45444E307AB8
                                                                                                                                                                                                                                  SHA-256:15F72B4F2C04EDDC778AAD999B5A329F55F0D10AC141862488D2DCE520541A85
                                                                                                                                                                                                                                  SHA-512:0C13040965135D199A29CFE8E1598AA8E840B141B85CCF1A45611B367AF046107FDA8478B1779E2AC665534DC4E84630267B42F902DB3A2CB78DD6D20939010E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+10) {. {-9223372036854775808 -36000 0 -10}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):113
                                                                                                                                                                                                                                  Entropy (8bit):4.959312316620187
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOeLXGm2OHaBBKn:SlSWB9X5yRShm2OHa7Kn
                                                                                                                                                                                                                                  MD5:5FC01E15A719B73A5AA5B0A6E7F16B0C
                                                                                                                                                                                                                                  SHA1:E1AAEF7C52DF944A9AEDCC74E6A07FABE09BAFCE
                                                                                                                                                                                                                                  SHA-256:69A82F9EB9E120FABFA88C846BC836B85A08FFF4B304914256E6C3A72CB371D0
                                                                                                                                                                                                                                  SHA-512:86659001C159730C012C385D505CD822F5CE6E59C0BD7899F90070372A56D348F0292F74C34A4E960E721D113DB5F65751A513D7C1A3CFBF09CBA22118323DED
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+11) {. {-9223372036854775808 -39600 0 -11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):113
                                                                                                                                                                                                                                  Entropy (8bit):4.934932781202811
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOK/kXGm2OH3FNyU7n:SlSWB9X5yRSKTm2OH3Xyan
                                                                                                                                                                                                                                  MD5:BEE0C510C41F541B4E919183459488B2
                                                                                                                                                                                                                                  SHA1:DA028394973155C52EDDDB4EB4CCACA7F3A74188
                                                                                                                                                                                                                                  SHA-256:3B3DA9CF6FEB6E90772E9EC391D857D060A2F52A34191C3A0472794FEC421F5F
                                                                                                                                                                                                                                  SHA-512:9EBE1FAD2B47DDA627F52F97094556F3A8C0D03BF2DD4C12CC8611BD2D59FE3A2C1016FFBDF0B95F2C5C56D81C8B2020EBF1D2AB4AAAFE33AB5469AFE1C596A1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+12) {. {-9223372036854775808 -43200 0 -12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.876100974396153
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOcFwFFkXGm2OHnFQVIK:SlSWB9X5yRS0wTm2OHnFQV7
                                                                                                                                                                                                                                  MD5:316ED84A4318F8641592A0959395EFA3
                                                                                                                                                                                                                                  SHA1:970C97E6F433524BE88031098DD4F5F479FB4AA6
                                                                                                                                                                                                                                  SHA-256:8323CA90E2902CAAD2EBCFFBF681FC3661424AE5B179140581AA768E36639C93
                                                                                                                                                                                                                                  SHA-512:6DD62C72E24A24F8FCD8EC085942920A04A55DD03D54C712ADA2BE0EDD6166F34A1229E045C50384808735C40CF72B98458E0329B9762B4B3E95E7ACABB0017E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+2) {. {-9223372036854775808 -7200 0 -02}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.904010922708719
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOCcXGm2OHBFVGHC:SlSWB9X5yRSCTm2OHBFAHC
                                                                                                                                                                                                                                  MD5:899F1AAB147D5A13D7E22CBE374F3F8D
                                                                                                                                                                                                                                  SHA1:C132B5E0859EB6C95C64D50408D4A310893D1E8F
                                                                                                                                                                                                                                  SHA-256:3C2EF9B7218D133E7611527CE1CD5F03FF6FED5DE245F082FF21F4571A7D9EA4
                                                                                                                                                                                                                                  SHA-512:63C8F98BAE437BB9717A3D13C70424FBB43CBA392A1750DE8EAB31C825F190C5DE1987B391591361F80CE084896B838BE78CBE56C1E1C4DC0A1A6D280742FD91
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+3) {. {-9223372036854775808 -10800 0 -03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.92751033740291
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOqLXGm2OHBvG9:SlSWB9X5yRStm2OHBO9
                                                                                                                                                                                                                                  MD5:9D050C35FCDFD703C387CF2065E6250B
                                                                                                                                                                                                                                  SHA1:EEE8A277CB49D03085A5C6FCEA94961790D23339
                                                                                                                                                                                                                                  SHA-256:B43B685B6B168FD964590BC6C4264511155DB76EBCB7A5BCB20C35C0AD9B8CC4
                                                                                                                                                                                                                                  SHA-512:D56449C34A7F63DCCE79F4A6C4731454BB909C6DA49593FFE6B59DD3DE755720931BFD245A799B7FB1397FC0AE0AF89E88AD4DAA91AB815740328B27D301DCDE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+4) {. {-9223372036854775808 -14400 0 -04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.911642645675445
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOEkXGm2OHLVvyV9C:SlSWB9X5yRSQm2OHLVKV9C
                                                                                                                                                                                                                                  MD5:81856E9473F48AB0F53B09CB6BEF61B1
                                                                                                                                                                                                                                  SHA1:52A906EE5B706091E407CA8A0D036A46727790EA
                                                                                                                                                                                                                                  SHA-256:B0224DBA144B1FE360E2922B1E558E79F6960A173045DE2A1EDACDC3F24A3E36
                                                                                                                                                                                                                                  SHA-512:7C9679A2C299741E98FF1E759313D1CDC050B73B7E4FB097FF3186B4C35271C203D54E12D758675639A3D3F3F1EB43D768834B9CE7D22376BEA71FB0ACF164A7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+5) {. {-9223372036854775808 -18000 0 -05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.930765051479699
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOAkEXGm2OHvTmUK:SlSWB9X5yRSbLm2OHvin
                                                                                                                                                                                                                                  MD5:757E578CE6FCD34966D9FF90D9F9A7BF
                                                                                                                                                                                                                                  SHA1:091E3FC890BF7A4C61CF6558F7984FD41F61803B
                                                                                                                                                                                                                                  SHA-256:28F4E6F7FDE80AE412D364D33A1714826F9F53FF980D2926D13229B691978979
                                                                                                                                                                                                                                  SHA-512:442FEBA01108124692A0F76ACA4868D5B7754C3527B9301AC0271DD5A379AF3675CE40B6C017310856D4CE700E3171B5EEA5EF89D5F8432EC3D6D27F48F2EEE8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+6) {. {-9223372036854775808 -21600 0 -06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.884164328721898
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDONedFkXGm2OHrXVYVe:SlSWB9X5yRSNwJm2OHriVe
                                                                                                                                                                                                                                  MD5:723CE2E217F73927FE030E4E004C68B5
                                                                                                                                                                                                                                  SHA1:40E46C8F3631298C3FFBF0DDC72E48E13A42A3F4
                                                                                                                                                                                                                                  SHA-256:2D2B6A351501CB1023F45CE9B16B759D8971E45C2B8E1348A6935707925F0280
                                                                                                                                                                                                                                  SHA-512:25E1C37047CD2411B6F986F30EC54B53A3D3841FD275D05732A0DF6C0718981F2343CEE77E241F347030244B22EC4A23FDEE077EB4D18BC1788F4E5AF4FDB804
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+7) {. {-9223372036854775808 -25200 0 -07}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.869188292977557
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOOFwFSXGm2OHmFvGRvn:SlSWB9X5yRSqwTm2OHaOJ
                                                                                                                                                                                                                                  MD5:A94A70486CE0942B538D855647EDFE78
                                                                                                                                                                                                                                  SHA1:1A20872C6D577DB332F0A536695CE677BC28F294
                                                                                                                                                                                                                                  SHA-256:9CF2C86CC6173F19E0DA78CCA46C302469AB5C01752DCEA6A20DC151E2D980CC
                                                                                                                                                                                                                                  SHA-512:3B6456D217A08A6DBAC0DB296384F4DED803F080FD5C0FD1527535D85397351C67B3D2BEDF8C4E2FEFD5C0B9297A8DA938CF855CDAA2BB902498B15E75A0F776
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+8) {. {-9223372036854775808 -28800 0 -08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.912907908622555
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDOwcXGm2OHNmuvn:SlSWB9X5yRSwTm2OHNmuv
                                                                                                                                                                                                                                  MD5:821C0743B99BBD9B672D1B1606B2DADD
                                                                                                                                                                                                                                  SHA1:152C09F6E8079A4036BA8316BE3E739D2ECE674B
                                                                                                                                                                                                                                  SHA-256:532D16E2CDBE8E547F54DC22B521153D2215E8B6653336A36F045E0D338B0D1B
                                                                                                                                                                                                                                  SHA-512:CCFC5BC6246B4C9EF77081E79F0A0B1DACC79449388AD08F38912E857E77E12824835C447F769A2C9C707C7E6353010A9907CDF3468A94263CF2B21FC1BF4710
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT+9) {. {-9223372036854775808 -32400 0 -09}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):154
                                                                                                                                                                                                                                  Entropy (8bit):4.849103265985896
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtyRDIyHp8RDMvn:SlSWB9IZaM3yF4FVAIgJtyRUyJ8RQvn
                                                                                                                                                                                                                                  MD5:FA608B6E2F9D0E64D2DF81B277D40E35
                                                                                                                                                                                                                                  SHA1:55A7735ACCF6A759D2069388B2943323E23EE56D
                                                                                                                                                                                                                                  SHA-256:48A929080C1E7C901246DC83A7A7F87396EAF9D982659460BF33A85B4C3FAE64
                                                                                                                                                                                                                                  SHA-512:35A8899B7084E85165886B07B6DD553745558EAF4297F702829A08BF71E5AA18790F0D02229093FA42515C97A1DDA7292F4D019DDB1251370D9896E94738D32A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:Etc/GMT-0) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):110
                                                                                                                                                                                                                                  Entropy (8bit):4.936514686189307
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDI4cXGm2OHMKUbvn:SlSWB9X5yRU4Tm2OHtUbv
                                                                                                                                                                                                                                  MD5:CCC4BDA6EDA4933FB64F329E83EB6118
                                                                                                                                                                                                                                  SHA1:7C1B47D376966451540B4D095D16973763A73A73
                                                                                                                                                                                                                                  SHA-256:A82AA68616ADEB647456EA641587D76981888B3A022C98EA11302D458295A4FA
                                                                                                                                                                                                                                  SHA-512:ACC3DF6AA6025B45F06326062B2F0803BB6FD97AAAEBB276731E5DC5C496731C0853D54B2A4476A4A2EC2DD4FFDF69D78255FC8BCAB2412CE86925A94CE0559D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-1) {. {-9223372036854775808 3600 0 +01}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.919647975606158
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDINFedFkXGm2OHMUUJv:SlSWB9X5yRUNCm2OHXQ
                                                                                                                                                                                                                                  MD5:566FBA546E6B7668830D1812659AE671
                                                                                                                                                                                                                                  SHA1:EF3AF5CE0BB944973D5B2DCC872903F0C3B7F0FF
                                                                                                                                                                                                                                  SHA-256:962E810E02BAE087AD969FEB91C07F2CBB868D09E1BA4A453EB4773F7897157A
                                                                                                                                                                                                                                  SHA-512:F42BB5ACDE563A8A875D7B3F1C10CE9A5CE7E52FA9EF2D14BDA2C45BCD5A6D9B44227D079853551BAA13EAED32F4CA3C34BAD88E616B528DEF7DFAE7F42929CB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-10) {. {-9223372036854775808 36000 0 +10}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.958847614227257
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIVEXGm2OHlVVmv:SlSWB9X5yRUVLm2OHlVAv
                                                                                                                                                                                                                                  MD5:02F46CC589D114C57B5687A703EB11C6
                                                                                                                                                                                                                                  SHA1:5199683CC7E5D18ED686B44E94FB72EA8C978A9A
                                                                                                                                                                                                                                  SHA-256:B1BEE376A0CBEA180391835DB97F8EB32873B2B58AD1AA1098E79FAC357799C5
                                                                                                                                                                                                                                  SHA-512:A0CDDCD3208D096712868FED0557CDF5FEC5E9FA5FB25864129D2A9047BCD1AFAA8270C1E41368D32DE2A7B1B66157BDCFC17F8CDF3EF6A9F0C74B42814B096F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-11) {. {-9223372036854775808 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.934250404386511
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIjWkXGm2OHwvv0UIvYv:SlSWB9X5yRUjCm2OHwvv0a
                                                                                                                                                                                                                                  MD5:F6AF5C34BDE9FFF73F8B9631C0173EE9
                                                                                                                                                                                                                                  SHA1:A717214203F4B4952AE12374AE78992084CD5A61
                                                                                                                                                                                                                                  SHA-256:622E51EE9D4601DB90818F4B8E324F790F4D2405D66B899FC018A41E00473C0F
                                                                                                                                                                                                                                  SHA-512:0B898328A19DA7FE1BD2FB161EF1511684B569E4262C8149A789855C6F86C84360BC9E6BF82BC571BD7C585A30E0658560029FCC7C3C180BC0D2EA1872860753
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-12) {. {-9223372036854775808 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.951215891260531
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIsXGm2OH1dNv74v:SlSWB9X5yRUjm2OHmv
                                                                                                                                                                                                                                  MD5:B505D6A064B6D976BD1BDE61AE937F1C
                                                                                                                                                                                                                                  SHA1:DBA0EA8DCCB50CC999397129369A340CA8A4C5B5
                                                                                                                                                                                                                                  SHA-256:EF28D4D6DAFE3AB08BE1CE9C32FAF7BF8F750332DF0D39314131F88DF463DFAC
                                                                                                                                                                                                                                  SHA-512:86A4CA670FBFFF95C9B22DA4E8957A4BE8A805457032AF47BDF08B5047881F692D665BEF8A76045EF50587149EDD52C8994A19CEE9675A3D12939D9CB9DE4649
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-13) {. {-9223372036854775808 46800 0 +13}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112
                                                                                                                                                                                                                                  Entropy (8bit):4.946259136243175
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIxmcXGm2OH0FVtQCn:SlSWB9X5yRUxmTm2OH8Jn
                                                                                                                                                                                                                                  MD5:6BD2D15FA9AAF7F44D88BED0F6C969F3
                                                                                                                                                                                                                                  SHA1:3080291F9C9C9422995583175C560338F626E4CD
                                                                                                                                                                                                                                  SHA-256:748D443DA743D385497A43198A114BD8349310494ECC85F47D39745D53F6E291
                                                                                                                                                                                                                                  SHA-512:651983293BAD1EDE1211EEAA3CAA28C73F84FFE2B8554CF198DF014BEF6B7413C4C49C3080FC73430804ECCA3D2BDB316B6B735B72E7BA3525B330E6A5352715
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-14) {. {-9223372036854775808 50400 0 +14}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):110
                                                                                                                                                                                                                                  Entropy (8bit):4.8751066179878215
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDInHkXGm2OH/VXCYvn:SlSWB9X5yRUnLm2OH/VSC
                                                                                                                                                                                                                                  MD5:DAE7D42076F09E2E2A51A58CC253837D
                                                                                                                                                                                                                                  SHA1:44C587A71AE31A7424E0F2B005D11F9E0B463E80
                                                                                                                                                                                                                                  SHA-256:9D0D3FAD960E9EBF599218213F3AE8A22766B6CB15C8CDBC7ABD8A3FFD75C29A
                                                                                                                                                                                                                                  SHA-512:CEE724EEC6EC86FB417CD4D06B3FC17A404953CCE8740A03B024C05C0436340D9B056F3F1B2706284F57CC49FA229EE311D088AFE3D65F0BF946B0A18282ED46
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-2) {. {-9223372036854775808 7200 0 +02}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.903159871492102
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIYdSXGm2OHkNsWYAvn:SlSWB9X5yRUGJm2OHkKWYAv
                                                                                                                                                                                                                                  MD5:3CABCADD8398567F6489C263BF55CA89
                                                                                                                                                                                                                                  SHA1:0981F225619E92D4B76ECB2C6D186156E46DA63D
                                                                                                                                                                                                                                  SHA-256:74EEBD9C48312D68DC5E54B843FACF3DB869E214D37214F1096AF1D6ECF6D9AF
                                                                                                                                                                                                                                  SHA-512:1FF86CFDAA407D7EFD0B0DBC32FC8ED03DAADF6D0D83463B4C6DA97B4B8D77FC381C4C140168AA06FA9A5444DDADBB39DBD8F22E4570EE86F2F7608AAFB0C7FC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-3) {. {-9223372036854775808 10800 0 +03}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.92687099262498
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIbSXGm2OHkVsRYvC:SlSWB9X5yRUtm2OHkSQC
                                                                                                                                                                                                                                  MD5:C157F79ADE92A69E46472EA921E1370F
                                                                                                                                                                                                                                  SHA1:4B9E5AFA769D5BDF3FDF05BC24A6A632C6D86ECB
                                                                                                                                                                                                                                  SHA-256:0606FBAB9374A74D4B2ED17DD04D9DCED7131768CCF673C5C3B739727743383F
                                                                                                                                                                                                                                  SHA-512:B6814282465ABF4DF31341306050F11ECAAFC5915C420A8E7F8D787E66308C58FF7C348D6CBDB4064C346800564000C7C763BDD01CB8CE3A8A81550F65C9A74C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-4) {. {-9223372036854775808 14400 0 +04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.91086034871979
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDI7wkXGm2OHM0VQL:SlSWB9X5yRU7Em2OHnVQL
                                                                                                                                                                                                                                  MD5:AF742680C5A3BA5981DD7F0646EF6CCA
                                                                                                                                                                                                                                  SHA1:0753749D4636D561A8942BB1641BDBCC42349A9B
                                                                                                                                                                                                                                  SHA-256:5E2D90AF8A161D47F30E1C4A0F5E1CAB5E9F24201557864A02D3009B1ECFEDE0
                                                                                                                                                                                                                                  SHA-512:9B738675FC02613929BF90A7C78DD632AB782D20B5E660578AB590858D22BCD79E5AFB191D41E9DF94E2E586B5D2A163AB7D8364A02A5DE60E5B838F8B85D2FD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-5) {. {-9223372036854775808 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.930155028450208
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIgwcXGm2OHETNSTL:SlSWB9X5yRUgwTm2OHETMn
                                                                                                                                                                                                                                  MD5:298F4671F470C4628B3174D5D1D0608D
                                                                                                                                                                                                                                  SHA1:5626202FB7186B4555C03F94CEE38AD0FAB81F40
                                                                                                                                                                                                                                  SHA-256:19760989015244E4F39AC12C07E6665038AE08282DAF8D6DB0BB5E2F642C922D
                                                                                                                                                                                                                                  SHA-512:F81B901249D3FAED3805471F256F55463A7A2FC8CB612FF95E698D63F9609D5D1B3B57DD87021C5DD809D971709EC3831351D54E971E25643B67161E9EAD5E25
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-6) {. {-9223372036854775808 21600 0 +06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.883134479361256
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIu/kXGm2OHAXUVSYvC:SlSWB9X5yRUuTm2OHAXUVSYvC
                                                                                                                                                                                                                                  MD5:2317D02708980D7F17B1A4BDE971D15F
                                                                                                                                                                                                                                  SHA1:2E78CDE3608F6B03DEB534D14D069D3D89DE85EF
                                                                                                                                                                                                                                  SHA-256:0BF01EEEBAA49CE9859C2A5835C6A826B158A7BC3B14C473FBB0167ABA9EA4B9
                                                                                                                                                                                                                                  SHA-512:21083EAEACD689FD07D458DB82BC2559445A1C558EB8BAF098B71CFD3A599BB756336F847CBE536648AF473E22E0000B2A8C44A45D0866994F03A78D4E841FC5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-7) {. {-9223372036854775808 25200 0 +07}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.8680235243759755
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIlEXGm2OHN/VsdYK:SlSWB9X5yRUlLm2OHUJ
                                                                                                                                                                                                                                  MD5:B940D187558341DBF4D619248C13C7CA
                                                                                                                                                                                                                                  SHA1:0C6B11AA9DBC0A395345F79B4B7325FBE870A414
                                                                                                                                                                                                                                  SHA-256:DAB4C0E14D2850BF917C5891E864834CA4BFD38D5470F119F529582976551862
                                                                                                                                                                                                                                  SHA-512:042176822D8BFD72FFC0727176596430B656E4986636E9869F883B7078389F936EFA8CCFA9BA7ED0963899BD7D134DB9CD25F24C42040781CC37F2701D0CA28A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-8) {. {-9223372036854775808 28800 0 +08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):111
                                                                                                                                                                                                                                  Entropy (8bit):4.91213701043219
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRDIedSXGm2OHENScCC:SlSWB9X5yRUwJm2OHsScCC
                                                                                                                                                                                                                                  MD5:DD58339761ECF5503A48267CFD8E3837
                                                                                                                                                                                                                                  SHA1:B58511A80448D74B38365EA537BBE0D21956F0E2
                                                                                                                                                                                                                                  SHA-256:383EFE43E20963058BFCD852813BDA3FCCC0B4A7AC26317E621589B4C97C1B90
                                                                                                                                                                                                                                  SHA-512:C865244051882FD141D369435CFEED0A1E1D254C0313C1EFE55F5AF72412BE11F2B76484170B94BC4E9FCC0D2EEC373D523732FF7945999717D5827FCE68F54F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/GMT-9) {. {-9223372036854775808 32400 0 +09}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):153
                                                                                                                                                                                                                                  Entropy (8bit):4.836974611939794
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtyRDVMFHp8RDMvn:SlSWB9IZaM3yF4FVAIgJtyRC1p8RQvn
                                                                                                                                                                                                                                  MD5:BE8C5C3B3DACB97FADEB5444976AF56A
                                                                                                                                                                                                                                  SHA1:A0464B66E70A1AF7963D2BE7BC1D88E5842EC99A
                                                                                                                                                                                                                                  SHA-256:89F4624DC69DE64B7AF9339FE17136A88A0C28F5F300575540F8953B4A621451
                                                                                                                                                                                                                                  SHA-512:A0E11D9DF5AD2C14A012E82F24298921780E091EEDD680535658F9CD1337A4103BA0676DF9B58865DD7D2CFA96AEED7BF786B88786FAF31B06713D61B4C0308A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:Etc/GMT0) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):158
                                                                                                                                                                                                                                  Entropy (8bit):4.862741414606617
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtyRp+FB5yRDMvn:SlSWB9IZaM3yF4FVAIgJtyRp6BURQvn
                                                                                                                                                                                                                                  MD5:2DADDAD47A64889162132E8DA0FFF54F
                                                                                                                                                                                                                                  SHA1:EC213743939D699A4EE4846E582B236F8C18CB29
                                                                                                                                                                                                                                  SHA-256:937970A93C2EB2D73684B644E671ACA5698BCB228810CC9CF15058D555347F43
                                                                                                                                                                                                                                  SHA-512:CA8C45BA5C1AF2F9C33D6E35913CED14B43A7AA37300928F14DEF8CB5E7D56B58968B9EE219A0ACCB4C17C52F0FBD80BD1018EF5426C137628429C7DAA41ACA2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:Etc/Greenwich) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):105
                                                                                                                                                                                                                                  Entropy (8bit):4.857741203314798
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yR5FkXGm2OHv1CCn:SlSWB9X5yRHm2OHNLn
                                                                                                                                                                                                                                  MD5:415F102602AFB6F9E9F2B58849A32CC9
                                                                                                                                                                                                                                  SHA1:002C7D99EBAA57E8599090CFBF39B8BEAABE4635
                                                                                                                                                                                                                                  SHA-256:549D4CC4336D35143A55A09C96FB9A36227F812CA070B2468BD3BB6BB4F1E58F
                                                                                                                                                                                                                                  SHA-512:6CA28E71F941D714F3AACA619D0F4FEEF5C35514E05953807C225DF976648F257D835B59A03991D009F738C6FD94EB50B4ECA45A011E63AFDCA537FBAC2B6D1B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/UCT) {. {-9223372036854775808 0 0 UCT}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):105
                                                                                                                                                                                                                                  Entropy (8bit):4.857741203314798
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5yRF3dFkXGm2OHvr:SlSWB9X5yR9dJm2OHj
                                                                                                                                                                                                                                  MD5:6343442DDDC19AF39CADD82AC1DDA9BD
                                                                                                                                                                                                                                  SHA1:9D20B726C012F14D99E701A69C60F81CB33E9DA6
                                                                                                                                                                                                                                  SHA-256:48B88EED5EF95011F41F5CA7DF48B6C71BED711B079E1132B2C1CD538947EF64
                                                                                                                                                                                                                                  SHA-512:4CFED8C80D9BC2A75D4659A14F22A507CF55D3DCC88318025BCB8C99AE7909CAF1F11B1ADC363EF007520BF09473CB68357644E41A9BBDAF9DB0B0A44ECC4FBF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Etc/UTC) {. {-9223372036854775808 0 0 UTC}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):158
                                                                                                                                                                                                                                  Entropy (8bit):4.825049978035721
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqAxmSwFVAIgESRLyRYzXDJMFfh8RFu:SlSWB9IZaM3yzUFVAIgBLyRY7VMr8RI
                                                                                                                                                                                                                                  MD5:7BE0766999E671DDD5033A61A8D84683
                                                                                                                                                                                                                                  SHA1:D2D3101E78919EB5FE324FFC85503A25CFD725E0
                                                                                                                                                                                                                                  SHA-256:90B776CF712B8FE4EEC587410C69A0EC27417E79006132A20288A9E3AC5BE896
                                                                                                                                                                                                                                  SHA-512:A4CA58CD4DC09393BBE3C43D0B5E851DEBEEDC0C5CEC7DCED4D24C14796FD336D5607B33296985BD14E7660DCE5C85C0FB625B2F1AD9AC10F1631A76ECEB04B8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/UTC)]} {. LoadTimeZoneFile Etc/UTC.}.set TZData(:Etc/Universal) $TZData(:Etc/UTC).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):153
                                                                                                                                                                                                                                  Entropy (8bit):4.824450775594084
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqAxmSwFVAIgESRLyRaQEBURFu:SlSWB9IZaM3yzUFVAIgBLyRYaRI
                                                                                                                                                                                                                                  MD5:64ED445C4272D11C85BD2CFC695F180F
                                                                                                                                                                                                                                  SHA1:EDE76B52D3EEBCC75C50E17C053009A453D60D42
                                                                                                                                                                                                                                  SHA-256:A68D32DA2214B81D1C0C318A5C77975DE7C4E184CB4D60F07858920B11D065FE
                                                                                                                                                                                                                                  SHA-512:4CE8FC2B7C389BD2058CE77CD7234D4EA3F81F40204C9190BF0FB6AA693FB40D0638BFB0EB0D9FA20CB88804B73F6EE8202439C1F553B1293C6D2E5964216A1D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/UTC)]} {. LoadTimeZoneFile Etc/UTC.}.set TZData(:Etc/Zulu) $TZData(:Etc/UTC).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8792
                                                                                                                                                                                                                                  Entropy (8bit):3.8152682180965747
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:nK5UUH6mek6EvDGwdSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVab:K5VfSTRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:C107BB0AC411789418982B201FF1F857
                                                                                                                                                                                                                                  SHA1:71691B3E9FCC3503943BAFD872A881C1F1EE8451
                                                                                                                                                                                                                                  SHA-256:2794B605AE149FFB58D88508A663BB54034FD542BF14B56DAE62801971612F5B
                                                                                                                                                                                                                                  SHA-512:BFC79B3245526ED54615F613D3158DC4CF44DAF3DB758DBA65977EC91263CEFFA628D36E7CA536E140AF727EC321D9047C36D56303718D1EC5B49F5A8BCAE2E9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Amsterdam) {. {-9223372036854775808 1172 0 LMT}. {-4260212372 1172 0 AMT}. {-1693700372 4772 1 NST}. {-1680484772 1172 0 AMT}. {-1663453172 4772 1 NST}. {-1650147572 1172 0 AMT}. {-1633213172 4772 1 NST}. {-1617488372 1172 0 AMT}. {-1601158772 4772 1 NST}. {-1586038772 1172 0 AMT}. {-1569709172 4772 1 NST}. {-1554589172 1172 0 AMT}. {-1538259572 4772 1 NST}. {-1523139572 1172 0 AMT}. {-1507501172 4772 1 NST}. {-1490566772 1172 0 AMT}. {-1470176372 4772 1 NST}. {-1459117172 1172 0 AMT}. {-1443997172 4772 1 NST}. {-1427667572 1172 0 AMT}. {-1406672372 4772 1 NST}. {-1396217972 1172 0 AMT}. {-1376950772 4772 1 NST}. {-1364768372 1172 0 AMT}. {-1345414772 4772 1 NST}. {-1333318772 1172 0 AMT}. {-1313792372 4772 1 NST}. {-1301264372 1172 0 AMT}. {-1282256372 4772 1 NST}. {-1269814772 1172 0 AMT}. {-1250720372 4772 1 NST}. {-123836517
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6690
                                                                                                                                                                                                                                  Entropy (8bit):3.730744509734253
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:u7rRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUbAyzF76:uXRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:13F10BC59FB9DBA47750CA0B3BFA25E9
                                                                                                                                                                                                                                  SHA1:992E50F4111D55FEBE3CF8600F0B714E22DD2B16
                                                                                                                                                                                                                                  SHA-256:E4F684F28AD24B60E21707820C40A99E83431A312D26E6093A198CB344C249DC
                                                                                                                                                                                                                                  SHA-512:DA5255BDE684BE2C306C6782A61DE38BFCF9CFF5FD117EBDE5EF364A5ED76B5AB88E6F7E08337EEB2CEC9CB03238D9592941BDAA01DFB061F21085D386451AFA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Andorra) {. {-9223372036854775808 364 0 LMT}. {-2177453164 0 0 WET}. {-733881600 3600 0 CET}. {481078800 7200 0 CEST}. {496803600 3600 0 CET}. {512528400 7200 1 CEST}. {528253200 3600 0 CET}. {543978000 7200 1 CEST}. {559702800 3600 0 CET}. {575427600 7200 1 CEST}. {591152400 3600 0 CET}. {606877200 7200 1 CEST}. {622602000 3600 0 CET}. {638326800 7200 1 CEST}. {654656400 3600 0 CET}. {670381200 7200 1 CEST}. {686106000 3600 0 CET}. {701830800 7200 1 CEST}. {717555600 3600 0 CET}. {733280400 7200 1 CEST}. {749005200 3600 0 CET}. {764730000 7200 1 CEST}. {780454800 3600 0 CET}. {796179600 7200 1 CEST}. {811904400 3600 0 CET}. {828234000 7200 1 CEST}. {846378000 3600 0 CET}. {859683600 7200 1 CEST}. {877827600 3600 0 CET}. {891133200 7200 1 CEST}. {909277200 3600 0 CET}. {922582800 7200 1 CEST}. {941331600 3600 0 CET}. {9540
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1992
                                                                                                                                                                                                                                  Entropy (8bit):3.5867428099003957
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:ce0exLWtjS+OVkb/cXODnOwUDOS5u8OimFeb/ROHc9qOYNkw/O2blbEUhtCUH9mt:iDTZVemFLN7NBx333+ix6b0JiGef
                                                                                                                                                                                                                                  MD5:103F48F9DDAC5D94F2BECDA949DE5E50
                                                                                                                                                                                                                                  SHA1:0582454439DD4E8D69E7E8EE9B8A3F041F062E89
                                                                                                                                                                                                                                  SHA-256:823A0A0DBA01D9B34794EB276F9ABB9D2EC1E60660B20EAA2BA097884E3934F2
                                                                                                                                                                                                                                  SHA-512:7419A8F5CF49BE76D7CD7D070FF4467CED851EC76E38A07BD590ED64B96DA446968195096DE2F8298C448778E0A40CAE717C8F234CCDBDF5C3C21B7D056EA4C1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Astrakhan) {. {-9223372036854775808 11532 0 LMT}. {-1441249932 10800 0 +03}. {-1247540400 14400 0 +05}. {354916800 18000 1 +05}. {370724400 14400 0 +04}. {386452800 18000 1 +05}. {402260400 14400 0 +04}. {417988800 18000 1 +05}. {433796400 14400 0 +04}. {449611200 18000 1 +05}. {465343200 14400 0 +04}. {481068000 18000 1 +05}. {496792800 14400 0 +04}. {512517600 18000 1 +05}. {528242400 14400 0 +04}. {543967200 18000 1 +05}. {559692000 14400 0 +04}. {575416800 18000 1 +05}. {591141600 14400 0 +04}. {606866400 10800 0 +04}. {606870000 14400 1 +04}. {622594800 10800 0 +03}. {638319600 14400 1 +04}. {654649200 10800 0 +03}. {670374000 14400 0 +04}. {701820000 10800 0 +04}. {701823600 14400 1 +04}. {717548400 10800 0 +03}. {733273200 14400 1 +04}. {748998000 10800 0 +03}. {764722800 14400 1 +04}. {780447600 10800 0 +03}. {7961724
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7686
                                                                                                                                                                                                                                  Entropy (8bit):3.635151038354021
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:JAK3+9wAuy+Hk+PVqVaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2l:JAKOK1XPzh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:D64695F05822EF0DF9E3762A1BC440A0
                                                                                                                                                                                                                                  SHA1:F17F03CFD908753E28F2C67D2C8649B8E24C35F7
                                                                                                                                                                                                                                  SHA-256:118289C1754C06024B36AE81FEE96603D182CB3B8D0FE0A7FD16AD34DB81374D
                                                                                                                                                                                                                                  SHA-512:3C5BDE2004D6499B46D9BAB8DBFDCC1FC2A729EEA4635D8C6CB4279AEE9B5655CE93D2E3F09B3E7295468007FFB5BE6FEC5429501E8FB4D3C2BCC05177C2158A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Athens) {. {-9223372036854775808 5692 0 LMT}. {-2344642492 5692 0 AMT}. {-1686101632 7200 0 EET}. {-1182996000 10800 1 EEST}. {-1178161200 7200 0 EET}. {-906861600 10800 1 EEST}. {-904878000 7200 0 CEST}. {-857257200 3600 0 CET}. {-844477200 7200 1 CEST}. {-828237600 3600 0 CET}. {-812422800 7200 0 EET}. {-552362400 10800 1 EEST}. {-541652400 7200 0 EET}. {166485600 10800 1 EEST}. {186184800 7200 0 EET}. {198028800 10800 1 EEST}. {213753600 7200 0 EET}. {228873600 10800 1 EEST}. {244080000 7200 0 EET}. {260323200 10800 1 EEST}. {275446800 7200 0 EET}. {291798000 10800 1 EEST}. {307407600 7200 0 EET}. {323388000 10800 1 EEST}. {338936400 7200 0 EET}. {347148000 7200 0 EET}. {354675600 10800 1 EEST}. {370400400 7200 0 EET}. {386125200 10800 1 EEST}. {401850000 7200 0 EET}. {417574800 10800 1 EEST}. {433299600 7200 0 EET}. {4490
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.827362756219521
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVxKL82wFVAIgoqyKL8p6yQahs3QavKL8i:SlSWB9IZaM3ymvKA2wFVAIgovKAUy70U
                                                                                                                                                                                                                                  MD5:19134F27463DEDF7E25BC72E031B856F
                                                                                                                                                                                                                                  SHA1:40D9E60D26C592ED79747D1253A9094FCDE5FD33
                                                                                                                                                                                                                                  SHA-256:5D31D69F259B5B2DFE016EB1B2B811BD51A1ED93011CBB34D2CF65E4806EB819
                                                                                                                                                                                                                                  SHA-512:B80202194A9D547AEC3B845D267736D831FB7E720E171265AC3F0074C8B511518952BF686A235E6DDEFC11752C3BD8A48A184930879B68980AC60E9FAECBFB44
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/London)]} {. LoadTimeZoneFile Europe/London.}.set TZData(:Europe/Belfast) $TZData(:Europe/London).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7059
                                                                                                                                                                                                                                  Entropy (8bit):3.733102701717456
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:TX6TRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUbAyzF76:TWRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:841E21EED6229503BF41A858601453B0
                                                                                                                                                                                                                                  SHA1:6F5632B23F2C710106211FBCD2C17DC40B026BFB
                                                                                                                                                                                                                                  SHA-256:813B4B4F13401D4F92B0F08FC1540936CCFF91EFD8B8D1A2C5429B23715C2748
                                                                                                                                                                                                                                  SHA-512:85863B12F17A4F7FAC14DF4D3AB50CE33C7232A519F7F10CC521AC0F695CD645857BD0807F0A9B45C169DD7C1240E026C567B35D1D157EE3DB3C80A57063E8FE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Belgrade) {. {-9223372036854775808 4920 0 LMT}. {-2713915320 3600 0 CET}. {-905824800 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-788922000 3600 0 CET}. {-777942000 7200 1 CEST}. {-766623600 3600 0 CET}. {407199600 3600 0 CET}. {417574800 7200 1 CEST}. {433299600 3600 0 CET}. {449024400 7200 1 CEST}. {465354000 3600 0 CET}. {481078800 7200 1 CEST}. {496803600 3600 0 CET}. {512528400 7200 1 CEST}. {528253200 3600 0 CET}. {543978000 7200 1 CEST}. {559702800 3600 0 CET}. {575427600 7200 1 CEST}. {591152400 3600 0 CET}. {606877200 7200 1 CEST}. {622602000 3600 0 CET}. {638326800 7200 1 CEST}. {654656400 3600 0 CET}. {670381200 7200 1 CEST}. {686106000 3600 0 CET}. {701830800 7200 1 CEST}. {717555600 3600 0 CET}. {733280400 7200 1 CES
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7746
                                                                                                                                                                                                                                  Entropy (8bit):3.733442486698092
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:hgt67dAtcRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUbAT:hiGRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:D1E45A4660E00A361729FCD7413361C1
                                                                                                                                                                                                                                  SHA1:BCC709103D07748E909DD999A954DFF7034F065F
                                                                                                                                                                                                                                  SHA-256:EAD23E3F58706F79584C1F3F9944A48670F428CACBE9A344A52E19B541AB4F66
                                                                                                                                                                                                                                  SHA-512:E3A0E6B4FC80A8D0215C81E95F9D3F71C0D9371EE0F6B2B7E966744C42FC64055370D322918EEA2917BFBA07030629C4493ADA257F9BD9C9BF6AD3C4A7FB1E70
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Berlin) {. {-9223372036854775808 3208 0 LMT}. {-2422054408 3600 0 CET}. {-1693706400 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-938905200 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-781052400 7200 1 CEST}. {-776559600 10800 0 CEMT}. {-765936000 7200 1 CEST}. {-761180400 3600 0 CET}. {-757386000 3600 0 CET}. {-748479600 7200 1 CEST}. {-733273200 3600 0 CET}. {-717631200 7200 1 CEST}. {-714610800 10800 1 CEMT}. {-710380800 7200 1 CEST}. {-701910000 3600 0 CET}. {-684975600 7200 1 CEST}. {-670460400 3600 0 CET}. {-654130800 7200 1 CEST}. {-639010800 3600 0 CET}. {315529200 3600 0 CET}. {323830800 7200 1 CEST}. {338950800 3600 0 CET
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):180
                                                                                                                                                                                                                                  Entropy (8bit):4.89628096026481
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVtXrAevFVAIgoquXrELyQahcvEB5yQazXrY:SlSWB9IZaM3ymzbAevFVAIgozbELy7cY
                                                                                                                                                                                                                                  MD5:7C0606BC846344D78A85B4C14CE85B95
                                                                                                                                                                                                                                  SHA1:CEDFDC3C81E519413DDD634477533C89E8AF2E35
                                                                                                                                                                                                                                  SHA-256:D7DF89C23D2803683FE3DB57BF326846C9B50E8685CCCF4230F24A5F4DC8E44E
                                                                                                                                                                                                                                  SHA-512:8F07791DE5796B418FFD8945AE13BAB1C9842B8DDC073ED64E12EA8985619B93472C39DD44DA8FAEF5614F4E6B4A9D96E0F52B4ECA11B2CCA9806D2F8DDF2778
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Prague)]} {. LoadTimeZoneFile Europe/Prague.}.set TZData(:Europe/Bratislava) $TZData(:Europe/Prague).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8907
                                                                                                                                                                                                                                  Entropy (8bit):3.75854119398076
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:BMlf+jdXtSYv9HMn2vDGwdSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHL:BMQSY1RSTRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:FA802B103E8829C07AE7E05DE7F3CD1F
                                                                                                                                                                                                                                  SHA1:46AFB26E3E9102F0544C5294DA67DC41E8B2E8FC
                                                                                                                                                                                                                                  SHA-256:AEB5860C2F041842229353E3F83CC2FEBC9518B115F869128E94A1605FB4A759
                                                                                                                                                                                                                                  SHA-512:488CE6B524071D2B72F8AD73C2DC00F5F4C1C3C93F91165BDA0BCCB2B2C644B792C4220B785E84835ABE81584FDC87A1DCDA7679A69318052C3854167CB43C61
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Brussels) {. {-9223372036854775808 1050 0 LMT}. {-2840141850 1050 0 BMT}. {-2450953050 0 0 WET}. {-1740355200 3600 0 CET}. {-1693702800 7200 0 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-1613826000 0 0 WET}. {-1604278800 3600 1 WEST}. {-1585530000 0 0 WET}. {-1574038800 3600 1 WEST}. {-1552266000 0 0 WET}. {-1539997200 3600 1 WEST}. {-1520557200 0 0 WET}. {-1507510800 3600 1 WEST}. {-1490576400 0 0 WET}. {-1473642000 3600 1 WEST}. {-1459126800 0 0 WET}. {-1444006800 3600 1 WEST}. {-1427677200 0 0 WET}. {-1411952400 3600 1 WEST}. {-1396227600 0 0 WET}. {-1379293200 3600 1 WEST}. {-1364778000 0 0 WET}. {-1348448400 3600 1 WEST}. {-1333328400 0 0 WET}. {-1316394000 3600 1 WEST}. {-1301263200 0 0 WET}. {-1284328800 3600 1 WEST}. {-126
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7706
                                                                                                                                                                                                                                  Entropy (8bit):3.6365022673390808
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:nQrdI+sYixX215VaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtk:nQrbEm1Oh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:79AAB44507DD6D06FA673CA20D4CF223
                                                                                                                                                                                                                                  SHA1:A2F1AA0E3F38EF24CD953C6B5E1EC29EA3EDB8C0
                                                                                                                                                                                                                                  SHA-256:C40DC0C9EE5FFF9F329823325A71F3F38BE940F159E64E0B0CED27B280C1F318
                                                                                                                                                                                                                                  SHA-512:BBEBB29FFD35A1F8B9D906795032976B3F69A0097ED7D764E3EB45574E66641C35F9006B3295FB090472FF5C09FC4D88D9249E924011A178EFB68D050AA6F871
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Bucharest) {. {-9223372036854775808 6264 0 LMT}. {-2469404664 6264 0 BMT}. {-1213148664 7200 0 EET}. {-1187056800 10800 1 EEST}. {-1175479200 7200 0 EET}. {-1159754400 10800 1 EEST}. {-1144029600 7200 0 EET}. {-1127700000 10800 1 EEST}. {-1111975200 7200 0 EET}. {-1096250400 10800 1 EEST}. {-1080525600 7200 0 EET}. {-1064800800 10800 1 EEST}. {-1049076000 7200 0 EET}. {-1033351200 10800 1 EEST}. {-1017626400 7200 0 EET}. {-1001901600 10800 1 EEST}. {-986176800 7200 0 EET}. {-970452000 10800 1 EEST}. {-954727200 7200 0 EET}. {296604000 10800 1 EEST}. {307486800 7200 0 EET}. {323816400 10800 1 EEST}. {338940000 7200 0 EET}. {354672000 10800 0 EEST}. {370396800 7200 0 EET}. {386121600 10800 1 EEST}. {401846400 7200 0 EET}. {417571200 10800 1 EEST}. {433296000 7200 0 EET}. {449020800 10800 1 EEST}. {465350400 7200 0 EET}. {481075200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7975
                                                                                                                                                                                                                                  Entropy (8bit):3.7352769955376464
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:ZpduGm56n0PcRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQlth:ZpMypRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:25864F8E5372B8E45B71D08667ED093C
                                                                                                                                                                                                                                  SHA1:83463D25C839782E2619CD5BE613DA1BD08ACBB5
                                                                                                                                                                                                                                  SHA-256:EF5CF8C9B3CA3F772A9C757A2CC1D561E00CB277A58E43ED583A450BBA654BF1
                                                                                                                                                                                                                                  SHA-512:0DAB3CA0C82AA80A4F9CC04C191BE180EB41CCF87ADB31F26068D1E6A3A2F121678252E36E387B589552E6F7BA965F7E3F4633F1FD066FC7849B1FD554F39EC7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Budapest) {. {-9223372036854775808 4580 0 LMT}. {-2500938980 3600 0 CET}. {-1693706400 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1640998800 3600 0 CET}. {-1633212000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-1600466400 7200 1 CEST}. {-1581202800 3600 0 CET}. {-906771600 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-788922000 3600 0 CET}. {-778471200 7200 1 CEST}. {-762660000 3600 0 CET}. {-749689200 7200 1 CEST}. {-733359600 3600 0 CET}. {-717634800 7200 1 CEST}. {-701910000 3600 0 CET}. {-686185200 7200 1 CEST}. {-670460400 3600 0 CET}. {-654130800 7200 1 CEST}. {-639010800 3600 0 CET}. {-621990000 7200 1 CEST}. {-605660400 3600 0 CET}. {-492656400 7200 1 CEST}. {-481168800 3600 0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.905738881351689
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVnCMPwVAIgoqkCMJW6yQahDZALMFB5h8Qa5CMP:SlSWB9IZaM3ym5XwVAIgo5Py7D17/8jH
                                                                                                                                                                                                                                  MD5:811B7E0B0EDD151E52DF369B9017E7C0
                                                                                                                                                                                                                                  SHA1:3C17D157A626F3AD7859BC0F667E0AB60E821D05
                                                                                                                                                                                                                                  SHA-256:221C8BA73684ED7D8CD92978ED0A53A930500A2727621CE1ED96333787174E82
                                                                                                                                                                                                                                  SHA-512:7F980E34BBCBC65BBF04526BF68684B3CE780611090392560569B414978709019D55F69368E98ADADC2C47116818A437D5C83F4E6CD40F4A1674D1CF90307CB5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Zurich)]} {. LoadTimeZoneFile Europe/Zurich.}.set TZData(:Europe/Busingen) $TZData(:Europe/Zurich).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7824
                                                                                                                                                                                                                                  Entropy (8bit):3.674889638637008
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:J2rdkayurpKXlGYtXfVA6bN3E48WLCtSYxUFtj2DVXvR2YuXOZp+eiXGEsTVVHU:J2r6G81T9bN3E48GCujWYqK
                                                                                                                                                                                                                                  MD5:92966EE642028D4C44C90F86CA1440AA
                                                                                                                                                                                                                                  SHA1:95F286585FF3A880F2F909E82F4C22C8F1D12BE3
                                                                                                                                                                                                                                  SHA-256:E92FFABF4705F93C2A4AD675555AEBC3C9418AC71EEB487AF0F7CD4EAB0431CE
                                                                                                                                                                                                                                  SHA-512:1D6018C83CA5998C590448FE98C59F3FCD0D5D7688B679B7F3C82B6F3209F25323BB302BF847FCCBD950F08A79AF36CA83DBDD4DB8A3557A682152A6B731B663
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Chisinau) {. {-9223372036854775808 6920 0 LMT}. {-2840147720 6900 0 CMT}. {-1637114100 6264 0 BMT}. {-1213148664 7200 0 EET}. {-1187056800 10800 1 EEST}. {-1175479200 7200 0 EET}. {-1159754400 10800 1 EEST}. {-1144029600 7200 0 EET}. {-1127700000 10800 1 EEST}. {-1111975200 7200 0 EET}. {-1096250400 10800 1 EEST}. {-1080525600 7200 0 EET}. {-1064800800 10800 1 EEST}. {-1049076000 7200 0 EET}. {-1033351200 10800 1 EEST}. {-1017626400 7200 0 EET}. {-1001901600 10800 1 EEST}. {-986176800 7200 0 EET}. {-970452000 10800 1 EEST}. {-954727200 7200 0 EET}. {-927165600 10800 1 EEST}. {-898138800 7200 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-800154000 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {4179
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7458
                                                                                                                                                                                                                                  Entropy (8bit):3.736544358182077
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:1Fpd6z8cRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUbAyo:1FpoRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:8FBF425E5833012C0A6276222721A106
                                                                                                                                                                                                                                  SHA1:78C5788ED4184A62E0E2986CC0F39EED3801AD76
                                                                                                                                                                                                                                  SHA-256:D2D091740C425C72C46ADDC23799FC431B699B80D244E4BCD7F42E31C1238EEB
                                                                                                                                                                                                                                  SHA-512:6DF08142EEBC7AF8A575DD7510B83DBD0E15DDA13801777684355937338CDA3D09E37527912F4EBBCC1B8758E3D65185E6006EB5C1349D1DC3AE7B6131105691
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Copenhagen) {. {-9223372036854775808 3020 0 LMT}. {-2524524620 3020 0 CMT}. {-2398294220 3600 0 CET}. {-1692496800 7200 1 CEST}. {-1680490800 3600 0 CET}. {-935110800 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-781052400 7200 0 CEST}. {-769388400 3600 0 CET}. {-747010800 7200 1 CEST}. {-736383600 3600 0 CET}. {-715215600 7200 1 CEST}. {-706748400 3600 0 CET}. {-683161200 7200 1 CEST}. {-675298800 3600 0 CET}. {315529200 3600 0 CET}. {323830800 7200 1 CEST}. {338950800 3600 0 CET}. {354675600 7200 1 CEST}. {370400400 3600 0 CET}. {386125200 7200 1 CEST}. {401850000 3600 0 CET}. {417574800 7200 1 CEST}. {433299600 3600 0 CET}. {449024400 7200 1 CEST}. {465354000 3600 0 CET}. {481078800 7200 1 CEST}. {496803600 3600 0 CET}. {512528
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9452
                                                                                                                                                                                                                                  Entropy (8bit):3.675115548319436
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:fIfr7ZO/H8XKKRg3psTZ+wfAIt3/LIjzI9jJeK:fIHZO/Hk5RmpsT7/sjzI9jJeK
                                                                                                                                                                                                                                  MD5:D9787AD03D1A020F01FFF1F9AB346C09
                                                                                                                                                                                                                                  SHA1:C194A0A7F218ABBEB7DB53E3B2062DC349A8C739
                                                                                                                                                                                                                                  SHA-256:E1DCBC878C8937FBE378033AEE6B0D8C72827BE3D9C094815BFA47AF92130792
                                                                                                                                                                                                                                  SHA-512:4C596C9BDE55605381C9B6F90837BA8C9EA2992EBC7F3ACDC207CFAE7612E8B13415FD4962DC8D3FD2A75D98025D0E052B8B8486F6C31742D791C6A2C1D1827F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Dublin) {. {-9223372036854775808 -1500 0 LMT}. {-2821649700 -1521 0 DMT}. {-1691962479 2079 1 IST}. {-1680471279 0 0 GMT}. {-1664143200 3600 1 BST}. {-1650146400 0 0 GMT}. {-1633903200 3600 1 BST}. {-1617487200 0 0 GMT}. {-1601848800 3600 1 BST}. {-1586037600 0 0 GMT}. {-1570399200 3600 1 BST}. {-1552168800 0 0 GMT}. {-1538344800 3600 1 BST}. {-1522533600 0 0 GMT}. {-1517011200 0 0 IST}. {-1507500000 3600 1 IST}. {-1490565600 0 0 IST}. {-1473631200 3600 1 IST}. {-1460930400 0 0 IST}. {-1442786400 3600 1 IST}. {-1428876000 0 0 IST}. {-1410732000 3600 1 IST}. {-1396216800 0 0 IST}. {-1379282400 3600 1 IST}. {-1364767200 0 0 IST}. {-1348437600 3600 1 IST}. {-1333317600 0 0 IST}. {-1315778400 3600 1 IST}. {-1301263200 0 0 IST}. {-1284328800 3600 1 IST}. {-1269813600 0 0 IST}. {-1253484000 3600 1 IST}. {-1238364000 0 0 IST}. {-
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9181
                                                                                                                                                                                                                                  Entropy (8bit):3.7982744899840535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:i2elBN44y3UKdDDMjEZtcRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIV0:i44y1xZGRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:F8AEFE8F561ED7E1DC81117676F7D0E0
                                                                                                                                                                                                                                  SHA1:1148176C2766B205B5D459A620D736B1D28283AA
                                                                                                                                                                                                                                  SHA-256:FB771A01326E1756C4026365BEE44A6B0FEF3876BF5463EFAB7CF4B97BF87CFC
                                                                                                                                                                                                                                  SHA-512:7C06CB215B920911E0DC9D24F0DD6E24DEC3D75FB2D0F175A9B4329304C9761FFFEE329DD797FF4343B41119397D7772D1D3DFC8F90C1DE205380DE463F42854
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Gibraltar) {. {-9223372036854775808 -1284 0 LMT}. {-2821649916 0 0 GMT}. {-1691964000 3600 1 BST}. {-1680472800 0 0 GMT}. {-1664143200 3600 1 BST}. {-1650146400 0 0 GMT}. {-1633903200 3600 1 BST}. {-1617487200 0 0 GMT}. {-1601848800 3600 1 BST}. {-1586037600 0 0 GMT}. {-1570399200 3600 1 BST}. {-1552168800 0 0 GMT}. {-1538344800 3600 1 BST}. {-1522533600 0 0 GMT}. {-1507500000 3600 1 BST}. {-1490565600 0 0 GMT}. {-1473631200 3600 1 BST}. {-1460930400 0 0 GMT}. {-1442786400 3600 1 BST}. {-1428876000 0 0 GMT}. {-1410732000 3600 1 BST}. {-1396216800 0 0 GMT}. {-1379282400 3600 1 BST}. {-1364767200 0 0 GMT}. {-1348437600 3600 1 BST}. {-1333317600 0 0 GMT}. {-1315778400 3600 1 BST}. {-1301263200 0 0 GMT}. {-1284328800 3600 1 BST}. {-1269813600 0 0 GMT}. {-1253484000 3600 1 BST}. {-1238364000 0 0 GMT}. {-1221429600 3600 1 BST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.830450830776494
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVxKL82wFVAIgoqyKL8p6yQakQAL/yQavKL8i:SlSWB9IZaM3ymvKA2wFVAIgovKAUyYL5
                                                                                                                                                                                                                                  MD5:DC2B3CAC4AF70A61D0F4C53288CC8D11
                                                                                                                                                                                                                                  SHA1:A423E06F88FDEED1960AF3C46A67F1CB9F293CAF
                                                                                                                                                                                                                                  SHA-256:9CB6E6FEC9461F94897F0310BFC3682A1134E284A56C729E7F4BCE726C2E2380
                                                                                                                                                                                                                                  SHA-512:8B455DA1D1A7AA1259E6E5A5CF90E62BA8073F769DCB8EB82503F2DFB70AA4539A688DC798880339A2722AA1871E8C8F16D8827064A2D7D8F2F232880359C78D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/London)]} {. LoadTimeZoneFile Europe/London.}.set TZData(:Europe/Guernsey) $TZData(:Europe/London).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7120
                                                                                                                                                                                                                                  Entropy (8bit):3.635790220811118
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:wQbXHk+PVqVaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtOEZ9A:w6XPzh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:E7A6AA8962067EF71174CD5AE79A8624
                                                                                                                                                                                                                                  SHA1:1250689DF0DFCCDD4B6B21C7867C4AA515D19ECD
                                                                                                                                                                                                                                  SHA-256:5FDBE427BC604FAC03316FD08138F140841C8CF2537CDF4B4BB20F2A9DFC4ECB
                                                                                                                                                                                                                                  SHA-512:5C590164499C4649D555F30054ECB5CF627CCCA8A9F94842328E90DD40477CADB1042D07EA4C368ABB7094D7A59A8C2EE7619E5B3458A0FAC066979B14AF44A6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Helsinki) {. {-9223372036854775808 5989 0 LMT}. {-2890258789 5989 0 HMT}. {-1535938789 7200 0 EET}. {-875671200 10800 1 EEST}. {-859773600 7200 0 EET}. {354672000 10800 1 EEST}. {370396800 7200 0 EET}. {386121600 10800 1 EEST}. {401846400 7200 0 EET}. {410220000 7200 0 EET}. {417574800 10800 1 EEST}. {433299600 7200 0 EET}. {449024400 10800 1 EEST}. {465354000 7200 0 EET}. {481078800 10800 1 EEST}. {496803600 7200 0 EET}. {512528400 10800 1 EEST}. {528253200 7200 0 EET}. {543978000 10800 1 EEST}. {559702800 7200 0 EET}. {575427600 10800 1 EEST}. {591152400 7200 0 EET}. {606877200 10800 1 EEST}. {622602000 7200 0 EET}. {638326800 10800 1 EEST}. {654656400 7200 0 EET}. {670381200 10800 1 EEST}. {686106000 7200 0 EET}. {701830800 10800 1 EEST}. {717555600 7200 0 EET}. {733280400 10800 1 EEST}. {749005200 7200 0 EET}. {764730000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.866592240835745
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVxKL82wFVAIgoqyKL8p6yQaqpfioxp8QavKL8i:SlSWB9IZaM3ymvKA2wFVAIgovKAUycqO
                                                                                                                                                                                                                                  MD5:9E18F66C32ADDDBCEDFE8A8B2135A0AC
                                                                                                                                                                                                                                  SHA1:9D2DC5BE334B0C6AEA15A98624321D56F57C3CB1
                                                                                                                                                                                                                                  SHA-256:6A03679D9748F4624078376D1FD05428ACD31E7CABBD31F4E38EBCCCF621C268
                                                                                                                                                                                                                                  SHA-512:014BAD4EF0209026424BC68CBF3F5D2B22B325D61A4476F1E4F020E1EF9CD4B365213E01C7EC6D9D40FA422FE8FE0FADB1E4CBB7D46905499691A642D813A379
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/London)]} {. LoadTimeZoneFile Europe/London.}.set TZData(:Europe/Isle_of_Man) $TZData(:Europe/London).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3974
                                                                                                                                                                                                                                  Entropy (8bit):3.7140382290341214
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:kICNapz9QnPPWDeP/vamdc2MKJ9k2gsh6YlnG:kuQnPo+CWJipP
                                                                                                                                                                                                                                  MD5:5F2F14127F11060A57C53565A24CB8F8
                                                                                                                                                                                                                                  SHA1:E79FC982C018CC7E3C29A956048ED3D0CFFE3311
                                                                                                                                                                                                                                  SHA-256:EAD62B6D04AA7623B9DF94D41E04C9E30C7BA8EB2CE3504105A0496A66EB87AE
                                                                                                                                                                                                                                  SHA-512:E709849DEF7F7CDAE3CA44F1939DF49D6FE5DE9C89F541343256FC0F7B9E55390AC496FF599D94B7F594D6BAE724AE4608A43F5870C18210525B061E801CC36B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Istanbul) {. {-9223372036854775808 6952 0 LMT}. {-2840147752 7016 0 IMT}. {-1869875816 7200 0 EET}. {-1693706400 10800 1 EEST}. {-1680490800 7200 0 EET}. {-1570413600 10800 1 EEST}. {-1552186800 7200 0 EET}. {-1538359200 10800 1 EEST}. {-1522551600 7200 0 EET}. {-1507514400 10800 1 EEST}. {-1490583600 7200 0 EET}. {-1440208800 10800 1 EEST}. {-1428030000 7200 0 EET}. {-1409709600 10800 1 EEST}. {-1396494000 7200 0 EET}. {-931140000 10800 1 EEST}. {-922762800 7200 0 EET}. {-917834400 10800 1 EEST}. {-892436400 7200 0 EET}. {-875844000 10800 1 EEST}. {-857358000 7200 0 EET}. {-781063200 10800 1 EEST}. {-764737200 7200 0 EET}. {-744343200 10800 1 EEST}. {-733806000 7200 0 EET}. {-716436000 10800 1 EEST}. {-701924400 7200 0 EET}. {-684986400 10800 1 EEST}. {-670474800 7200 0 EET}. {-654141600 10800 1 EEST}. {-639025200 7200 0 EET}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.831245786685746
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVxKL82wFVAIgoqyKL8p6yQap6cEBx/yQavKL8i:SlSWB9IZaM3ymvKA2wFVAIgovKAUyzO5
                                                                                                                                                                                                                                  MD5:F43ABA235B8B98F5C64181ABD1CEEC3A
                                                                                                                                                                                                                                  SHA1:A4A7D71ED148FBE53C2DF7497A89715EB24E84B7
                                                                                                                                                                                                                                  SHA-256:8E97798BE473F535816D6D9307B85102C03CC860D3690FE59E0B7EEF94D62D54
                                                                                                                                                                                                                                  SHA-512:B0E0FC97F08CB656E228353594FC907FC94A998859BB22648BF78043063932D0FC7282D31F63FCB79216218695B5DCDF298C37F0CB206160798CF3CA2C7598E1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/London)]} {. LoadTimeZoneFile Europe/London.}.set TZData(:Europe/Jersey) $TZData(:Europe/London).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2397
                                                                                                                                                                                                                                  Entropy (8bit):3.8622541648513464
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:cGv6a621nwJ2JoJrv0WvXlnDqVV0Qv3LEevBFoBGrjI9q1F008bBJd8:cGvt67yurvxXl6V/DYtX6
                                                                                                                                                                                                                                  MD5:FE44AD99AF96A031D21D308B0E534928
                                                                                                                                                                                                                                  SHA1:36A666585D0895155D31A6E5AFD6B7395C7334AA
                                                                                                                                                                                                                                  SHA-256:0C65366AB59C4B8734DE0F69E7081269A367116363EB3863D16FB7184CCC5EB9
                                                                                                                                                                                                                                  SHA-512:2789E8FC8FD73A0D3C915F5CBAD158D2A4995EE51607C4368F3AE1CC6418E93E204E4FCE6F796CDC60BB2E0ED8F79650DA4549C7663589B58E189D0D10F059C5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Kaliningrad) {. {-9223372036854775808 4920 0 LMT}. {-2422056120 3600 0 CET}. {-1693706400 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-938905200 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-788922000 7200 0 CET}. {-778730400 10800 1 CEST}. {-762663600 7200 0 CET}. {-757389600 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7202
                                                                                                                                                                                                                                  Entropy (8bit):3.6738341956502953
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:j/fE2JyurpyVaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtOEZ2:j/fN8GHh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:4E693AC10DD3FC66700A878B94D3701D
                                                                                                                                                                                                                                  SHA1:692200B78A3EA482577D13BE5588FEB0BF94DF01
                                                                                                                                                                                                                                  SHA-256:3AAC94E73BB4C803BBB4DE14826DAA0AC82BAE5C0841FD7C58B62A5C155C064D
                                                                                                                                                                                                                                  SHA-512:9B68D418B98DDF855C257890376AEC300FC6024E08C85AF5CFFE70BE9AC39D75293C35D841DB8A7BE5574FD185D736F5CB72205531736A202D25305744A2DD15
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Kiev) {. {-9223372036854775808 7324 0 LMT}. {-2840148124 7324 0 KMT}. {-1441159324 7200 0 EET}. {-1247536800 10800 0 MSK}. {-892522800 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-825382800 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 14400 1 MSD}. {622594800 10800 0 MSK}. {638319600 14400 1 MSD}. {646786800 10800 1 EEST}. {686102400 7200 0 EET}. {701820000 10800 1 EEST}. {717541200 7200 0 EET}. {733269600 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1959
                                                                                                                                                                                                                                  Entropy (8bit):3.5751912319178496
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:c1e/5gjS+OVkb/cXODnOwUDOS5u8OimFeb/ROHc9qOYNkw/O2blbEUhtCUH9mUBR:dWDTZVemFLN7NBx333+ix6b0JiG1
                                                                                                                                                                                                                                  MD5:249037A8019D3A5244DD59D8C3316403
                                                                                                                                                                                                                                  SHA1:2DABDE83753CE65D1A2D3949FF9B94401A2DD8C3
                                                                                                                                                                                                                                  SHA-256:5FE8535DD9A4729B68BF5EC178C6F978753A4A01BDC6F5529C2F8A3872B470D1
                                                                                                                                                                                                                                  SHA-512:4180DE17FDDA1417DD24229F775DD45FDE99078E71F2A583E6629D022DCD1B30CEB1ABCEEC78286CAE286E8CBAFC5A7AB20464D53B8BE2615B4681302C05B120
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Kirov) {. {-9223372036854775808 11928 0 LMT}. {-1593820800 10800 0 +03}. {-1247540400 14400 0 +05}. {354916800 18000 1 +05}. {370724400 14400 0 +04}. {386452800 18000 1 +05}. {402260400 14400 0 +04}. {417988800 18000 1 +05}. {433796400 14400 0 +04}. {449611200 18000 1 +05}. {465343200 14400 0 +04}. {481068000 18000 1 +05}. {496792800 14400 0 +04}. {512517600 18000 1 +05}. {528242400 14400 0 +04}. {543967200 18000 1 +05}. {559692000 14400 0 +04}. {575416800 18000 1 +05}. {591141600 14400 0 +04}. {606866400 10800 0 +04}. {606870000 14400 1 +04}. {622594800 10800 0 +03}. {638319600 14400 1 +04}. {654649200 10800 0 +03}. {670374000 14400 0 +04}. {701820000 10800 0 +04}. {701823600 14400 1 +04}. {717548400 10800 0 +03}. {733273200 14400 1 +04}. {748998000 10800 0 +03}. {764722800 14400 1 +04}. {780447600 10800 0 +03}. {796172400 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9471
                                                                                                                                                                                                                                  Entropy (8bit):3.738653060534981
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:1SgVSz+IZHX68PlXIFj544IrvfMsbxZTH7qwQ:1SYSz+IZHX68PlYFUM8xZTH7qwQ
                                                                                                                                                                                                                                  MD5:AD82B05F966F0EAD5B2F4FD7B6D56718
                                                                                                                                                                                                                                  SHA1:DE5A9BB8B0FCA79C38DD35905FF074503D5AAF13
                                                                                                                                                                                                                                  SHA-256:EE61A08BED392B75FBE67666BDCF7CE26DFA570FC2D1DEC9FFEF51E5D8CD8DF7
                                                                                                                                                                                                                                  SHA-512:68DC078090E2AF1EAF0150BBCF63E52E4675BF22E2FF6BBA4B4D0B244BFF23C73310A3E63365A4217B8466F2C2E7A4384D05D778F70513183B3A59016A55DDB0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Lisbon) {. {-9223372036854775808 -2205 0 LMT}. {-2713908195 -2205 0 LMT}. {-1830384000 0 0 WET}. {-1689555600 3600 1 WEST}. {-1677801600 0 0 WET}. {-1667437200 3600 1 WEST}. {-1647738000 0 0 WET}. {-1635814800 3600 1 WEST}. {-1616202000 0 0 WET}. {-1604365200 3600 1 WEST}. {-1584666000 0 0 WET}. {-1572742800 3600 1 WEST}. {-1553043600 0 0 WET}. {-1541206800 3600 1 WEST}. {-1521507600 0 0 WET}. {-1442451600 3600 1 WEST}. {-1426813200 0 0 WET}. {-1379293200 3600 1 WEST}. {-1364778000 0 0 WET}. {-1348448400 3600 1 WEST}. {-1333328400 0 0 WET}. {-1316394000 3600 1 WEST}. {-1301274000 0 0 WET}. {-1284339600 3600 1 WEST}. {-1269824400 0 0 WET}. {-1221440400 3600 1 WEST}. {-1206925200 0 0 WET}. {-1191200400 3600 1 WEST}. {-1175475600 0 0 WET}. {-1127696400 3600 1 WEST}. {-1111971600 0 0 WET}. {-1096851600 3600 1 WEST}. {-1080522000
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.901869793666386
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV/sUE2tvFVAIgoq8sUE2vqLyQavPSJ5QahsUE2u:SlSWB9IZaM3ymhrE2tvFVAIgohrE2vqm
                                                                                                                                                                                                                                  MD5:5F2AEC41DECD9E26955876080C56B247
                                                                                                                                                                                                                                  SHA1:4FDEC0926933AE5651DE095C519A2C4F9E567691
                                                                                                                                                                                                                                  SHA-256:88146DA16536CCF587907511FB0EDF40E392E6F6A6EFAB38260D3345CF2832E1
                                                                                                                                                                                                                                  SHA-512:B71B6C21071DED75B9B36D49EB5A779C5F74817FF070F70FEAB9E3E719E5F1937867547852052AA7BBAE8B842493FBC7DFAFD3AC47B70D36893541419DDB2D74
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Belgrade)]} {. LoadTimeZoneFile Europe/Belgrade.}.set TZData(:Europe/Ljubljana) $TZData(:Europe/Belgrade).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9839
                                                                                                                                                                                                                                  Entropy (8bit):3.737361476589814
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Gj4y1xZfvm8nKrhFs3XRnRaQqTLJaMt/VZ1R6Y+:GjPxZfvmgEhS3XRmau/VZ1R6Y+
                                                                                                                                                                                                                                  MD5:2A53A87C26A5D2AF62ECAAD8CECBF0D7
                                                                                                                                                                                                                                  SHA1:025D31C1D32F1100C1B00858929FD29B4E66E8F6
                                                                                                                                                                                                                                  SHA-256:2A69A7C9A2EE3057EBDB2615DBE5CB08F5D334210449DC3E42EA88564C29583A
                                                                                                                                                                                                                                  SHA-512:81EFA13E4AB30A9363E80EC1F464CC51F8DF3C492771494F3624844E074BA9B84FE50EF6C32F9467E6DAB41BD5159B492B752D0C97F3CB2F4B698C04E68C0255
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/London) {. {-9223372036854775808 -75 0 LMT}. {-3852662325 0 0 GMT}. {-1691964000 3600 1 BST}. {-1680472800 0 0 GMT}. {-1664143200 3600 1 BST}. {-1650146400 0 0 GMT}. {-1633903200 3600 1 BST}. {-1617487200 0 0 GMT}. {-1601848800 3600 1 BST}. {-1586037600 0 0 GMT}. {-1570399200 3600 1 BST}. {-1552168800 0 0 GMT}. {-1538344800 3600 1 BST}. {-1522533600 0 0 GMT}. {-1507500000 3600 1 BST}. {-1490565600 0 0 GMT}. {-1473631200 3600 1 BST}. {-1460930400 0 0 GMT}. {-1442786400 3600 1 BST}. {-1428876000 0 0 GMT}. {-1410732000 3600 1 BST}. {-1396216800 0 0 GMT}. {-1379282400 3600 1 BST}. {-1364767200 0 0 GMT}. {-1348437600 3600 1 BST}. {-1333317600 0 0 GMT}. {-1315778400 3600 1 BST}. {-1301263200 0 0 GMT}. {-1284328800 3600 1 BST}. {-1269813600 0 0 GMT}. {-1253484000 3600 1 BST}. {-1238364000 0 0 GMT}. {-1221429600 3600 1 BST}. {-120
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8826
                                                                                                                                                                                                                                  Entropy (8bit):3.7634145613638657
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:TYt4c9+dcVhv9HMLftvDGwdSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAr:0w2h1QSTRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:804A17ED0B32B9751C38110D28EB418B
                                                                                                                                                                                                                                  SHA1:24235897E163D33970451C48C4260F6C10C56ADD
                                                                                                                                                                                                                                  SHA-256:00E8152B3E5CD216E4FD8A992250C46E600E2AD773EEDDD87DAD31012BE55693
                                                                                                                                                                                                                                  SHA-512:53AFDDE8D516CED5C6CF0A906DBF72AF09A62278D1FC4D5C1562BBCE853D322457A6346C3DE8F112FCF665102E19A2E677972E941D0C80D0AB7C8DD0B694628E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Luxembourg) {. {-9223372036854775808 1476 0 LMT}. {-2069713476 3600 0 CET}. {-1692496800 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1662343200 7200 1 CEST}. {-1650157200 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-1612659600 0 0 WET}. {-1604278800 3600 1 WEST}. {-1585519200 0 0 WET}. {-1574038800 3600 1 WEST}. {-1552258800 0 0 WET}. {-1539997200 3600 1 WEST}. {-1520550000 0 0 WET}. {-1507510800 3600 1 WEST}. {-1490572800 0 0 WET}. {-1473642000 3600 1 WEST}. {-1459119600 0 0 WET}. {-1444006800 3600 1 WEST}. {-1427673600 0 0 WET}. {-1411866000 3600 1 WEST}. {-1396224000 0 0 WET}. {-1379293200 3600 1 WEST}. {-1364774400 0 0 WET}. {-1348448400 3600 1 WEST}. {-1333324800 0 0 WET}. {-1316394000 3600 1 WEST}. {-1301270400 0 0 WET}. {-1284339600 3600 1 WEST}. {-1269813600 0 0 WET}. {-1253484000 3600 1 WEST}. {-
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8225
                                                                                                                                                                                                                                  Entropy (8bit):3.745589534746728
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:kHF0p8d9VPb/aKrwSSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVab:oNHzy8STRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:795CAAE9AECE3900DEA1F5EBD0ED668B
                                                                                                                                                                                                                                  SHA1:61F1745E7B60E19F1286864B7A4285E8CCF11202
                                                                                                                                                                                                                                  SHA-256:4BE326DD950DDAD6FB9C392A31CEED1CB1525D043F1F7C14332FEB226AEA1859
                                                                                                                                                                                                                                  SHA-512:BBBABBE86A757D3EE9267128E7DA810346E74FD9CD3EF37192A831958FF0EDBBE47F14DA63669F6799056081D0365194E22D64D14B97490E4333504DFE22D151
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Madrid) {. {-9223372036854775808 -884 0 LMT}. {-2177452800 0 0 WET}. {-1631926800 3600 1 WEST}. {-1616889600 0 0 WET}. {-1601168400 3600 1 WEST}. {-1585353600 0 0 WET}. {-1442451600 3600 1 WEST}. {-1427673600 0 0 WET}. {-1379293200 3600 1 WEST}. {-1364774400 0 0 WET}. {-1348448400 3600 1 WEST}. {-1333324800 0 0 WET}. {-1316390400 3600 1 WEST}. {-1301270400 0 0 WET}. {-1284339600 3600 1 WEST}. {-1269820800 0 0 WET}. {-1026954000 3600 1 WEST}. {-1017619200 0 0 WET}. {-1001898000 3600 1 WEST}. {-999482400 7200 1 WEMT}. {-986090400 3600 1 WEST}. {-954115200 0 0 WET}. {-940208400 3600 0 CET}. {-873079200 7200 1 CEST}. {-862621200 3600 0 CET}. {-842839200 7200 1 CEST}. {-828320400 3600 0 CET}. {-811389600 7200 1 CEST}. {-796870800 3600 0 CET}. {-779940000 7200 1 CEST}. {-765421200 3600 0 CET}. {-748490400 7200 1 CEST}. {-733971600
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8425
                                                                                                                                                                                                                                  Entropy (8bit):3.728789296531475
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:wqZKgpNc6sln3mcRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZY:wChslJRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:5F73FCB70E5B27E540C1A5133F3B791C
                                                                                                                                                                                                                                  SHA1:406A2FB6439A3532150D69E711F253665F000B3C
                                                                                                                                                                                                                                  SHA-256:5E3BB07FD3592163A756596A25060683CDA7930C7F4411A406B3E1506F9B901C
                                                                                                                                                                                                                                  SHA-512:5263ABBE91D95BDD359B666BCDDAA6B4C8B810E986B9A94A80AF2B28E48C9C949EC5D5F21158AD306F7AF5BB6A47408C9AA5C5BB6D0053A9B9DA89E76E126FB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Malta) {. {-9223372036854775808 3484 0 LMT}. {-2403478684 3600 0 CET}. {-1690765200 7200 1 CEST}. {-1680487200 3600 0 CET}. {-1664758800 7200 1 CEST}. {-1648951200 3600 0 CET}. {-1635123600 7200 1 CEST}. {-1616896800 3600 0 CET}. {-1604278800 7200 1 CEST}. {-1585533600 3600 0 CET}. {-1571014800 7200 1 CEST}. {-1555293600 3600 0 CET}. {-932432400 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812588400 7200 1 CEST}. {-798073200 3600 0 CET}. {-781052400 7200 1 CEST}. {-766717200 3600 0 CET}. {-750898800 7200 1 CEST}. {-733359600 3600 0 CET}. {-719456400 7200 1 CEST}. {-701917200 3600 0 CET}. {-689209200 7200 1 CEST}. {-670460400 3600 0 CET}. {-114051600 7200 1 CEST}. {-103168800 3600 0 CET}. {-81997200 7200 1 CEST}. {-71715600 3600 0 CET}. {-50547600 7200 1 CEST}. {-40266000 3600 0 CET}
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.913470013356756
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV1AYKjGyVAIgoq2AYKjvCW6yQausWILMFJ8QarAYKa:SlSWB9IZaM3ymrAdjGyVAIgorAdjoyGK
                                                                                                                                                                                                                                  MD5:CFB0DE2E11B8AF400537BD0EF493C004
                                                                                                                                                                                                                                  SHA1:32E8FCB8571575E9DFE09A966F88C7D3EBCD183E
                                                                                                                                                                                                                                  SHA-256:5F82A28F1FEE42693FD8F3795F8E0D7E8C15BADF1FD9EE4D45794C4C0F36108C
                                                                                                                                                                                                                                  SHA-512:9E36B2EACA06F84D56D9A9A0A83C7C106D26A6A55CBAA696729F105600F5A0105F193899D5996C416EFAABC4649E91BA0ED90D38E8DF7B305C6D951A31C80718
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Helsinki)]} {. LoadTimeZoneFile Europe/Helsinki.}.set TZData(:Europe/Mariehamn) $TZData(:Europe/Helsinki).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2102
                                                                                                                                                                                                                                  Entropy (8bit):3.8519171770148932
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:K6ccjMsJ2JoJrZXnDqVV0Qv3LEevBFoBGrjI9q1F008bBJdO:PRjMAyurZX6V/DYtXE
                                                                                                                                                                                                                                  MD5:E5ECB372FF8F5ED274597551ED2C35F0
                                                                                                                                                                                                                                  SHA1:6792E2676C59F43B9F260AF2F33E4C2484E71D64
                                                                                                                                                                                                                                  SHA-256:78A57D601978869FCAA2737BEC4FDAB72025BC5FDDF7188CCC89034FA767DA6C
                                                                                                                                                                                                                                  SHA-512:261FFB4C7974C5F1C0AECA49D9B26F3BC2998C63CEF9CB168B1060E9EC12F7057DB5376128AFD8A31AF2CC9EF79577E96CD9863AA46AC330A5F057F72E43B7B9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Minsk) {. {-9223372036854775808 6616 0 LMT}. {-2840147416 6600 0 MMT}. {-1441158600 7200 0 EET}. {-1247536800 10800 0 MSK}. {-899780400 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-804646800 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 14400 1 MSD}. {622594800 10800 0 MSK}. {631141200 10800 0 MSK}. {670374000 7200 0 EEMMTT}. {670377600 10800 1 EEST}. {686102400 7200 0 EET}. {7018272
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8871
                                                                                                                                                                                                                                  Entropy (8bit):3.7700564621466666
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:2LCV8tXttpD72RXbvDGwdSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHT/:eAYt+STRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:B2BA91B2CDD19E255B68EA35E033C061
                                                                                                                                                                                                                                  SHA1:246E377E815FFC11BBAF898E952194FBEDAE9AA2
                                                                                                                                                                                                                                  SHA-256:768E3D45DB560777C8E13ED9237956CFE8630D840683FAD065A2F6948FD797BE
                                                                                                                                                                                                                                  SHA-512:607383524C478F1CB442679F6DE0964F8916EE1A8B0EF6806BDF7652E4520B0E842A611B432FB190C30C391180EA1867268BBBF6067310F70D5E72CB3E4D789F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Monaco) {. {-9223372036854775808 1772 0 LMT}. {-2486680172 561 0 PMT}. {-1855958961 0 0 WET}. {-1689814800 3600 1 WEST}. {-1680397200 0 0 WET}. {-1665363600 3600 1 WEST}. {-1648342800 0 0 WET}. {-1635123600 3600 1 WEST}. {-1616893200 0 0 WET}. {-1604278800 3600 1 WEST}. {-1585443600 0 0 WET}. {-1574038800 3600 1 WEST}. {-1552266000 0 0 WET}. {-1539997200 3600 1 WEST}. {-1520557200 0 0 WET}. {-1507510800 3600 1 WEST}. {-1490576400 0 0 WET}. {-1470618000 3600 1 WEST}. {-1459126800 0 0 WET}. {-1444006800 3600 1 WEST}. {-1427677200 0 0 WET}. {-1411952400 3600 1 WEST}. {-1396227600 0 0 WET}. {-1379293200 3600 1 WEST}. {-1364778000 0 0 WET}. {-1348448400 3600 1 WEST}. {-1333328400 0 0 WET}. {-1316394000 3600 1 WEST}. {-1301274000 0 0 WET}. {-1284339600 3600 1 WEST}. {-1269824400 0 0 WET}. {-1253494800 3600 1 WEST}. {-1238374800 0 0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2347
                                                                                                                                                                                                                                  Entropy (8bit):3.859849674605335
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cYedmnClAHEFFkebUe9OtUe9h7+UeGH3UeRUeIuUeKqCbUeaJJUevTkUetUeibEV:kmnAA4F7wxJ2JoJrprXn1CL9yLI0vjls
                                                                                                                                                                                                                                  MD5:AB2CB4A38196852883272148B4A14085
                                                                                                                                                                                                                                  SHA1:ED22233A615B775DB528053807858A0B69E9D4FB
                                                                                                                                                                                                                                  SHA-256:D9814005CB99F2275A4356A8B226E16C7C823ADC940F3A7BBB909D4C01BF44E3
                                                                                                                                                                                                                                  SHA-512:F2179FC1C15954FD7F7B824C5310183C96EDC630880E1C8C85DF4423ECC5994B8A9CA826745CC8BCA77945A36BCADAA87620C31FFBD40071438695A610EBF045
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Moscow) {. {-9223372036854775808 9017 0 LMT}. {-2840149817 9017 0 MMT}. {-1688265017 9079 0 MMT}. {-1656819079 12679 1 MST}. {-1641353479 9079 0 MMT}. {-1627965079 16279 1 MDST}. {-1618716679 12679 1 MST}. {-1596429079 16279 1 MDST}. {-1593820800 14400 0 MSD}. {-1589860800 10800 0 MSK}. {-1542427200 14400 1 MSD}. {-1539493200 18000 1 +05}. {-1525323600 14400 1 MSD}. {-1491188400 7200 0 EET}. {-1247536800 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 14400 1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.73570159193188
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq85GKLWVAIgNwMGKLG6yQatHefeWFKYGKL1:SlSWB9IZaM3yZdLWVAIgGMdL9y3HefeW
                                                                                                                                                                                                                                  MD5:47C275C076A278CA8E1FF24E9E46CC22
                                                                                                                                                                                                                                  SHA1:55992974C353552467C2B57E3955E4DD86BBFAD2
                                                                                                                                                                                                                                  SHA-256:34B61E78EF15EA98C056C1AC8C6F1FA0AE87BD6BC85C58BE8DA44D017B2CA387
                                                                                                                                                                                                                                  SHA-512:1F74FC0B452C0BE35360D1C9EC8347063E8480CA37BE893FD4FF7FC2279B7D0C0909A26763C7755DFB19BE9736340D3FB00D39E9F6BF23C1D2F0015372139847
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Nicosia)]} {. LoadTimeZoneFile Asia/Nicosia.}.set TZData(:Europe/Nicosia) $TZData(:Asia/Nicosia).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7651
                                                                                                                                                                                                                                  Entropy (8bit):3.7309855254369766
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:aG6sT+cQJWxdocRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQt:abcQJWxd/RNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:2A3F771DD9EAE2E9C1D8394C12C0ED71
                                                                                                                                                                                                                                  SHA1:541DCF144EFFE2DFF27B81A50D245C7385CC0871
                                                                                                                                                                                                                                  SHA-256:8DDFB0296622E0BFDBEF4D0C2B4EA2522DE26A16D05340DFECA320C0E7B2B1F7
                                                                                                                                                                                                                                  SHA-512:E1526BD21E379F8B2285481E3E12C1CF775AE43E205D3E7E4A1906B87821D5E15B101B24463A055B6013879CD2777112C7F27B5C5220F280E3C48240367AA663
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Oslo) {. {-9223372036854775808 2580 0 LMT}. {-2366757780 3600 0 CET}. {-1691884800 7200 1 CEST}. {-1680573600 3600 0 CET}. {-927511200 7200 0 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-781052400 7200 0 CEST}. {-765327600 3600 0 CET}. {-340844400 7200 1 CEST}. {-324514800 3600 0 CET}. {-308790000 7200 1 CEST}. {-293065200 3600 0 CET}. {-277340400 7200 1 CEST}. {-261615600 3600 0 CET}. {-245890800 7200 1 CEST}. {-230166000 3600 0 CET}. {-214441200 7200 1 CEST}. {-198716400 3600 0 CET}. {-182991600 7200 1 CEST}. {-166662000 3600 0 CET}. {-147913200 7200 1 CEST}. {-135212400 3600 0 CET}. {315529200 3600 0 CET}. {323830800 7200 1 CEST}. {338950800 3600 0 CET}. {354675600 7200 1 CEST}. {370400400 3600 0 CET}. {386125200 7200 1 CEST}. {40185
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8838
                                                                                                                                                                                                                                  Entropy (8bit):3.7637328221887567
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:1XV8tXttpD724lvDGwdSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIu:1FYtPSTRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:153CA0EF3813D91C5E23B34ADFE7A318
                                                                                                                                                                                                                                  SHA1:F7F18CB34424A9B62172F00374853F1D4A89BEE4
                                                                                                                                                                                                                                  SHA-256:092BF010A1CF3819B102C2A70340F4D67C87BE2E6A8154716241012B5DFABD88
                                                                                                                                                                                                                                  SHA-512:E2D418D43D9DFD169238DDB0E790714D3B88D16398FA041A9646CB35F24EF79EE48DA4B6201E6A598E89D4C651F8A2FB9FB874B2010A51B3CD35A86767BAF4D2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Paris) {. {-9223372036854775808 561 0 LMT}. {-2486678901 561 0 PMT}. {-1855958901 0 0 WET}. {-1689814800 3600 1 WEST}. {-1680397200 0 0 WET}. {-1665363600 3600 1 WEST}. {-1648342800 0 0 WET}. {-1635123600 3600 1 WEST}. {-1616893200 0 0 WET}. {-1604278800 3600 1 WEST}. {-1585443600 0 0 WET}. {-1574038800 3600 1 WEST}. {-1552266000 0 0 WET}. {-1539997200 3600 1 WEST}. {-1520557200 0 0 WET}. {-1507510800 3600 1 WEST}. {-1490576400 0 0 WET}. {-1470618000 3600 1 WEST}. {-1459126800 0 0 WET}. {-1444006800 3600 1 WEST}. {-1427677200 0 0 WET}. {-1411952400 3600 1 WEST}. {-1396227600 0 0 WET}. {-1379293200 3600 1 WEST}. {-1364778000 0 0 WET}. {-1348448400 3600 1 WEST}. {-1333328400 0 0 WET}. {-1316394000 3600 1 WEST}. {-1301274000 0 0 WET}. {-1284339600 3600 1 WEST}. {-1269824400 0 0 WET}. {-1253494800 3600 1 WEST}. {-1238374800 0 0 W
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.86256001696314
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV/sUE2tvFVAIgoq8sUE2vqLyQazKIGl1/yQahsUE2u:SlSWB9IZaM3ymhrE2tvFVAIgohrE2vq7
                                                                                                                                                                                                                                  MD5:4F430ECF91032E40457F2D2734887860
                                                                                                                                                                                                                                  SHA1:D1C099523C34ED0BD48C24A511377B232548591D
                                                                                                                                                                                                                                  SHA-256:F5AB2E253CA0AB7A9C905B720B19F713469877DE1874D5AF81A8F3E74BA17FC8
                                                                                                                                                                                                                                  SHA-512:2E6E73076A18F1C6C8E89949899F81F232AE66FEB8FFA2A5CE5447FFF581A0D5E0E88DABEAA3C858CC5544C2AE9C6717E590E846CBFD58CEF3B7558F677334FB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Belgrade)]} {. LoadTimeZoneFile Europe/Belgrade.}.set TZData(:Europe/Podgorica) $TZData(:Europe/Belgrade).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7763
                                                                                                                                                                                                                                  Entropy (8bit):3.7367850410615597
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:3Nt6F3oxSscRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUE:3/xSTRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:D04290286789AB05490A7DE8569D80AB
                                                                                                                                                                                                                                  SHA1:B65938E29CBFB65D253E041EE1CD92FE75C3C663
                                                                                                                                                                                                                                  SHA-256:60494447C38C67E8173D4A9CDBA8D16AF90545FA83F3558DB8C9B7D0D052DD45
                                                                                                                                                                                                                                  SHA-512:B0897CD4785D737B7C5E5CE717B55AEE8689F83105DDB8A0DA2B4977961124AFA5AF573D57AA4467E5DB68FC5F927D7B58AEE7280238392C5666CC090476EC91
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Prague) {. {-9223372036854775808 3464 0 LMT}. {-3786829064 3464 0 PMT}. {-2469401864 3600 0 CET}. {-1693706400 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-938905200 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-781052400 7200 1 CEST}. {-777862800 7200 0 CEST}. {-765327600 3600 0 CET}. {-746578800 7200 1 CEST}. {-733359600 3600 0 CET}. {-728517600 0 1 GMT}. {-721260000 0 0 CET}. {-716425200 7200 1 CEST}. {-701910000 3600 0 CET}. {-684975600 7200 1 CEST}. {-670460400 3600 0 CET}. {-654217200 7200 1 CEST}. {-639010800 3600 0 CET}. {283993200 3600 0 CET}. {291776400 7200 1 CEST}. {307501200 3600 0 CET}. {323830800 7200 1 CEST}. {338
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7400
                                                                                                                                                                                                                                  Entropy (8bit):3.686652767751974
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:A46YyurGXl6V/jfaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtk:AnGG160h2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:5F71EBD41FC26CA6FAA0A26CE83FA618
                                                                                                                                                                                                                                  SHA1:0FC66EEB374A2930A7F6E2BB5B7D6C4FD00A258C
                                                                                                                                                                                                                                  SHA-256:6F63E58F355EF6C4CF8F954E01544B0E152605A72B400C731E3100B422A567D0
                                                                                                                                                                                                                                  SHA-512:20B730949A4967C49D259D4D00D8020579580F7FAA0278FBCEBDF8A8173BBF63846DDBF26FFFBBADB0FAF3FD0EB427DBB8CF18A4A80F7B023D2027CC952A773F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Riga) {. {-9223372036854775808 5794 0 LMT}. {-2840146594 5794 0 RMT}. {-1632008194 9394 1 LST}. {-1618702594 5794 0 RMT}. {-1601681794 9394 1 LST}. {-1597275394 5794 0 RMT}. {-1377308194 7200 0 EET}. {-928029600 10800 0 MSK}. {-899521200 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-795834000 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 10800 1 EEST}. {622598
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8511
                                                                                                                                                                                                                                  Entropy (8bit):3.729257183076779
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:YnZKupNc6XTWycRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQt:YVhiRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:3E209874EA8830B8436F897B0B7682B1
                                                                                                                                                                                                                                  SHA1:FC9AB2212C10C25850ACE69DC3BE125FD0912092
                                                                                                                                                                                                                                  SHA-256:626E7F8389382108E323B8447416BAC420A29442D852817024A39A97D556F365
                                                                                                                                                                                                                                  SHA-512:24C1A7890E076C4D58426D62726BC21FA6F70F16B5E9797405B7404AACB1CB2FC283483018418EF0CEE43720838864E01427C60269D98866A48F35CAF0483EFA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Rome) {. {-9223372036854775808 2996 0 LMT}. {-3259097396 2996 0 RMT}. {-2403565200 3600 0 CET}. {-1690765200 7200 1 CEST}. {-1680487200 3600 0 CET}. {-1664758800 7200 1 CEST}. {-1648951200 3600 0 CET}. {-1635123600 7200 1 CEST}. {-1616896800 3600 0 CET}. {-1604278800 7200 1 CEST}. {-1585533600 3600 0 CET}. {-1571014800 7200 1 CEST}. {-1555293600 3600 0 CET}. {-932432400 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-830307600 7200 0 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-807152400 7200 0 CEST}. {-798073200 3600 0 CET}. {-781052400 7200 1 CEST}. {-766717200 3600 0 CET}. {-750898800 7200 1 CEST}. {-733359600 3600 0 CET}. {-719456400 7200 1 CEST}. {-701917200 3600 0 CET}. {-689209200 7200 1 CEST}. {-670460400 3600 0 CET}. {-114051600 7200 1 CEST}. {-103168800 3600 0 CET}. {-81997200 7200 1 C
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2045
                                                                                                                                                                                                                                  Entropy (8bit):3.5710319343050183
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cBesqgOjS+OVkb/cXODnOwUDOS5u8OimFeb/ROHc9qOYNkw/O2blbEUhtCUHiWnb:rdDTZVemFLN7NBx3BngyxJvqJ2FJ/jz
                                                                                                                                                                                                                                  MD5:30271DF851CE290256FA0BE793F3A918
                                                                                                                                                                                                                                  SHA1:307BF37BD5110537B023A648AAC41F86E3D34ACB
                                                                                                                                                                                                                                  SHA-256:11400A62327FB9DEFB2D16EBD8E759F94C37EF4F12C49AC97DA2E5031FFA0079
                                                                                                                                                                                                                                  SHA-512:3E86BDF258BA23AFF9E1BDCDFE7853D5413A589160F67AF7424CE014B7A77A948B8BF973EB02A0FFFE47D5D0EA4464D851DF294C04AF685C0AF7A0EB08DD9067
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Samara) {. {-9223372036854775808 12020 0 LMT}. {-1593820800 10800 0 +03}. {-1247540400 14400 0 +04}. {-1102305600 14400 0 +05}. {354916800 18000 1 +05}. {370724400 14400 0 +04}. {386452800 18000 1 +05}. {402260400 14400 0 +04}. {417988800 18000 1 +05}. {433796400 14400 0 +04}. {449611200 18000 1 +05}. {465343200 14400 0 +04}. {481068000 18000 1 +05}. {496792800 14400 0 +04}. {512517600 18000 1 +05}. {528242400 14400 0 +04}. {543967200 18000 1 +05}. {559692000 14400 0 +04}. {575416800 18000 1 +05}. {591141600 14400 0 +04}. {606866400 10800 0 +04}. {606870000 14400 1 +04}. {622594800 10800 0 +03}. {638319600 14400 1 +04}. {654649200 10800 0 +03}. {670374000 7200 0 +03}. {670377600 10800 1 +03}. {686102400 10800 0 +03}. {687916800 14400 0 +04}. {701820000 18000 1 +05}. {717544800 14400 0 +04}. {733269600 18000 1 +05}. {748994400
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.908962717024613
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVvjFwFVAIgoqsuCHRLyQawELDX7x/yQax9:SlSWB9IZaM3ymx5wFVAIgoxuCxLyt/yR
                                                                                                                                                                                                                                  MD5:C50388AD7194924572FA470761DD09C7
                                                                                                                                                                                                                                  SHA1:EF0A2223B06BE12EFE55EE72BF2C941B7BFB2FFE
                                                                                                                                                                                                                                  SHA-256:7F89757BAE3C7AE59200DCEEEE5C38A7F74EBAA4AA949F54AFD5E9BB64B13123
                                                                                                                                                                                                                                  SHA-512:0CE5FF2F839CD64A2C9A5AE6BBE122C91342AE44BDECDB9A3BA9F08578BC0B474BC0AF0E773868B273423289254909A38902B225A0092D048AC44BCF883AB4B0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Rome)]} {. LoadTimeZoneFile Europe/Rome.}.set TZData(:Europe/San_Marino) $TZData(:Europe/Rome).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.890934294125181
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV/sUE2tvFVAIgoq8sUE2vqLyQawEX3GEaQahsUE2u:SlSWB9IZaM3ymhrE2tvFVAIgohrE2vqa
                                                                                                                                                                                                                                  MD5:5C12CEEDB17515260E2E143FB8F867F5
                                                                                                                                                                                                                                  SHA1:51B9CDF922BFBA52BF2618B63435EC510DEAE423
                                                                                                                                                                                                                                  SHA-256:7C45DFD5F016982F01589FD2D1BAF97898D5716951A4E08C3540A76E8D56CEB1
                                                                                                                                                                                                                                  SHA-512:7A6B7FDFD6E5CFEB2D1AC136922304B0A65362E19307E0F1E20DBF48BED95A262FAC9CBCDB015C3C744D57118A85BD47A57636A05144430BF6707404F8E53E8C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Belgrade)]} {. LoadTimeZoneFile Europe/Belgrade.}.set TZData(:Europe/Sarajevo) $TZData(:Europe/Belgrade).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1990
                                                                                                                                                                                                                                  Entropy (8bit):3.5705804674707893
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cWe35gjS+OVkb/cXODnOwUDOS5u8OimFeb/ROHc9qOYNkwLUk+EUhtCUH9mUBU9R:qWDTZVemFLN70333+ix6b0JiGk
                                                                                                                                                                                                                                  MD5:EEA55E1788265CCC7B3BDB775AF3DD38
                                                                                                                                                                                                                                  SHA1:E327A5965114AB8BF6E479989E43786F0B74CFB1
                                                                                                                                                                                                                                  SHA-256:0031D4DEC64866DEB1B5E566BB957F2C0E46E5751B31DF9C8A3DA1912AEC4CB2
                                                                                                                                                                                                                                  SHA-512:21EF7D364814259F23319D4BC0E4F7F0653D35C1DD03D22ACD8E9A540EE8A9E651BEE22501E4150F6C74901AC2ED750CE08AAE0551DF5A44AB11FD4A3DB49D59
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Saratov) {. {-9223372036854775808 11058 0 LMT}. {-1593820800 10800 0 +03}. {-1247540400 14400 0 +05}. {354916800 18000 1 +05}. {370724400 14400 0 +04}. {386452800 18000 1 +05}. {402260400 14400 0 +04}. {417988800 18000 1 +05}. {433796400 14400 0 +04}. {449611200 18000 1 +05}. {465343200 14400 0 +04}. {481068000 18000 1 +05}. {496792800 14400 0 +04}. {512517600 18000 1 +05}. {528242400 14400 0 +04}. {543967200 18000 1 +05}. {559692000 14400 0 +04}. {575416800 10800 0 +04}. {575420400 14400 1 +04}. {591145200 10800 0 +03}. {606870000 14400 1 +04}. {622594800 10800 0 +03}. {638319600 14400 1 +04}. {654649200 10800 0 +03}. {670374000 14400 0 +04}. {701820000 10800 0 +04}. {701823600 14400 1 +04}. {717548400 10800 0 +03}. {733273200 14400 1 +04}. {748998000 10800 0 +03}. {764722800 14400 1 +04}. {780447600 10800 0 +03}. {796172400
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2307
                                                                                                                                                                                                                                  Entropy (8bit):3.8673720237532523
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:wMxjIJJ2JoJrsyCmh7VloiIa0QM0ScfSblniT+CC:jjInyur/hUaKln
                                                                                                                                                                                                                                  MD5:F745F2F2FDEA14C70EA27BA35D4E3051
                                                                                                                                                                                                                                  SHA1:C4F01A629E6BAFB31F722FA65DC92B36D4E61E43
                                                                                                                                                                                                                                  SHA-256:EAE97716107B2BF4A14A08DD6197E0542B6EE27C3E12C726FC5BAEF16A144165
                                                                                                                                                                                                                                  SHA-512:0E32BE79C2576943D3CB684C2E25EE3970BE7F490FF8FD41BD897249EA560F280933B26B3FBB841C67915A3427CB009A1BFC3DACD70C4F77E33664104E32033E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Simferopol) {. {-9223372036854775808 8184 0 LMT}. {-2840148984 8160 0 SMT}. {-1441160160 7200 0 EET}. {-1247536800 10800 0 MSK}. {-888894000 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-811645200 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 14400 1 MSD}. {622594800 10800 0 MSK}. {631141200 10800 0 MSK}. {646786800 7200 0 EET}. {694216800 7200 0 EET}. {701820000 10800 1 EEST}. {71754
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):182
                                                                                                                                                                                                                                  Entropy (8bit):4.906520812033373
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV/sUE2tvFVAIgoq8sUE2vqLyQawOgpr8QahsUE2u:SlSWB9IZaM3ymhrE2tvFVAIgohrE2vq3
                                                                                                                                                                                                                                  MD5:BB062D4D5D6EA9BA172AC0555227A09C
                                                                                                                                                                                                                                  SHA1:75CCA7F75CEB77BE5AFB02943917DB048051F396
                                                                                                                                                                                                                                  SHA-256:51820E2C5938CEF89A6ED2114020BD32226EF92102645526352E1CB7995B7D0A
                                                                                                                                                                                                                                  SHA-512:8C6AD79DD225C566D2D93606575A1BF8DECF091EDFEED1F10CB41C5464A6A9F1C15BEB4957D76BD1E03F5AE430319480A3FDACEF3116EA2AF0464427468BC855
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Belgrade)]} {. LoadTimeZoneFile Europe/Belgrade.}.set TZData(:Europe/Skopje) $TZData(:Europe/Belgrade).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7396
                                                                                                                                                                                                                                  Entropy (8bit):3.6373782291014924
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:8lAV/6vcBrYixX21/BVaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykePG:8lAV/SEm1/mh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:8B538BB68A7FF0EB541EB2716264BAD9
                                                                                                                                                                                                                                  SHA1:49899F763786D4E7324CC5BAAECFEA87D5C4F6C7
                                                                                                                                                                                                                                  SHA-256:9D60EF4DBA6D3802CDD25DC87E00413EC7F37777868C832A9E4963E8BCDB103C
                                                                                                                                                                                                                                  SHA-512:AD8D75EE4A484050BB108577AE16E609358A9E4F31EA1649169B4A26C8348A502B4135FE3A282A2454799250C6EDF9E70B236BCF23E1F6540E123E39E81BBE41
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Sofia) {. {-9223372036854775808 5596 0 LMT}. {-2840146396 7016 0 IMT}. {-2369527016 7200 0 EET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-788922000 3600 0 CET}. {-781048800 7200 0 EET}. {291762000 10800 0 EEST}. {307576800 7200 0 EET}. {323816400 10800 1 EEST}. {339026400 7200 0 EET}. {355266000 10800 1 EEST}. {370393200 7200 0 EET}. {386715600 10800 1 EEST}. {401846400 7200 0 EET}. {417571200 10800 1 EEST}. {433296000 7200 0 EET}. {449020800 10800 1 EEST}. {465350400 7200 0 EET}. {481075200 10800 1 EEST}. {496800000 7200 0 EET}. {512524800 10800 1 EEST}. {528249600 7200 0 EET}. {543974400 10800 1 EEST}. {559699200 7200 0 EET}. {575424000 10800 1 EEST}. {591148800 7200 0 EET}. {606873600 10800 1 EEST}. {622598400 7200 0 EET}. {638323200 10
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7058
                                                                                                                                                                                                                                  Entropy (8bit):3.730067397634837
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:K39ucRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUbAyzF76:K3HRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:7F6C45358FC5E91125ACBDD46BBD93FE
                                                                                                                                                                                                                                  SHA1:C07A80D3C136679751D64866B725CC390D73B750
                                                                                                                                                                                                                                  SHA-256:119E9F7B1284462EB8E920E7216D1C219B09A73B323796BBF843346ECD71309A
                                                                                                                                                                                                                                  SHA-512:585AE0B1DE1F5D31E45972169C831D837C19D05E21F65FAD3CB84BEF8270C31BF2F635FB803CB70C569FAC2C8AA6ABDE057943F4B51BF1D73B72695FE95ECFD2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Stockholm) {. {-9223372036854775808 4332 0 LMT}. {-2871681132 3614 0 SET}. {-2208992414 3600 0 CET}. {-1692496800 7200 1 CEST}. {-1680483600 3600 0 CET}. {315529200 3600 0 CET}. {323830800 7200 1 CEST}. {338950800 3600 0 CET}. {354675600 7200 1 CEST}. {370400400 3600 0 CET}. {386125200 7200 1 CEST}. {401850000 3600 0 CET}. {417574800 7200 1 CEST}. {433299600 3600 0 CET}. {449024400 7200 1 CEST}. {465354000 3600 0 CET}. {481078800 7200 1 CEST}. {496803600 3600 0 CET}. {512528400 7200 1 CEST}. {528253200 3600 0 CET}. {543978000 7200 1 CEST}. {559702800 3600 0 CET}. {575427600 7200 1 CEST}. {591152400 3600 0 CET}. {606877200 7200 1 CEST}. {622602000 3600 0 CET}. {638326800 7200 1 CEST}. {654656400 3600 0 CET}. {670381200 7200 1 CEST}. {686106000 3600 0 CET}. {701830800 7200 1 CEST}. {717555600 3600 0 CET}. {733280400 7200 1 CEST
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7295
                                                                                                                                                                                                                                  Entropy (8bit):3.6772204206246193
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:dcqDyurGXl6V/DraKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtk:e7GG16gh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:981078CAEAA994DD0C088B8C4255018A
                                                                                                                                                                                                                                  SHA1:5B5E542491FCCC80B04F6F3CA3BA76FEE35BC207
                                                                                                                                                                                                                                  SHA-256:716CFFE58847E0084C904A01EF4230F63275660691A4BA54D0B80654E215CC8F
                                                                                                                                                                                                                                  SHA-512:3010639D28C7363D0B787F84EF57EE30F457BD8A6A64AEDED1E813EB1AF0A8D85DA0A788C810509F932867F7361B338753CC9B79ACA95D2D32A77F7A8AA8BC9F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Tallinn) {. {-9223372036854775808 5940 0 LMT}. {-2840146740 5940 0 TMT}. {-1638322740 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-1593824400 5940 0 TMT}. {-1535938740 7200 0 EET}. {-927943200 10800 0 MSK}. {-892954800 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-797648400 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 10800 1 EEST}. {622598400 7200 0 EET}. {638
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7412
                                                                                                                                                                                                                                  Entropy (8bit):3.7216700074911437
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:6t1WXXRM8DAdRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQlth:6GXh9AdRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:872AB00046280F53657A47D41FBA5EFE
                                                                                                                                                                                                                                  SHA1:311BF2342808BD9DC8AB2C2856A1F91F50CFB740
                                                                                                                                                                                                                                  SHA-256:D02C2CD894AE4D3C2619A4249088A566B02517FA3BF65DEFAF4280C407E5B5B3
                                                                                                                                                                                                                                  SHA-512:2FF901990FA8D6713D875F90FE611E54B35A2216C380E88D408C4FB5BD06916EE804DC6331C117C3AC643731BEADB5BDEDEA0F963B89FAEDB07CA3FFD0B3A535
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Tirane) {. {-9223372036854775808 4760 0 LMT}. {-1767230360 3600 0 CET}. {-932346000 7200 0 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-843519600 3600 0 CET}. {136854000 7200 1 CEST}. {149896800 3600 0 CET}. {168130800 7200 1 CEST}. {181432800 3600 0 CET}. {199839600 7200 1 CEST}. {213141600 3600 0 CET}. {231894000 7200 1 CEST}. {244591200 3600 0 CET}. {263257200 7200 1 CEST}. {276040800 3600 0 CET}. {294706800 7200 1 CEST}. {307490400 3600 0 CET}. {326156400 7200 1 CEST}. {339458400 3600 0 CET}. {357087600 7200 1 CEST}. {370389600 3600 0 CET}. {389142000 7200 1 CEST}. {402444000 3600 0 CET}. {419468400 7200 1 CEST}. {433807200 3600 0 CET}. {449622000 7200 1 CEST}. {457480800 7200 0 CEST}. {465354000 3600 0 CET}. {481078800 7200 1 CEST}. {496803600 3600 0 CET}. {512528400 7200 1 CEST}. {528253200 3600 0 CET}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.85845283098493
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV+NM/LpVAIgoq9NM/eO6yQa3MPgJM1p8QagNM/cn:SlSWB9IZaM3ymI6NVAIgoI6eFytM4M8g
                                                                                                                                                                                                                                  MD5:743453106E8CD7AE48A2F575255AF700
                                                                                                                                                                                                                                  SHA1:7CD6F6DCA61792B4B2CBF6645967B9349ECEACBE
                                                                                                                                                                                                                                  SHA-256:C28078D4B42223871B7E1EB42EEB4E70EA0FED638288E9FDA5BB5F954D403AFB
                                                                                                                                                                                                                                  SHA-512:458072C7660BEAFEB9AE5A2D3AEA6DA582574D80193C89F08A57B17033126E28A175F5B6E2990034660CAE3BC1E837F8312BC4AA365F426BD54588D0C5A12EB8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Chisinau)]} {. LoadTimeZoneFile Europe/Chisinau.}.set TZData(:Europe/Tiraspol) $TZData(:Europe/Chisinau).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2046
                                                                                                                                                                                                                                  Entropy (8bit):3.588329521363201
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cUeRgjS+OVkb/cXODnOwUDOS5u8OimFeb/ROHc9qOYNkw/O2blbEUhtCUHiWn0it:EWDTZVemFLN7NBx3Bnu3+ix6b0JiGef
                                                                                                                                                                                                                                  MD5:E4394950F7838CD984172D68DA413486
                                                                                                                                                                                                                                  SHA1:75F84A4C887463DE3F82C7F0339DD7D71871AA65
                                                                                                                                                                                                                                  SHA-256:CB780BBC06F9268CE126461AF9B6539FF16964767A8763479099982214280896
                                                                                                                                                                                                                                  SHA-512:7D0E3904300FDD3C4814E15A3C042F3E641BF56AF6867DA7580D1DAD8E07F5B4F0C0717A34E8336C0908D760EDCD48605C7B6BA06A5165BD2BD3AF0B68399C59
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Ulyanovsk) {. {-9223372036854775808 11616 0 LMT}. {-1593820800 10800 0 +03}. {-1247540400 14400 0 +05}. {354916800 18000 1 +05}. {370724400 14400 0 +04}. {386452800 18000 1 +05}. {402260400 14400 0 +04}. {417988800 18000 1 +05}. {433796400 14400 0 +04}. {449611200 18000 1 +05}. {465343200 14400 0 +04}. {481068000 18000 1 +05}. {496792800 14400 0 +04}. {512517600 18000 1 +05}. {528242400 14400 0 +04}. {543967200 18000 1 +05}. {559692000 14400 0 +04}. {575416800 18000 1 +05}. {591141600 14400 0 +04}. {606866400 10800 0 +04}. {606870000 14400 1 +04}. {622594800 10800 0 +03}. {638319600 14400 1 +04}. {654649200 10800 0 +03}. {670374000 7200 0 +03}. {670377600 10800 1 +03}. {686102400 7200 0 +02}. {695779200 10800 0 +04}. {701823600 14400 1 +04}. {717548400 10800 0 +03}. {733273200 14400 1 +04}. {748998000 10800 0 +03}. {764722800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7287
                                                                                                                                                                                                                                  Entropy (8bit):3.681086026612126
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:DptgbYyurZiVaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtOEZ2:Dp4GZNh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:E1088083B0D5570AF8FBE54A4C553AFB
                                                                                                                                                                                                                                  SHA1:A6EC8636A0092737829B873C4879E9D4C1B0A288
                                                                                                                                                                                                                                  SHA-256:19D87DB3DAB942037935FEC0A9A5E5FE24AFEB1E5F0F1922AF2AF2C2E186621D
                                                                                                                                                                                                                                  SHA-512:C58AA37111AE29F85C9C3F1E52DB3C9B2E2DCEFBBB9ACA4C61AD9B00AA7F3A436E754D2285774E882614B16D5DB497ED370A06EE1AFC513579E1E5F1475CA160
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Uzhgorod) {. {-9223372036854775808 5352 0 LMT}. {-2500939752 3600 0 CET}. {-946774800 3600 0 CET}. {-938905200 7200 1 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796870800 7200 1 CEST}. {-794714400 3600 0 CET}. {-773456400 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 14400 1 MSD}. {622594800 10800 0 MSK}. {631141200 10800 0 MSK}. {646786800 3600 0 CET}. {670384800 7200 0 EET}. {694216800
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.906311228352029
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVnCMPwVAIgoqkCMJW6yQa1NEHp8Qa5CMP:SlSWB9IZaM3ym5XwVAIgo5PyvNEJ8jH
                                                                                                                                                                                                                                  MD5:C1817BA53C7CD6BF007A7D1E17FBDFF1
                                                                                                                                                                                                                                  SHA1:C72DCD724E24BBE7C22F9279B05EE03924603348
                                                                                                                                                                                                                                  SHA-256:E000C8E2A27AE8494DC462D486DC28DAFA502F644FC1540B7B6050EABE4712DC
                                                                                                                                                                                                                                  SHA-512:E48C1E1E60233CEC648004B6441F4A49D18D07904F88670A6F9A3DACC3006F7D7CE4A9ACB6C9B6DB8F45CB324EA1BCF6CC3DA8C1FFB40A948BB2231AC4B57EEB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Zurich)]} {. LoadTimeZoneFile Europe/Zurich.}.set TZData(:Europe/Vaduz) $TZData(:Europe/Zurich).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):171
                                                                                                                                                                                                                                  Entropy (8bit):4.8663121336740405
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVvjFwFVAIgoqsuCHRLyQa1xLM1p8Qax9:SlSWB9IZaM3ymx5wFVAIgoxuCxLyvN+a
                                                                                                                                                                                                                                  MD5:0652C9CF19CCF5C8210330B22F200D47
                                                                                                                                                                                                                                  SHA1:052121E14825CDF98422CAA2CDD20184F184A446
                                                                                                                                                                                                                                  SHA-256:3BC0656B5B52E3C3C6B7BC5A53F9228AAFA3EB867982CFD9332B7988687D310B
                                                                                                                                                                                                                                  SHA-512:1880524DCA926F4BFD1972E53D5FE616DE18E4A29E9796ABEAEE4D7CD10C6FE79C0D731B305BD4DAA6FC3917B286543D622F2291B76DABA231B9B22A784C7475
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Rome)]} {. LoadTimeZoneFile Europe/Rome.}.set TZData(:Europe/Vatican) $TZData(:Europe/Rome).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7659
                                                                                                                                                                                                                                  Entropy (8bit):3.7322931990772257
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:2ntWj6DmcRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUbAT:2tWURNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:E8D0D78179D1E9D738CEEC1D0D4943E5
                                                                                                                                                                                                                                  SHA1:E0469B86F545FFFA81CE9694C96FE30F33F745DD
                                                                                                                                                                                                                                  SHA-256:44FF42A100EA0EB448C3C00C375F1A53614B0B5D468ADF46F2E5EAFF44F7A64C
                                                                                                                                                                                                                                  SHA-512:FACA076F44A64211400910E4A7CAD475DD24745ECCE2FE608DD47B0D5BB9221FF15B9D58A767A90FF8D25E0545C3E50B3E464FF80B1D23E934489420640F5C8A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Vienna) {. {-9223372036854775808 3921 0 LMT}. {-2422055121 3600 0 CET}. {-1693706400 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618700400 3600 0 CET}. {-1577926800 3600 0 CET}. {-1569711600 7200 1 CEST}. {-1555801200 3600 0 CET}. {-938905200 7200 0 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796777200 3600 0 CET}. {-781052400 7200 1 CEST}. {-780188400 3600 0 CET}. {-757386000 3600 0 CET}. {-748479600 7200 1 CEST}. {-733359600 3600 0 CET}. {-717634800 7200 1 CEST}. {-701910000 3600 0 CET}. {-684975600 7200 1 CEST}. {-670460400 3600 0 CET}. {323823600 7200 1 CEST}. {338940000 3600 0 CET}. {347151600 3600 0 CET}. {354675600 7200 1 CEST}. {370400400 3600 0 CET}. {386125200 7200 1 CEST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7233
                                                                                                                                                                                                                                  Entropy (8bit):3.682695131194103
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:/FsyurvxXl6V/DAOLl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtk:/fGJ16Oh2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:CF7967CD882413C1423CCD5A1EDC8B2E
                                                                                                                                                                                                                                  SHA1:72F5F5D280530A67591FC0F88BF272E2975E173C
                                                                                                                                                                                                                                  SHA-256:1E13055C7BF8D7469AFC28B0ED91171D203B382B62F78D140C1CB12CF968637C
                                                                                                                                                                                                                                  SHA-512:777B7418FFB8DFE4E6A2B1057BB3CFF2358269044F0E5887260663790D0344BDFD8BF5C220987E30B2D8D391BB96C17C8C5EE86DA83EC4874F7EC3172477DFB6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Vilnius) {. {-9223372036854775808 6076 0 LMT}. {-2840146876 5040 0 WMT}. {-1672536240 5736 0 KMT}. {-1585100136 3600 0 CET}. {-1561251600 7200 0 EET}. {-1553565600 3600 0 CET}. {-928198800 10800 0 MSK}. {-900126000 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-802141200 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 7200 0 EEMMTT}. {606873600 10800 1 EEST}. {622598400 7200 0 EET}. {638
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2021
                                                                                                                                                                                                                                  Entropy (8bit):3.5806689351967527
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:cRecrebjS+OVkb/cXODnOwUDOS5u8OimFeb/ROHc9qOYNkwLUk+EUhtCUH9mUBUv:YenDTZVemFLN70333+ix6b0JiGE
                                                                                                                                                                                                                                  MD5:DFC3D37284F1DCFE802539DB1E684399
                                                                                                                                                                                                                                  SHA1:67778FFE4326B1391C3CFE991B3C84C1E9ACA2D2
                                                                                                                                                                                                                                  SHA-256:AAFA26F7ED5733A2E45E77D67D7E4E521918CBDC19DAB5BA7774C60B9FDC203F
                                                                                                                                                                                                                                  SHA-512:B5A63E363CF9814C6E530840D9BB5A78C36493BAD54060781BACDF10DFA8C95988081DE3364E56D3FDFDBB5A6489E549D8CB1C0B5D1C57F53A1B1915B291A0D9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Volgograd) {. {-9223372036854775808 10660 0 LMT}. {-1577761060 10800 0 +03}. {-1247540400 14400 0 +04}. {-256881600 14400 0 +05}. {354916800 18000 1 +05}. {370724400 14400 0 +04}. {386452800 18000 1 +05}. {402260400 14400 0 +04}. {417988800 18000 1 +05}. {433796400 14400 0 +04}. {449611200 18000 1 +05}. {465343200 14400 0 +04}. {481068000 18000 1 +05}. {496792800 14400 0 +04}. {512517600 18000 1 +05}. {528242400 14400 0 +04}. {543967200 18000 1 +05}. {559692000 14400 0 +04}. {575416800 10800 0 +04}. {575420400 14400 1 +04}. {591145200 10800 0 +03}. {606870000 14400 1 +04}. {622594800 10800 0 +03}. {638319600 14400 1 +04}. {654649200 10800 0 +03}. {670374000 14400 0 +04}. {701820000 10800 0 +04}. {701823600 14400 1 +04}. {717548400 10800 0 +03}. {733273200 14400 1 +04}. {748998000 10800 0 +03}. {764722800 14400 1 +04}. {780447
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8366
                                                                                                                                                                                                                                  Entropy (8bit):3.731361496484662
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:uOZMLerhW4v4Qzh3VEbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0c:uArhW4v4yENH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:5F72F26A78BECD6702560DE8C7CCB850
                                                                                                                                                                                                                                  SHA1:A14E10DCC128B88B3E9C5D2A86DAC7D254CEB123
                                                                                                                                                                                                                                  SHA-256:054C1CDABAD91C624A4007D7594C30BE96906D5F29B54C292E0B721F8CB03830
                                                                                                                                                                                                                                  SHA-512:564A575EA2FBDB1D262CF55D55BEFC0BF6EF2081D88DE25712B742F5800D2FBE155EDEF0303F62D497BA0E849174F235D8599E09E1C997789E24FE5583F4B0FC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Warsaw) {. {-9223372036854775808 5040 0 LMT}. {-2840145840 5040 0 WMT}. {-1717032240 3600 0 CET}. {-1693706400 7200 1 CEST}. {-1680483600 3600 0 CET}. {-1663455600 7200 1 CEST}. {-1650150000 3600 0 CET}. {-1632006000 7200 1 CEST}. {-1618696800 7200 0 EET}. {-1600473600 10800 1 EEST}. {-1587168000 7200 0 EET}. {-931734000 7200 0 CEST}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-812502000 7200 1 CEST}. {-796870800 7200 0 CEST}. {-796608000 3600 0 CET}. {-778726800 7200 1 CEST}. {-762660000 3600 0 CET}. {-748486800 7200 1 CEST}. {-733273200 3600 0 CET}. {-715215600 7200 1 CEST}. {-701910000 3600 0 CET}. {-684975600 7200 1 CEST}. {-670460400 3600 0 CET}. {-654130800 7200 1 CEST}. {-639010800 3600 0 CET}. {-397094400 7200 1 CEST}. {-386812800 3600 0 CET}. {-371088000 7200 1 CEST}. {-355363200 3600 0
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):182
                                                                                                                                                                                                                                  Entropy (8bit):4.851218990240677
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV/sUE2tvFVAIgoq8sUE2vqLyQa5rXv1/h8QahsUE2u:SlSWB9IZaM3ymhrE2tvFVAIgohrE2vqK
                                                                                                                                                                                                                                  MD5:445F589A26E47F9D7BDF1A403A96108E
                                                                                                                                                                                                                                  SHA1:B119D93796DA7C793F9ED8C5BB8BB65C8DDBFC81
                                                                                                                                                                                                                                  SHA-256:6E3ED84BC34D90950D267230661C2EC3C32BA190BD57DDC255F4BE901678B208
                                                                                                                                                                                                                                  SHA-512:F45AF9AC0AF800FDCC74DBED1BDFA106A6A58A15308B5B62B4CB6B091FCFD321F156618BE2C157A1A6CAFAAAC399E4C6B590AF7CE7176F757403B55F09842FD2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Belgrade)]} {. LoadTimeZoneFile Europe/Belgrade.}.set TZData(:Europe/Zagreb) $TZData(:Europe/Belgrade).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7238
                                                                                                                                                                                                                                  Entropy (8bit):3.6787190163584103
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:Tnh2yurpr2nVaKl9sUM2kNU4tztagAwkY5V778e27zo2yiQ6kjmyykeP2lwtOEZ2:T1Gt2ch2kNU4tB715pyzHy1gA
                                                                                                                                                                                                                                  MD5:4AC1F6AB26F3869C757247346BCB72B5
                                                                                                                                                                                                                                  SHA1:CB0880906DC630F3C2B934998853CD05AAA1FE39
                                                                                                                                                                                                                                  SHA-256:3E9F843F5C6DDBE8E6431BE28ACB95507DDDCA6C521E2FD3355A103BF38F3CB7
                                                                                                                                                                                                                                  SHA-512:C4A3AB7B5BA3BC371285654159CB1767ECD52DEDAA61BF69586F6ED61F9F1E877796C28438FF582962C12780484214B5EA670654C87240E01EDD2A4B271EDEEF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Zaporozhye) {. {-9223372036854775808 8440 0 LMT}. {-2840149240 8400 0 +0220}. {-1441160400 7200 0 EET}. {-1247536800 10800 0 MSK}. {-894769200 3600 0 CET}. {-857257200 3600 0 CET}. {-844556400 7200 1 CEST}. {-828226800 3600 0 CET}. {-826419600 10800 0 MSD}. {354920400 14400 1 MSD}. {370728000 10800 0 MSK}. {386456400 14400 1 MSD}. {402264000 10800 0 MSK}. {417992400 14400 1 MSD}. {433800000 10800 0 MSK}. {449614800 14400 1 MSD}. {465346800 10800 0 MSK}. {481071600 14400 1 MSD}. {496796400 10800 0 MSK}. {512521200 14400 1 MSD}. {528246000 10800 0 MSK}. {543970800 14400 1 MSD}. {559695600 10800 0 MSK}. {575420400 14400 1 MSD}. {591145200 10800 0 MSK}. {606870000 14400 1 MSD}. {622594800 10800 0 MSK}. {638319600 14400 1 MSD}. {654649200 10800 0 MSK}. {670374000 10800 0 EEST}. {686091600 7200 0 EET}. {701820000 10800 1 EEST}. {71
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7055
                                                                                                                                                                                                                                  Entropy (8bit):3.732572949993817
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:k7tmcRbjOP9/V+H4Mnb4Nkrloy4xBqffZRgKs0AzxAHTdIVaAq0VZQltUbAyzF76:kbRNH4Mn82rlo6XIZ9ALeBO
                                                                                                                                                                                                                                  MD5:D9A3FAE7D9B5C9681D7A98BFACB6F57A
                                                                                                                                                                                                                                  SHA1:11268DFEE6D2472B3D8615ED6D70B361521854A2
                                                                                                                                                                                                                                  SHA-256:C920B4B7C160D8CEB8A08E33E5727B14ECD347509CABB1D6CDC344843ACF009A
                                                                                                                                                                                                                                  SHA-512:7709778B82155FBF35151F9D436F3174C057EBF7927C48F841B1D8AF008EEA9BC181D862A57C436EC69A528FB8B9854D9E974FC9EEC4FFDFE983299102BCDFB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Europe/Zurich) {. {-9223372036854775808 2048 0 LMT}. {-3675198848 1786 0 BMT}. {-2385246586 3600 0 CET}. {-904435200 7200 1 CEST}. {-891129600 3600 0 CET}. {-872985600 7200 1 CEST}. {-859680000 3600 0 CET}. {347151600 3600 0 CET}. {354675600 7200 1 CEST}. {370400400 3600 0 CET}. {386125200 7200 1 CEST}. {401850000 3600 0 CET}. {417574800 7200 1 CEST}. {433299600 3600 0 CET}. {449024400 7200 1 CEST}. {465354000 3600 0 CET}. {481078800 7200 1 CEST}. {496803600 3600 0 CET}. {512528400 7200 1 CEST}. {528253200 3600 0 CET}. {543978000 7200 1 CEST}. {559702800 3600 0 CET}. {575427600 7200 1 CEST}. {591152400 3600 0 CET}. {606877200 7200 1 CEST}. {622602000 3600 0 CET}. {638326800 7200 1 CEST}. {654656400 3600 0 CET}. {670381200 7200 1 CEST}. {686106000 3600 0 CET}. {701830800 7200 1 CEST}. {717555600 3600 0 CET}. {733280400 7200 1 CEST}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):165
                                                                                                                                                                                                                                  Entropy (8bit):4.848987525932415
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVxKL82wFVAIgoqyKL8p6wox6QavKL8i:SlSWB9IZaM3ymvKA2wFVAIgovKAUwR1O
                                                                                                                                                                                                                                  MD5:2639233BCD0119FD601F55F2B6279443
                                                                                                                                                                                                                                  SHA1:AADF9931DF78F5BC16ED4638947E77AE52E80CA1
                                                                                                                                                                                                                                  SHA-256:846E203E4B40EA7DC1CB8633BF950A8173D7AA8073C186588CC086BC7C4A2BEE
                                                                                                                                                                                                                                  SHA-512:8F571F2BBE4C60E240C4EBBB81D410786D1CB8AD0761A99ABB61DDB0811ACC92DCC2F765A7962B5C560B86732286356357D3F408CAC32AC1B2C1F8EAD4AEAEA6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/London)]} {. LoadTimeZoneFile Europe/London.}.set TZData(:GB) $TZData(:Europe/London).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):170
                                                                                                                                                                                                                                  Entropy (8bit):4.860435123210029
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVxKL82wFVAIgoqyKL8p6w4b/h8QavKL8i:SlSWB9IZaM3ymvKA2wFVAIgovKAUw4bx
                                                                                                                                                                                                                                  MD5:51335479044A047F5597F0F06975B839
                                                                                                                                                                                                                                  SHA1:234CD9635E61E7D429C70E886FF9C9F707FEAF1F
                                                                                                                                                                                                                                  SHA-256:FAC3B11B1F4DA9D68CCC193526C4E369E3FAA74F95C8BEE8BB9FAE014ACD5900
                                                                                                                                                                                                                                  SHA-512:4E37EFDFBAFA5C517BE86195373D083FF4370C5031B35A735E3225E7B17A75899FAFFBDF0C8BCFCBC5DC2D037EE9465AD3ED7C0FA55992027DFD69618DC9918F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/London)]} {. LoadTimeZoneFile Europe/London.}.set TZData(:GB-Eire) $TZData(:Europe/London).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):148
                                                                                                                                                                                                                                  Entropy (8bit):4.817383285510599
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtwZ8RDMvn:SlSWB9IZaM3yF4FVAIgJtwZ8RQvn
                                                                                                                                                                                                                                  MD5:D19DC8277A68AA289A361D28A619E0B0
                                                                                                                                                                                                                                  SHA1:27F5F30CC2603E1BCB6270AF84E9512DADEEB055
                                                                                                                                                                                                                                  SHA-256:5B90891127A65F7F3C94B44AA0204BD3F488F21326E098B197FB357C51845B66
                                                                                                                                                                                                                                  SHA-512:B5DD9C2D55BDB5909A29FD386CF107B83F56CD9B9F979A5D3854B4112B7F8950F4E91FB86AF6556DCF583EE469470810F3F8FB6CCF04FDBD6625A4346D3CD728
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:GMT) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):150
                                                                                                                                                                                                                                  Entropy (8bit):4.868642878112439
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtwe7/8RDMvn:SlSWB9IZaM3yF4FVAIgJtwI8RQvn
                                                                                                                                                                                                                                  MD5:B5065CD8B1CB665DACDB501797AF5104
                                                                                                                                                                                                                                  SHA1:0DB4E9AC6E38632302D9689A0A39632C2592F5C7
                                                                                                                                                                                                                                  SHA-256:6FC1D3C727CD9386A11CAF4983A2FC06A22812FDC7752FBFA7A5252F92BB0E70
                                                                                                                                                                                                                                  SHA-512:BBA1793CA3BBC768EC441210748098140AE820910036352F5784DD8B2DABA8303BA2E266CB923B500E8F90494D426E8BF115ACD0C000CD0C65896CE7A6AD9D66
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:GMT+0) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):150
                                                                                                                                                                                                                                  Entropy (8bit):4.8553095447791055
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtw4Hp8RDMvn:SlSWB9IZaM3yF4FVAIgJtw4J8RQvn
                                                                                                                                                                                                                                  MD5:E71CDE5E33573E78E01F4B7AB19F5728
                                                                                                                                                                                                                                  SHA1:C296752C449ED90AE20F5AEC3DC1D8F329C2274F
                                                                                                                                                                                                                                  SHA-256:78C5044C723D21375A1154AE301F29D13698C82B3702042C8B8D1EFF20954078
                                                                                                                                                                                                                                  SHA-512:6EBB39EF85DA70833F8B6CCD269346DC015743BC049F6F1B385625C5498F4E953A0CEDE76C60314EE671FE0F6EEB56392D62E0128F5B04BC68681F71718FE2BB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:GMT-0) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):149
                                                                                                                                                                                                                                  Entropy (8bit):4.843152601955343
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtwPHp8RDMvn:SlSWB9IZaM3yF4FVAIgJtwvp8RQvn
                                                                                                                                                                                                                                  MD5:FE666CDF1E9AA110A7A0AE699A708927
                                                                                                                                                                                                                                  SHA1:0E7FCDA9B47BC1D5F4E0DFAD8A9E7B73D71DC9E3
                                                                                                                                                                                                                                  SHA-256:0A883AFE54FAE0ED7D6535BDAB8A767488A491E6F6D3B7813CF76BB32FED4382
                                                                                                                                                                                                                                  SHA-512:763591A47057D67E47906AD22270D589100A7380B6F9EAA9AFD9D6D1EE254BCB1471FEC43531C4196765B15F2E27AF9AAB5A688D1C88B45FE7EEA67B6371466E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:GMT0) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):154
                                                                                                                                                                                                                                  Entropy (8bit):4.869510201987464
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqSsM4DvFVAIgexvqtwE+FB5yRDMvn:SlSWB9IZaM3yF4FVAIgJtwE6BURQvn
                                                                                                                                                                                                                                  MD5:F989F3DB0290B2126DA85D78B74E2061
                                                                                                                                                                                                                                  SHA1:43A0A1737E1E3EF0501BB65C1E96CE4D0B5635FC
                                                                                                                                                                                                                                  SHA-256:41A45FCB805DB6054CD1A4C7A5CFBF82668B3B1D0E44A6F54DFB819E4C71F68A
                                                                                                                                                                                                                                  SHA-512:3EDB8D901E04798B566E6D7D72841C842803AE761BEF3DEF37B8CA481E79915A803F61360FA2F317D7BDCD913AF8F5BB14F404E80CFA4A34E4310055C1DF39F2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/GMT)]} {. LoadTimeZoneFile Etc/GMT.}.set TZData(:Greenwich) $TZData(:Etc/GMT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):106
                                                                                                                                                                                                                                  Entropy (8bit):4.860812879108152
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5/Lm/kXGm2OH1V9i:SlSWB9X5jmTm2OH1V8
                                                                                                                                                                                                                                  MD5:3D99F2C6DADF5EEEA4965A04EB17B1BB
                                                                                                                                                                                                                                  SHA1:8DF607A911ADF6A9DD67D786FC9198262F580312
                                                                                                                                                                                                                                  SHA-256:2C83D64139BFB1115DA3F891C26DD53B86436771A30FB4DD7C8164B1C0D5BCDE
                                                                                                                                                                                                                                  SHA-512:EDA863F3A85268BA7A8606E3DCB4D7C88B0681AD8C4CFA1249A22B184F83BFDE9855DD4E5CFC3A4692220E5BEFBF99ED10E13BD98DBCA37D6F29A10AB660EBE2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:HST) {. {-9223372036854775808 -36000 0 HST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.865313867650324
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8LizFVAIgN2qPJL/XF1p4WFKQ1n:SlSWB9IZaM3yWzFVAIgAML//p4wKi
                                                                                                                                                                                                                                  MD5:D828C0668A439FEB9779589A646793F8
                                                                                                                                                                                                                                  SHA1:1509415B72E2155725FB09615B3E0276F3A46E87
                                                                                                                                                                                                                                  SHA-256:CF8BFEC73D36026955FA6F020F42B6360A64ED870A88C575A5AA0CD9756EF51B
                                                                                                                                                                                                                                  SHA-512:0F864B284E48B993DD13296AF05AEB14EBE26AF32832058C1FC32FCCE78E85925A25D980052834035D37935FAAF1CB0A9579AECBE6ADCDB2791A134D88204EBF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Hong_Kong)]} {. LoadTimeZoneFile Asia/Hong_Kong.}.set TZData(:Hongkong) $TZData(:Asia/Hong_Kong).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.840758003302018
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqLGsA/8rtdVAIgvMGsA/8rN6+GAKyx/2RQqGsA/8ru:SlSWB9IZaM3yj6dVAIgv1b+XZx+RQj7
                                                                                                                                                                                                                                  MD5:18DEAAAC045B4F103F2D795E0BA77B00
                                                                                                                                                                                                                                  SHA1:F3B3FE5029355173CD5BA626E075BA73F3AC1DC6
                                                                                                                                                                                                                                  SHA-256:9BB28A38329767A22CD073DF34E46D0AA202172A4116FBF008DDF802E60B743B
                                                                                                                                                                                                                                  SHA-512:18140274318E913F0650D21107B74C07779B832C9906F1A2E98433B96AAEADF70D07044EB420A2132A6833EF7C3887B8927CFD40D272A13E69C74A63904F43C9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Atlantic/Reykjavik)]} {. LoadTimeZoneFile Atlantic/Reykjavik.}.set TZData(:Iceland) $TZData(:Atlantic/Reykjavik).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.75703014401897
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt+L6EL/liEi2eDcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL+LzM2eDkr
                                                                                                                                                                                                                                  MD5:1E84F531F7992BFBD53B87831FE349E9
                                                                                                                                                                                                                                  SHA1:E46777885945B7C151C6D46C8F7292FC332A5576
                                                                                                                                                                                                                                  SHA-256:F4BDCAE4336D22F7844BBCA933795063FA1BCA9EB228C7A4D8222BB07A706427
                                                                                                                                                                                                                                  SHA-512:545D6DEB94B7A13D69F387FE758C9FC474DC02703F2D485FD42539D3CE03975CDEEFB985E4AA7742957952AF9E9F1E2DB84389277C3864C32C31D890BD399FB9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Indian/Antananarivo) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.802684724729281
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5+L6EL9WJxwFFkXGm2OHi/FvvUcfJ7XH0VQGFr6VVFSTL:SlSWB9X5+LxWJxwFJm2OHqFvd+VQSr6e
                                                                                                                                                                                                                                  MD5:4618C8D4F26C02A3A303DD1FB5DCFE46
                                                                                                                                                                                                                                  SHA1:857D376F5AFE75784E7F578C83E111B2EE18F74E
                                                                                                                                                                                                                                  SHA-256:94262B5A1E3423CD26BFFB3E36F63C1A6880304D00EE5B05985072D82032C765
                                                                                                                                                                                                                                  SHA-512:3F5CDDE3D2D5C8BC3DD6423888D7DB6A8EA3D4881ABE9E3857B9D0DDF756D0ECD9CAB7EF66343B0636D32E5CCF0ECEC1F56B9F4BC521CD24B3DB1D935F994AF0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Chagos) {. {-9223372036854775808 17380 0 LMT}. {-1988167780 18000 0 +05}. {820436400 21600 0 +06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):148
                                                                                                                                                                                                                                  Entropy (8bit):4.911693487750565
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5+L6EL9FBIEW3v/kXGm2OHAWMx5vXTLyvMVSYvC:SlSWB9X5+LxpW3vTm2OHAnx5PTIMVSYK
                                                                                                                                                                                                                                  MD5:5026A59BD9CCD6ABA665B4895EDB0171
                                                                                                                                                                                                                                  SHA1:8361778F615EFDDAA660E49545249005B6FC66C3
                                                                                                                                                                                                                                  SHA-256:37E1DAD2B019CCD6F8927602B079AD6DB7D71F55CBDA165B0A3EEF580B86DACF
                                                                                                                                                                                                                                  SHA-512:E081BDE3FC0D07E75C83C308A662C3A1837A387137BFA8D8E4A59797159F465654BAFFCE6B1458602255BD784CEE0BF70F542C3E893BC87A566630D54084CDCC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Christmas) {. {-9223372036854775808 25372 0 LMT}. {-2364102172 25200 0 +07}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):146
                                                                                                                                                                                                                                  Entropy (8bit):4.811431467315532
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5+L6EL9d/FkXGm2OHGXTvxoevXmVUXxXW5d6TW8C:SlSWB9X5+LxpJm2OHGXCeP3BG5Uq
                                                                                                                                                                                                                                  MD5:4C9502EC642E813E7B699281DD9809DF
                                                                                                                                                                                                                                  SHA1:98804A95F13CF4EED983AC019CD1A9EFC01AF719
                                                                                                                                                                                                                                  SHA-256:E8C591860DD42374C64E30850A3626017989CF16DDB85FDCC111AD92BD311425
                                                                                                                                                                                                                                  SHA-512:8BD7718055789FA7CFB2D50270C563E4D69E16283745701B07073A1CDA271F95B1884F297C2F22CB36EC9983BC759F03B05B39DFD0604CD3278DBCBFB6E12CA6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Cocos) {. {-9223372036854775808 23260 0 LMT}. {-2209012060 23400 0 +0630}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.775639640601132
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt+L6EL9TKlBx+DcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL+LxGV+Dkr
                                                                                                                                                                                                                                  MD5:DAD21C1CD103E6FF24ECB26ECC6CC783
                                                                                                                                                                                                                                  SHA1:FBCCCF55EDFC882B6CB003E66B0B7E52A3E0EFDE
                                                                                                                                                                                                                                  SHA-256:DA2F64ADC2674BE934C13992652F285927D8A44504327950678AD3B3EC285DCE
                                                                                                                                                                                                                                  SHA-512:EA3B155D39D34AFB789F486FAA5F2B327ADB62E43FE5757D353810F9287D9E706773A034D3B2E5F050CCC2A24B31F28A8C44109CCCF43509F2B8547D107FD4A4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Indian/Comoro) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):143
                                                                                                                                                                                                                                  Entropy (8bit):4.822244827214297
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5+L6EL12hJFkXGm2OHvdFFr9vM0VQL:SlSWB9X5+L5Mm2OHlFFr1nVQL
                                                                                                                                                                                                                                  MD5:5223EC10BCFBC18A9FA392340530E164
                                                                                                                                                                                                                                  SHA1:A59B4F19A3F052B2A3EB57E0D2652E81FB665B50
                                                                                                                                                                                                                                  SHA-256:17750D6A9B8ED41809D8DC976777A5252CCB70F39C3BF396B55557A8E504CB09
                                                                                                                                                                                                                                  SHA-512:2B2EFC470FE4461F82B1F1909C2A953934938D5DC8B54B2DA3A48678CF23ECD7874187E0FA4F6241FC02AEE0AF29B861C3FEEC15BB90E5C7D3A609DBB50EDC2C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Kerguelen) {. {-9223372036854775808 0 0 -00}. {-631152000 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):143
                                                                                                                                                                                                                                  Entropy (8bit):4.873998321422911
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5+L6ELzJMyFkXGm2OHuVdF+YvXTW1U9VsRYvC:SlSWB9X5+L/TJm2OHWgYPhSQC
                                                                                                                                                                                                                                  MD5:F8D00BD4AD23557FB4FC8EB095842C26
                                                                                                                                                                                                                                  SHA1:AD4AE41D0AD49E80FCF8CADE6889459EA30B57F7
                                                                                                                                                                                                                                  SHA-256:997C33DBCEA54DE671A4C4E0E6F931623BF4F39A821F9F15075B9ECCCCA3F1B8
                                                                                                                                                                                                                                  SHA-512:F67D348ECCCA244681EE7B70F7815593CFB2D7D4502832B2EB653EBF01AC66ACED29F7EA2E223D295C4D4F64287D372070EF863CCB201ACD8DF470330812013D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Mahe) {. {-9223372036854775808 13308 0 LMT}. {-2006653308 14400 0 +04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.833774224054436
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5+L6ELzEyFkXGm2OHnz8evXZT5lxGYUQwGN0VQL:SlSWB9X5+L/EyJm2OHnz8ePZT5rG5QwI
                                                                                                                                                                                                                                  MD5:EC0C456538BE81FA83AF440948EED55E
                                                                                                                                                                                                                                  SHA1:11D7BA32A38547AF88F4182B6C1C3373AD89D75C
                                                                                                                                                                                                                                  SHA-256:18A4B14CD05E4B25431BAF7BFCF2049491BF4E36BB31846D7F18F186C9ECD019
                                                                                                                                                                                                                                  SHA-512:FF57F9EDFAD16E32B6A0BA656C5949A0A664D22001D5149BF036C322AEC1682E8B523C8E64E5A49B7EFA535A13459234C16237C09FC5B40F08AC22D56681C4BE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Maldives) {. {-9223372036854775808 17640 0 LMT}. {-2840158440 17640 0 MMT}. {-315636840 18000 0 +05}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):262
                                                                                                                                                                                                                                  Entropy (8bit):4.450791926516311
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5+L/Hm2OHlNndSvulvSQFFYc0FZFeVhvSQFFbBjvVFZFbGlvSQC:MBp5+L/HmdHlNnS6jz0F7KZjbBjVF7bd
                                                                                                                                                                                                                                  MD5:040680E086764FC47EEBE039358E223C
                                                                                                                                                                                                                                  SHA1:4D10E6F69835533748DD5FD2E7409F9732221210
                                                                                                                                                                                                                                  SHA-256:C4054D56570F9362AB8FF7E4DBA7F8032720289AE01C03A861CCD8DEC9D2ABB2
                                                                                                                                                                                                                                  SHA-512:FC00B4AD7328EBC3025A482B3D6A0B176F3430BD3D06B918974EAC5BD30AD8551E0C6BE1DC03BE18A9BC6DD0919ED2A3717E20749ABECBFBD202764047D0D292
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Mauritius) {. {-9223372036854775808 13800 0 LMT}. {-1988164200 14400 0 +04}. {403041600 18000 1 +04}. {417034800 14400 0 +04}. {1224972000 18000 1 +04}. {1238274000 14400 0 +04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):180
                                                                                                                                                                                                                                  Entropy (8bit):4.778847657463255
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsVVMMvwVAIgNGExVMSt+L6ELzO1h4DcVVMMv:SlSWB9IZaM3y7VcVAIgNTxL+L/O1h4De
                                                                                                                                                                                                                                  MD5:D89C649468B3C22CF5FA659AE590DE53
                                                                                                                                                                                                                                  SHA1:83DF2C14F1E51F5B89DCF6B833E421389F9F23DC
                                                                                                                                                                                                                                  SHA-256:071D17F347B4EB9791F4929803167497822E899761654053BD774C5A899B4B9C
                                                                                                                                                                                                                                  SHA-512:68334E11AAB0F8DCEEB787429832A60F4F0169B6112B7F74048EACFDE78F9C4D100E1E2682D188C3965E41A83477D3AECC80B73A2A8A1A80A952E59B431576A8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Nairobi)]} {. LoadTimeZoneFile Africa/Nairobi.}.set TZData(:Indian/Mayotte) $TZData(:Africa/Nairobi).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):146
                                                                                                                                                                                                                                  Entropy (8bit):4.933616581218054
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5+L6ELsActFkXGm2OHuU7oevUdvcUeNVsRYvC:SlSWB9X5+Lam2OHb7oezfNSQC
                                                                                                                                                                                                                                  MD5:C50A592BB886F2FA48657900AE10789F
                                                                                                                                                                                                                                  SHA1:16D73BFFDAD18E751968E100BB391AABB29169E1
                                                                                                                                                                                                                                  SHA-256:3775EA8EBF5CBBD240E363FB62AEF8D2865A9D9969E40A15731DCC0AC03107EB
                                                                                                                                                                                                                                  SHA-512:F875F287E6C3A7B7325DB038CF419AA34FD0072FD3FCD138102008959F397026B647D8D339CB01362330905382FE7DCF5F8EC98C9B8C4FFF59A6FF4E78678BB7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Indian/Reunion) {. {-9223372036854775808 13312 0 LMT}. {-1848886912 14400 0 +04}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):161
                                                                                                                                                                                                                                  Entropy (8bit):4.757854680369306
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8g5YFevFVAIgNqjNAt+XiMr4WFKBun:SlSWB9IZaM3yA5owFVAIgcjSt+Xvr4wh
                                                                                                                                                                                                                                  MD5:848663FD5F685FE1E14C655A0ABA7D6A
                                                                                                                                                                                                                                  SHA1:59A1BEE5B3BE01FB9D2C73777B7B4F1615DCE034
                                                                                                                                                                                                                                  SHA-256:DB6D0019D3B0132EF8B8693B1AB2B325D77DE3DD371B1AFDAE4904BE610BA2A6
                                                                                                                                                                                                                                  SHA-512:B1F8C08AF68C919DB332E6063647AF15CB9FED4046C16BEF9A58203044E36A0D1E69BD1B8703B15003B929409A8D83238B5AA67B910B920F0674C8A0EB5CF125
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Tehran)]} {. LoadTimeZoneFile Asia/Tehran.}.set TZData(:Iran) $TZData(:Asia/Tehran).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):172
                                                                                                                                                                                                                                  Entropy (8bit):4.778464205793726
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq85zFFwVAIgN0AzFzt+WXnMr4WFKYzFp:SlSWB9IZaM3yZbwVAIgCAb+zr4wKY7
                                                                                                                                                                                                                                  MD5:B9D1F6BD0B0416791036C0E3402C8438
                                                                                                                                                                                                                                  SHA1:E1A7471062C181B359C06804420091966B809957
                                                                                                                                                                                                                                  SHA-256:E6EC28F69447C3D3DB2CB68A51EDCEF0F77FF4B563F7B65C9C71FF82771AA3E1
                                                                                                                                                                                                                                  SHA-512:A5981FD91F6A9A84F44A6C9A3CF247F9BE3AB52CE5FE8EE1A7BE19DD63D0B22818BC15287FE73A5EEC8BCE6022B9EAF54A10AA719ADF31114E188F31EA273E92
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Jerusalem)]} {. LoadTimeZoneFile Asia/Jerusalem.}.set TZData(:Israel) $TZData(:Asia/Jerusalem).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.668645988954937
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx00EIECpVAIg200EIEvvt9S//2IAcGE0EIEVn:SlSWB9IZaM3y7952VAIgp95vF029095V
                                                                                                                                                                                                                                  MD5:EA38E93941E21CB08AA49A023DCC06FB
                                                                                                                                                                                                                                  SHA1:1AD77CAC25DC6D1D04320FF2621DD8E7D227ECBF
                                                                                                                                                                                                                                  SHA-256:21908F008F08C55FB48F1C3D1A1B2016BDB10ED375060329451DE4E487CF0E5F
                                                                                                                                                                                                                                  SHA-512:D6F0684A757AD42B8010B80B4BE6542ADE96D140EC486B4B768E167502C776B8D289622FBC48BD19EB3D0B3BC4156715D5CCFC7952A479A990B07935B15D26DC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Jamaica)]} {. LoadTimeZoneFile America/Jamaica.}.set TZData(:Jamaica) $TZData(:America/Jamaica).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):159
                                                                                                                                                                                                                                  Entropy (8bit):4.791469556628492
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8aowVAIgNqaF9hM7/4WFK6n:SlSWB9IZaM3ypwVAIgcaF4r4wK6n
                                                                                                                                                                                                                                  MD5:338A18DEDF5A813466644B2AAE1A7CF5
                                                                                                                                                                                                                                  SHA1:BB76CE671853780F4971D2E173AE71E82EA24690
                                                                                                                                                                                                                                  SHA-256:535AF1A79CD01735C5D6FC6DB08C5B0EAFB8CF0BC89F7E943CF419CFA745CA26
                                                                                                                                                                                                                                  SHA-512:4D44CC28D2D0634200FEA0537EBC5DD50E639365B89413C6BF911DC2B95B78E27F1B92733FB859C794A8C027EA89E45E8C2D6E1504FF315AF68DB02526226AD2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Tokyo)]} {. LoadTimeZoneFile Asia/Tokyo.}.set TZData(:Japan) $TZData(:Asia/Tokyo).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.759848173726549
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG1/EOM2wFVAIgObT1/EOM8O68/FMKpUDH1/EOMi:SlSWB9IZaM3yc1EiwFVAIgOb1E48xME+
                                                                                                                                                                                                                                  MD5:A9C8CA410CA3BD4345BF6EAB53FAB97A
                                                                                                                                                                                                                                  SHA1:57AE7E6D3ED855B1FBF6ABF2C9846DFA9B3FFF47
                                                                                                                                                                                                                                  SHA-256:A63A99F0E92F474C4AA99293C4F4182336520597A86FCDD91DAE8B25AFC30B98
                                                                                                                                                                                                                                  SHA-512:C97CF1301DCEEE4DE26BCEEB60545BB70C083CD2D13ED89F868C7856B3532473421599ED9E7B166EA53A9CF44A03245192223D47BC1104CEBD1BF0AC6BF10898
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Kwajalein)]} {. LoadTimeZoneFile Pacific/Kwajalein.}.set TZData(:Kwajalein) $TZData(:Pacific/Kwajalein).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):171
                                                                                                                                                                                                                                  Entropy (8bit):4.779409803819657
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqsbKJqYkdVAIgNGEnKJuYvW67beDcbKJ9n:SlSWB9IZaM3y7JdVAIgNTnYvW6PeD9n
                                                                                                                                                                                                                                  MD5:C4739F7B58073CC7C72EF2D261C05C5E
                                                                                                                                                                                                                                  SHA1:12FE559CA2FEA3F8A6610B1D4F43E299C9FB7BA5
                                                                                                                                                                                                                                  SHA-256:28A94D9F1A60980F8026409A65F381EDB7E5926A79D07562D28199B6B63AF9B4
                                                                                                                                                                                                                                  SHA-512:B2DC5CB1AD7B6941F498FF3D5BD6538CAF0ED19A2908DE645190A5C5F40AF5B34752AE8A83E6C50D370EA619BA969C9AB7F797F171192200CDA1657FFFB7F05A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Africa/Tripoli)]} {. LoadTimeZoneFile Africa/Tripoli.}.set TZData(:Libya) $TZData(:Africa/Tripoli).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7471
                                                                                                                                                                                                                                  Entropy (8bit):3.7115445412724797
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:TJOwNDgaXSgm7VTslzZBYxWq9beN6db6yq3BgLjx1uuE0KRPGdNjClOQuonZ2ltb:bSV7xxWq9aYdbsC/eLdGLg9a
                                                                                                                                                                                                                                  MD5:2F62D867C8605730BC8E43D300040D54
                                                                                                                                                                                                                                  SHA1:06AD982DF03C7309AF01477749BAB9F7ED8935A7
                                                                                                                                                                                                                                  SHA-256:D6C70E46A68B82FFC7A4D96FDA925B0FAAF973CB5D3404A55DFF2464C3009173
                                                                                                                                                                                                                                  SHA-512:0D26D622511635337E5C03D82435A9B4A9BCA9530F940A70A24AE67EA4794429A5D68B59197B978818BEF0799C3D5FA792F5720965291661ED067570BC56226B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:MET) {. {-9223372036854775808 3600 0 MET}. {-1693706400 7200 1 MEST}. {-1680483600 3600 0 MET}. {-1663455600 7200 1 MEST}. {-1650150000 3600 0 MET}. {-1632006000 7200 1 MEST}. {-1618700400 3600 0 MET}. {-938905200 7200 1 MEST}. {-857257200 3600 0 MET}. {-844556400 7200 1 MEST}. {-828226800 3600 0 MET}. {-812502000 7200 1 MEST}. {-796777200 3600 0 MET}. {-781052400 7200 1 MEST}. {-766623600 3600 0 MET}. {228877200 7200 1 MEST}. {243997200 3600 0 MET}. {260326800 7200 1 MEST}. {276051600 3600 0 MET}. {291776400 7200 1 MEST}. {307501200 3600 0 MET}. {323830800 7200 1 MEST}. {338950800 3600 0 MET}. {354675600 7200 1 MEST}. {370400400 3600 0 MET}. {386125200 7200 1 MEST}. {401850000 3600 0 MET}. {417574800 7200 1 MEST}. {433299600 3600 0 MET}. {449024400 7200 1 MEST}. {465354000 3600 0 MET}. {481078800 7200 1 MEST}. {496803600 3600 0 MET
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):106
                                                                                                                                                                                                                                  Entropy (8bit):4.856431808856169
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx56xwkXGm2OHrXV4fvYv:SlSWB9X562m2OHrCi
                                                                                                                                                                                                                                  MD5:FF6BDAC2C77D8287B46E966480BFEACC
                                                                                                                                                                                                                                  SHA1:4C90F910C74E5262A27CC65C3433D34B5D885243
                                                                                                                                                                                                                                  SHA-256:FB6D9702FC9FB82779B4DA97592546043C2B7D068F187D0F79E23CB5FE76B5C2
                                                                                                                                                                                                                                  SHA-512:CA197B25B36DD47D86618A4D39BFFB91FEF939BC02EEB96679D7EA88E5D38737D3FE6BD4FD9D16C31CA5CF77D17DC31E5333F4E28AB777A165050EA5A4D106BA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:MST) {. {-9223372036854775808 -25200 0 MST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8227
                                                                                                                                                                                                                                  Entropy (8bit):3.755606924782105
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:xG5c2sGm+4I1zXN+C2mWBNQMsmNTxf6AeO+cblX:12dVUC2mWBNwWTxyWR
                                                                                                                                                                                                                                  MD5:2AB5643D8EF9FD9687A5C67AEB04AF98
                                                                                                                                                                                                                                  SHA1:2E8F1DE5C8113C530E5E6C10064DEA4AE949AAE6
                                                                                                                                                                                                                                  SHA-256:97028B43406B08939408CB1DD0A0C63C76C9A352AEA5F400CE6D4B8D3C68F500
                                                                                                                                                                                                                                  SHA-512:72A8863192E14A4BD2E05C508F8B376DD75BB4A3625058A97BBB33F7200B2012D92D445982679E0B7D11C978B80F7128B3A79B77938CEF6315AA6C4B1E0AC09C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:MST7MDT) {. {-9223372036854775808 -25200 0 MST}. {-1633273200 -21600 1 MDT}. {-1615132800 -25200 0 MST}. {-1601823600 -21600 1 MDT}. {-1583683200 -25200 0 MST}. {-880210800 -21600 1 MWT}. {-769395600 -21600 1 MPT}. {-765388800 -25200 0 MST}. {-84380400 -21600 1 MDT}. {-68659200 -25200 0 MST}. {-52930800 -21600 1 MDT}. {-37209600 -25200 0 MST}. {-21481200 -21600 1 MDT}. {-5760000 -25200 0 MST}. {9968400 -21600 1 MDT}. {25689600 -25200 0 MST}. {41418000 -21600 1 MDT}. {57744000 -25200 0 MST}. {73472400 -21600 1 MDT}. {89193600 -25200 0 MST}. {104922000 -21600 1 MDT}. {120643200 -25200 0 MST}. {126694800 -21600 1 MDT}. {152092800 -25200 0 MST}. {162378000 -21600 1 MDT}. {183542400 -25200 0 MST}. {199270800 -21600 1 MDT}. {215596800 -25200 0 MST}. {230720400 -21600 1 MDT}. {247046400 -25200 0 MST}. {262774800 -21600 1 MDT}. {278496000 -252
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):185
                                                                                                                                                                                                                                  Entropy (8bit):4.836487818373659
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0qfSwVAIg20qfo6AdMSKBbh4IAcGEqfu:SlSWB9IZaM3y7eHVAIgpeo68K5h490eu
                                                                                                                                                                                                                                  MD5:C3AEEA7B991B609A1CB253FDD5057D11
                                                                                                                                                                                                                                  SHA1:0212056C2A20DD899FA4A26B10C261AB19D20AA4
                                                                                                                                                                                                                                  SHA-256:599F79242382ED466925F61DD6CE59192628C7EAA0C5406D3AA98EC8A5162824
                                                                                                                                                                                                                                  SHA-512:38094FD29B1C31FC9D894B8F38909DD9ED3A76B2A27F6BC250ACD7C1EFF4529CD0B29B66CA7CCBEB0146DFF3FF0AC4AEEEC422F7A93422EF70BF723D12440A93
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Tijuana)]} {. LoadTimeZoneFile America/Tijuana.}.set TZData(:Mexico/BajaNorte) $TZData(:America/Tijuana).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):186
                                                                                                                                                                                                                                  Entropy (8bit):4.841665860441288
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0zjRJ+vFVAIg20zjRJZvt6AdMPCoQIAcGEzjRJ3:SlSWB9IZaM3y7zjRJQFVAIgpzjRJ1t6n
                                                                                                                                                                                                                                  MD5:89A5ED35215BA46C76BF2BD5ED620031
                                                                                                                                                                                                                                  SHA1:26F134644023A2D0DA4C8997C54E36C053AA1060
                                                                                                                                                                                                                                  SHA-256:D624945E20F30CCB0DB2162AD3129301E5281B8868FBC05ACA3AA8B6FA05A9DF
                                                                                                                                                                                                                                  SHA-512:C2563867E830F7F882E393080CE16A62A0CDC5841724E0D507CBA362DB8363BB75034986107C2428243680FE930BAC226E11FE6BA99C31E0C1A35D6DD1C14676
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Mazatlan)]} {. LoadTimeZoneFile America/Mazatlan.}.set TZData(:Mexico/BajaSur) $TZData(:America/Mazatlan).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):195
                                                                                                                                                                                                                                  Entropy (8bit):4.8300311016675606
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7zBDdVAIgpzBy6BXl490zBw:MBaIMYzipzU6Bi90zi
                                                                                                                                                                                                                                  MD5:E771850BA5A1C218EB1B31FDC564DF02
                                                                                                                                                                                                                                  SHA1:3675838740B837A96FF32694D1FA56DE01DE064F
                                                                                                                                                                                                                                  SHA-256:06A45F534B35538F32A77703C6523CE947D662D136C5EC105BD6616922AEEB44
                                                                                                                                                                                                                                  SHA-512:BD7AF307AD61C310EDAF01E618BE9C1C79239E0C8CDEC85792624A7CCE1B6251B0ADE066B8610AFDB0179F3EF474503890642284800B81E599CB830EC6C7C9AA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Mexico_City)]} {. LoadTimeZoneFile America/Mexico_City.}.set TZData(:Mexico/General) $TZData(:America/Mexico_City).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.8398862338201765
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG/u4pVAIgObT/NCxL5E1nUDH/uvn:SlSWB9IZaM3ycqIVAIgOboLivn
                                                                                                                                                                                                                                  MD5:7B274C782E9FE032AC4B3E137BF147BB
                                                                                                                                                                                                                                  SHA1:8469D17EC75D0580667171EFC9DE3FDF2C1E0968
                                                                                                                                                                                                                                  SHA-256:2228231C1BEF0173A639FBC4403B6E5BF835BF5918CC8C16757D915A392DBF75
                                                                                                                                                                                                                                  SHA-512:AE72C1F244D9457C70A120FD00F2C0FC2BDC467DBD5C203373291E00427499040E489F2B1358757EA281BA8143E28FB54D03EDE67970F74DACFCB308AC7F74CE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Auckland)]} {. LoadTimeZoneFile Pacific/Auckland.}.set TZData(:NZ) $TZData(:Pacific/Auckland).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.832832776993659
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG9WQ+DdVAIgObT9WQrF5AmtBFB/pUDH9WQpn:SlSWB9IZaM3ycwQ+DdVAIgObwQ5zzJjA
                                                                                                                                                                                                                                  MD5:C8D83C210169F458683BB35940E11DF6
                                                                                                                                                                                                                                  SHA1:278546F4E33AD5D0033AF6768EFAB0DE247DA74F
                                                                                                                                                                                                                                  SHA-256:CECF81746557F6F957FEF12DBD202151F614451F52D7F6A35C72B830075C478D
                                                                                                                                                                                                                                  SHA-512:4539AE6F7AF7579C3AA5AE4DEB97BD14ED83569702D3C4C3945DB06A2D8FFF260DA1DB21FF21B0BED91EE9C993833D471789B3A99C9A2986B7AC8ABFBBE5A8B7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Chatham)]} {. LoadTimeZoneFile Pacific/Chatham.}.set TZData(:NZ-CHAT) $TZData(:Pacific/Chatham).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):172
                                                                                                                                                                                                                                  Entropy (8bit):4.80475858956378
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx06RGFwVAIg206RAO0L5vf1+IAcGE6Ru:SlSWB9IZaM3y7+SwVAIgp+iLpd+90+u
                                                                                                                                                                                                                                  MD5:38C56298E75306F39D278F60B50711A6
                                                                                                                                                                                                                                  SHA1:8FD9CEAD17CCD7D981CEF4E782C3916BFEF2D11F
                                                                                                                                                                                                                                  SHA-256:E10B8574DD83C93D3C49E9E2226148CBA84538802316846E74DA6004F1D1534D
                                                                                                                                                                                                                                  SHA-512:F6AA67D78A167E553B97F092CC3791B591F800A6D286BE37C06F7ECABDFBCF43A397AEDC6E3EB9EB6A1CB95E8883D4D4F97890CA1877930AFCD5643B0C8548E9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Denver)]} {. LoadTimeZoneFile America/Denver.}.set TZData(:Navajo) $TZData(:America/Denver).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):166
                                                                                                                                                                                                                                  Entropy (8bit):4.854287452296565
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8qvwVAIgNtAnL75h4WFKdv:SlSWB9IZaM3yMwVAIgEH5h4wKt
                                                                                                                                                                                                                                  MD5:AF9DD8961DB652EE1E0495182D99820D
                                                                                                                                                                                                                                  SHA1:979602E3C59719A67DE3C05633242C12E0693C43
                                                                                                                                                                                                                                  SHA-256:9A6109D98B35518921E4923B50053E7DE9B007372C5E4FFF75654395D6B56A82
                                                                                                                                                                                                                                  SHA-512:F022C3EFABFC3B3D3152C345ACD28387FFEA4B61709CBD42B2F3684D33BED469C4C25F2328E5E7D9D74D968E25A0419E7BCFF0EB55650922906B9D3FF57B06C8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Shanghai)]} {. LoadTimeZoneFile Asia/Shanghai.}.set TZData(:PRC) $TZData(:Asia/Shanghai).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8227
                                                                                                                                                                                                                                  Entropy (8bit):3.751820462019181
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:9d89jJC2ZCHtffWsBNwj/lpmlOxGcKcnRH31t+ucgge:49jgNf+aNwj/lpmlOxnKcndIG
                                                                                                                                                                                                                                  MD5:DB5250A28A3853951AF00231677AACAC
                                                                                                                                                                                                                                  SHA1:1FC1DA1121B9F5557D246396917205B97F6BC295
                                                                                                                                                                                                                                  SHA-256:4DFC264F4564957F333C0208DA52DF03301D2FD07943F53D8B51ECCDD1CB8153
                                                                                                                                                                                                                                  SHA-512:72594A17B1E29895A6B4FC636AAE1AB28523C9C8D50118FA5A7FDFD3944AD3B742B17B260A69B44756F4BA1671268DD3E8223EF314FF7850AFB81202BA2BBF44
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:PST8PDT) {. {-9223372036854775808 -28800 0 PST}. {-1633269600 -25200 1 PDT}. {-1615129200 -28800 0 PST}. {-1601820000 -25200 1 PDT}. {-1583679600 -28800 0 PST}. {-880207200 -25200 1 PWT}. {-769395600 -25200 1 PPT}. {-765385200 -28800 0 PST}. {-84376800 -25200 1 PDT}. {-68655600 -28800 0 PST}. {-52927200 -25200 1 PDT}. {-37206000 -28800 0 PST}. {-21477600 -25200 1 PDT}. {-5756400 -28800 0 PST}. {9972000 -25200 1 PDT}. {25693200 -28800 0 PST}. {41421600 -25200 1 PDT}. {57747600 -28800 0 PST}. {73476000 -25200 1 PDT}. {89197200 -28800 0 PST}. {104925600 -25200 1 PDT}. {120646800 -28800 0 PST}. {126698400 -25200 1 PDT}. {152096400 -28800 0 PST}. {162381600 -25200 1 PDT}. {183546000 -28800 0 PST}. {199274400 -25200 1 PDT}. {215600400 -28800 0 PST}. {230724000 -25200 1 PDT}. {247050000 -28800 0 PST}. {262778400 -25200 1 PDT}. {278499600 -288
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5431
                                                                                                                                                                                                                                  Entropy (8bit):3.5627170055641306
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:2DBgcGFG9qbhX7zHJ4uoyM/15WNQ+NyVy:2DBgcGFGkXxaD/CR
                                                                                                                                                                                                                                  MD5:6718CD07DCEBD2CA85FC1764BE45E46C
                                                                                                                                                                                                                                  SHA1:0BCD2E4267F2BDB499EA613C17B9C38CCFC2177A
                                                                                                                                                                                                                                  SHA-256:5D3D1B4180482099119383DC160520DCDA5D4E3EEC87F22EA20B7D4B599F5249
                                                                                                                                                                                                                                  SHA-512:95C16BC92B9B3C80F9FA10F5B49DAEB472D45C2489A455A31177A8679E21EF668F85450E1770CFB77CA43477B68EF11B3A4090C11CE6F7FA518040EA7B502855
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Apia) {. {-9223372036854775808 45184 0 LMT}. {-2445424384 -41216 0 LMT}. {-1861878784 -41400 0 -1130}. {-631110600 -39600 0 -11}. {1285498800 -36000 1 -11}. {1301752800 -39600 0 -11}. {1316872800 -36000 1 -11}. {1325239200 50400 0 +13}. {1333202400 46800 0 +13}. {1348927200 50400 1 +13}. {1365256800 46800 0 +13}. {1380376800 50400 1 +13}. {1396706400 46800 0 +13}. {1411826400 50400 1 +13}. {1428156000 46800 0 +13}. {1443276000 50400 1 +13}. {1459605600 46800 0 +13}. {1474725600 50400 1 +13}. {1491055200 46800 0 +13}. {1506175200 50400 1 +13}. {1522504800 46800 0 +13}. {1538229600 50400 1 +13}. {1554559200 46800 0 +13}. {1569679200 50400 1 +13}. {1586008800 46800 0 +13}. {1601128800 50400 1 +13}. {1617458400 46800 0 +13}. {1632578400 50400 1 +13}. {1648908000 46800 0 +13}. {1664028000 50400 1 +13}. {1680357600 46800 0 +13}. {169
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8487
                                                                                                                                                                                                                                  Entropy (8bit):3.8173754903771018
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:WNj7nBIc0fw4eJ7a1N1oKe13aNiWbF8sYBpYhuVn:Cmc3J7a1N18QOs8
                                                                                                                                                                                                                                  MD5:6C008D6437C7490EE498605B5B096FDB
                                                                                                                                                                                                                                  SHA1:D7F6E7B3920C54EFE02A44883DBCD0A75C7FC46A
                                                                                                                                                                                                                                  SHA-256:B5BD438B748BA911E0E1201A83B623BE3F8130951C1377D278A7E7BC9CB7F672
                                                                                                                                                                                                                                  SHA-512:DA6992D257B1BA6124E39F90DDEE17DC3E2F3B38C3A68B77A93065E3E5873D28B8AE5D21CEC223BAADFBDD1B3A735BF1CEC1BDEB0C4BEAB72AAA23433A707207
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Auckland) {. {-9223372036854775808 41944 0 LMT}. {-3192435544 41400 0 NZMT}. {-1330335000 45000 1 NZST}. {-1320057000 41400 0 NZMT}. {-1300699800 43200 1 NZST}. {-1287396000 41400 0 NZMT}. {-1269250200 43200 1 NZST}. {-1255946400 41400 0 NZMT}. {-1237800600 43200 1 NZST}. {-1224496800 41400 0 NZMT}. {-1206351000 43200 1 NZST}. {-1192442400 41400 0 NZMT}. {-1174901400 43200 1 NZST}. {-1160992800 41400 0 NZMT}. {-1143451800 43200 1 NZST}. {-1125914400 41400 0 NZMT}. {-1112607000 43200 1 NZST}. {-1094464800 41400 0 NZMT}. {-1081157400 43200 1 NZST}. {-1063015200 41400 0 NZMT}. {-1049707800 43200 1 NZST}. {-1031565600 41400 0 NZMT}. {-1018258200 43200 1 NZST}. {-1000116000 41400 0 NZMT}. {-986808600 43200 1 NZST}. {-968061600 41400 0 NZMT}. {-955359000 43200 1 NZST}. {-936612000 41400 0 NZMT}. {-923304600 43200 1 NZST}. {-757425600 43200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):270
                                                                                                                                                                                                                                  Entropy (8bit):4.659789664861683
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5Ftgm2OHHhp5PZiuoDZDVeXU8vScCv/yZEiIv:MBp5FtgmdHf5PZiDZJek8HCvK6iIv
                                                                                                                                                                                                                                  MD5:A85F8A9502E818ADE7759166B9C7A9AD
                                                                                                                                                                                                                                  SHA1:5E706E5491AFE1A8399D7815158924381A1F6D27
                                                                                                                                                                                                                                  SHA-256:C910696B4CC7CA3E713EE08A024D26C1E4E4003058DECD5B54B92A0B2F8A17E0
                                                                                                                                                                                                                                  SHA-512:682BDC7DA0C9BFFD98992973295E180FB3FAACEA514760211B5291AEE26CABF200B68CA0EA80D9083C52F32C2EE3D0A5E84141363D1784C2A6A9FD24C2CF38E9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Bougainville) {. {-9223372036854775808 37336 0 LMT}. {-2840178136 35312 0 PMMT}. {-2366790512 36000 0 +10}. {-868010400 32400 0 +09}. {-768906000 36000 0 +10}. {1419696000 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7907
                                                                                                                                                                                                                                  Entropy (8bit):3.5670394561999235
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:1zwIBIWUkebw49ikidrGlb0D6DALquK8KfStVt:1jIbw49ikiAcWuB
                                                                                                                                                                                                                                  MD5:5DF25A6A6E7322528FE41B6FD5FE5119
                                                                                                                                                                                                                                  SHA1:E84915BA27443F01243050D648DF6388A1E8EDBA
                                                                                                                                                                                                                                  SHA-256:B6727010950418F6FC142658C74EE1D717E7FD2B46267FC215E53CA3D55E894E
                                                                                                                                                                                                                                  SHA-512:842ABE39AB26713D523A36895D7435DC2058846431CB2A0B7B47E204F8C315ADB855F95EC2852D57B73ECA0576CB1A49BB104C0D7BB9DE2E96143DA9C77F9A58
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Chatham) {. {-9223372036854775808 44028 0 LMT}. {-3192437628 44100 0 +1215}. {-757426500 45900 0 +1245}. {152632800 49500 1 +1245}. {162309600 45900 0 +1245}. {183477600 49500 1 +1245}. {194968800 45900 0 +1245}. {215532000 49500 1 +1245}. {226418400 45900 0 +1245}. {246981600 49500 1 +1245}. {257868000 45900 0 +1245}. {278431200 49500 1 +1245}. {289317600 45900 0 +1245}. {309880800 49500 1 +1245}. {320767200 45900 0 +1245}. {341330400 49500 1 +1245}. {352216800 45900 0 +1245}. {372780000 49500 1 +1245}. {384271200 45900 0 +1245}. {404834400 49500 1 +1245}. {415720800 45900 0 +1245}. {436284000 49500 1 +1245}. {447170400 45900 0 +1245}. {467733600 49500 1 +1245}. {478620000 45900 0 +1245}. {499183200 49500 1 +1245}. {510069600 45900 0 +1245}. {530632800 49500 1 +1245}. {541519200 45900 0 +1245}. {562082400 49500 1 +1245}. {5735736
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):145
                                                                                                                                                                                                                                  Entropy (8bit):4.989695428683993
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDH9CoFeEXGm2OHIOYvXmdcnWZUUJv:SlSWB9X5ZzLm2OHNYPmdcXQ
                                                                                                                                                                                                                                  MD5:61C075090B025E69800B23E0AD60459F
                                                                                                                                                                                                                                  SHA1:F847CA6D35BD4AF2C70B318D4EE4A2FB5C77D449
                                                                                                                                                                                                                                  SHA-256:3237743592D8719D0397FA278BB501E6F403985B643D1DE7E2DA91DD11BE215B
                                                                                                                                                                                                                                  SHA-512:5D07FB2FEAA9110D62CFD95BC729AA57F2A176C977D2E2C00374AF36EE84C4FB9416ECBEF179298928AAE9634B69C5FE889C5C9D2DFF290CAC0F6E53EDEC1A48
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Chuuk) {. {-9223372036854775808 36428 0 LMT}. {-2177489228 36000 0 +10}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7935
                                                                                                                                                                                                                                  Entropy (8bit):3.4518545894421475
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:OX45AGaHe2Y9btlqStWdmPndSy//TQMpeQkZyYbK6HdtLQOXJ/+:OX45AGdT9ZtWdmPnZ/TQfbbKsXJ2
                                                                                                                                                                                                                                  MD5:9B0B358E33E33FEFE38BEF73232919F3
                                                                                                                                                                                                                                  SHA1:7164F24730A37875128BE3F2FB4E9BC076AB9F39
                                                                                                                                                                                                                                  SHA-256:E02B71C59DF59109D12EBE60ED153922F1DFF3F5C4AD207E267AB025792C51F4
                                                                                                                                                                                                                                  SHA-512:A0C4A98B0B40FDE690A8EEE7A2C2F16C3E70C6F406FF0699B98CB837C72C6A1259395167795F2CFBBD2943E602AC0483C62B9D6209B8258018F7D78E103BBB15
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Easter) {. {-9223372036854775808 -26248 0 LMT}. {-2524495352 -26248 0 EMT}. {-1178124152 -25200 0 -07}. {-36619200 -21600 1 -07}. {-23922000 -25200 0 -07}. {-3355200 -21600 1 -07}. {7527600 -25200 0 -07}. {24465600 -21600 1 -07}. {37767600 -25200 0 -07}. {55915200 -21600 1 -07}. {69217200 -25200 0 -07}. {87969600 -21600 1 -07}. {100666800 -25200 0 -07}. {118209600 -21600 1 -07}. {132116400 -25200 0 -07}. {150868800 -21600 1 -07}. {163566000 -25200 0 -07}. {182318400 -21600 1 -07}. {195620400 -25200 0 -07}. {213768000 -21600 1 -07}. {227070000 -25200 0 -07}. {245217600 -21600 1 -07}. {258519600 -25200 0 -07}. {277272000 -21600 1 -07}. {289969200 -25200 0 -07}. {308721600 -21600 1 -07}. {321418800 -25200 0 -07}. {340171200 -21600 1 -07}. {353473200 -25200 0 -07}. {371620800 -21600 1 -07}. {384922800 -21600 0 -06}. {403070400 -180
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):705
                                                                                                                                                                                                                                  Entropy (8bit):4.002147979275868
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5cJmdH6mv6kJ2RX/x6DydjX2tHcsXFX2hE5zuGqptxv:cuesUMkGdXWF3A
                                                                                                                                                                                                                                  MD5:48DEC5B1A9AADA4F09D03FEB037A2FE8
                                                                                                                                                                                                                                  SHA1:6D25E80F0570236565F098DD0A637F546957F117
                                                                                                                                                                                                                                  SHA-256:4F9AC8B0FE89990E8CF841EED9C05D92D53568DE772247F70A70DC11CBD78532
                                                                                                                                                                                                                                  SHA-512:0FA4693F3FDAB12DB04B6D50E0782A352CF95A7C2765CF1906BAA35355755E324E1B17005DF3748DBE42743FE824AE983316958B2EC0A9B0B7D136BEC06AB983
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Efate) {. {-9223372036854775808 40396 0 LMT}. {-1829387596 39600 0 +11}. {433256400 43200 1 +11}. {448977600 39600 0 +11}. {467298000 43200 1 +11}. {480427200 39600 0 +11}. {496760400 43200 1 +11}. {511876800 39600 0 +11}. {528210000 43200 1 +11}. {543931200 39600 0 +11}. {559659600 43200 1 +11}. {575380800 39600 0 +11}. {591109200 43200 1 +11}. {606830400 39600 0 +11}. {622558800 43200 1 +11}. {638280000 39600 0 +11}. {654008400 43200 1 +11}. {669729600 39600 0 +11}. {686062800 43200 1 +11}. {696340800 39600 0 +11}. {719931600 43200 1 +11}. {727790400 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):208
                                                                                                                                                                                                                                  Entropy (8bit):4.767926806075848
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5Vm2OH1oePmWXytFBVyv7fPfTVVFmv:MBp5VmdH15PZsBVyDXfZvY
                                                                                                                                                                                                                                  MD5:D7EE7623A410715B1F34DC06F5400996
                                                                                                                                                                                                                                  SHA1:1ADD299AB66A0BCC32D92EAFBC2CA3B277E1FA3D
                                                                                                                                                                                                                                  SHA-256:8CAF3AE352EC168BC0C948E788BB3CBFE3991F36A678A24B47711543D450AED8
                                                                                                                                                                                                                                  SHA-512:356C3ECC40211B36FA1ECF8601AA8FAAE8080606F55AA4E706D239B8EE35ADE3987708716376D73053DB7A59B9A9B7A267EEDA6ED2A80A558FABA48E851C0EB1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Enderbury) {. {-9223372036854775808 -41060 0 LMT}. {-2177411740 -43200 0 -12}. {307627200 -39600 0 -11}. {788871600 46800 0 +13}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):178
                                                                                                                                                                                                                                  Entropy (8bit):4.865240332098143
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDH4ErKYvcXGm2OH18VkevXmUENBBdNiCPFVFv74v:SlSWB9X5BE3Lm2OH1VePmH7fP+v
                                                                                                                                                                                                                                  MD5:6CC11F5FAA361F69262AB8E7F4DB4F90
                                                                                                                                                                                                                                  SHA1:EA7ED940C0A3B5941972439DE1D735B4DC4AE0AA
                                                                                                                                                                                                                                  SHA-256:21C4C35919A24CD9C80BE1BD51C6714AA7EBF447396B3A2E63D330D905FA9945
                                                                                                                                                                                                                                  SHA-512:152709462F29EE14A727BE625E7ABD59625B6C4D4B36A2CE76B68D96CD176EDECA91DF26DAC553346ED360F2CA0F6C62981F50B088AE7BE1B998B425D91EF3B5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Fakaofo) {. {-9223372036854775808 -41096 0 LMT}. {-2177411704 -39600 0 -11}. {1325242800 46800 0 +13}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5505
                                                                                                                                                                                                                                  Entropy (8bit):3.545141446818078
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:9ebtKf1V/ncXDwwn+q5Y6h+ueDJyqm5DHzv:EbIf1V/nGD5n+q5YPO
                                                                                                                                                                                                                                  MD5:67BE85DD77F7B520FD5705A4412157E3
                                                                                                                                                                                                                                  SHA1:04FA33692B8DBB8DDF89EF790646A0535943953D
                                                                                                                                                                                                                                  SHA-256:2FE87FF4AEBB58506B4E2552D3CB66AAC1D038D8C62F8C70B0EAF1CC508EC9FA
                                                                                                                                                                                                                                  SHA-512:35D4C46D187912D2B39C07A50DB0C56427ACF3755AD4B563B734BE26CA9C441AA0C2836266C803919786BF6DA9118A880CCF221FE9F9A9E30D610BE8E4913A9F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Fiji) {. {-9223372036854775808 42944 0 LMT}. {-1709985344 43200 0 +12}. {909842400 46800 1 +12}. {920124000 43200 0 +12}. {941896800 46800 1 +12}. {951573600 43200 0 +12}. {1259416800 46800 1 +12}. {1269698400 43200 0 +12}. {1287842400 46800 1 +12}. {1299333600 43200 0 +12}. {1319292000 46800 1 +12}. {1327154400 43200 0 +12}. {1350741600 46800 1 +12}. {1358604000 43200 0 +12}. {1382796000 46800 1 +12}. {1390050000 43200 0 +12}. {1414850400 46800 1 +12}. {1421503200 43200 0 +12}. {1446300000 46800 1 +12}. {1452952800 43200 0 +12}. {1478354400 46800 1 +12}. {1484402400 43200 0 +12}. {1509804000 46800 1 +12}. {1515852000 43200 0 +12}. {1541253600 46800 1 +12}. {1547301600 43200 0 +12}. {1572703200 46800 1 +12}. {1579356000 43200 0 +12}. {1604152800 46800 1 +12}. {1610805600 43200 0 +12}. {1636207200 46800 1 +12}. {1642255200 43200
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):148
                                                                                                                                                                                                                                  Entropy (8bit):4.974991227981989
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDH4QwyFtXGm2OHwodGevXmcpXrWXVN0UIvYv:SlSWB9X5BCEm2OHwxePmgSX0a
                                                                                                                                                                                                                                  MD5:23994D1C137B8BC2BA6E97739B38E7BD
                                                                                                                                                                                                                                  SHA1:36772677B3C869C49A829AF08486923321ADD50A
                                                                                                                                                                                                                                  SHA-256:F274C6CD08E5AA46FDEA219095DA8EA60DA0E95E5FD1CBCB9E6611DE47980F9E
                                                                                                                                                                                                                                  SHA-512:CB2DB35960D11322AD288912C5D82C8C579791E40E510A90D34AAB20136B17AA019EFD55D1C4A2D9E88F7AF79F15779AF7EC6856F3085161AC84C93872C61176
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Funafuti) {. {-9223372036854775808 43012 0 LMT}. {-2177495812 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):238
                                                                                                                                                                                                                                  Entropy (8bit):4.63034174284777
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5fEjFJm2OHvQYezie7KV9dRncRviWFrN5/uFfXFfrin:MBp5fSFJmdH0zV7O9DdWFN5/uFfXdGn
                                                                                                                                                                                                                                  MD5:307B016C9E6A915B1760D9A6AD8E63C1
                                                                                                                                                                                                                                  SHA1:26B797811821C09CF6BAB76E05FF612359DF7318
                                                                                                                                                                                                                                  SHA-256:F1CB2B1EBD4911857F5F183E446A22E731BD57925AD07B15CA78A7BDDFED611F
                                                                                                                                                                                                                                  SHA-512:F7AAAEE32CAC84F7D54C29E07CB8952D61585B85CB4FFFB93DD824A71403FDF356EC0761E5EEE19D9F8139F11A9CAB0A7DAEADBD13B6DD4C0CDF9FB573794542
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Galapagos) {. {-9223372036854775808 -21504 0 LMT}. {-1230746496 -18000 0 -05}. {504939600 -21600 0 -06}. {722930400 -18000 1 -06}. {728888400 -21600 0 -06}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):149
                                                                                                                                                                                                                                  Entropy (8bit):4.931482658662627
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDH5hBfcXGm2OHKToxYvUdNfiuvn:SlSWB9X5kTm2OHPxYYquv
                                                                                                                                                                                                                                  MD5:98754C9D99442282F5C911725764C5D1
                                                                                                                                                                                                                                  SHA1:7E679DC38A7C7873695E10814B04E3919D1BFB41
                                                                                                                                                                                                                                  SHA-256:7D09014BE33CB2B50554B6937B3E870156FDCB5C36E9F8E8925711E79C12FC74
                                                                                                                                                                                                                                  SHA-512:2044AEEDFEF948E502667D1C60E22814202E4BA657DE89A962B6E9E160A93B3B77BF0AC4F5159FC45D43B2038E624D90A4589FB87F3449CA10D350EF60373D17
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Gambier) {. {-9223372036854775808 -32388 0 LMT}. {-1806678012 -32400 0 -09}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):151
                                                                                                                                                                                                                                  Entropy (8bit):4.934129846149006
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDH5RyJTLJyFkXGm2OHddHvpoxYvUdMWdHPVmv:SlSWB9X5LJHgm2OHdFGxYAHPAv
                                                                                                                                                                                                                                  MD5:193872CE34E69F8B499203BC70C2639B
                                                                                                                                                                                                                                  SHA1:7A2B8E346E3BF3BE48AAA330C3EEE47332E994AB
                                                                                                                                                                                                                                  SHA-256:F1D21C339E8155711AA7EF9F4059A738A8A4CE7A6B78FFDD8DCC4AC0DB5A0010
                                                                                                                                                                                                                                  SHA-512:D2114AD27922799B8C38B0486D1FAE838EC94A461388960A6F2D19F7763E09FF75A9C4619C52BE2626E8EA2275794B694C1A76E2711D10B77CE6E34259DBF2BE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Guadalcanal) {. {-9223372036854775808 38388 0 LMT}. {-1806748788 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):204
                                                                                                                                                                                                                                  Entropy (8bit):4.833752908914461
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5bm2OHauezyRtAePmdSUUyWGHZFUeMn:MBp5bmdHanzCtBP1yWleMn
                                                                                                                                                                                                                                  MD5:AD14439D9E27F2D3545E17082150DC75
                                                                                                                                                                                                                                  SHA1:43DE1D4A90ABE54320583FAB46E6F9B428C0B577
                                                                                                                                                                                                                                  SHA-256:CE4D3D493E625DA15A8B4CD3008D9CBDF20C73101C82F4D675F5B773F4A5CF70
                                                                                                                                                                                                                                  SHA-512:77800323ED5AF49DA5E6314E94938BEAAEDD69BB61E338FAF024C3A22747310307A13C6CBBAFE5A48164855B238C2CAD354426F0EE7201B4FB5C129D68CB0E3B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Guam) {. {-9223372036854775808 -51660 0 LMT}. {-3944626740 34740 0 LMT}. {-2177487540 36000 0 GST}. {977493600 36000 0 ChST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):332
                                                                                                                                                                                                                                  Entropy (8bit):4.582125163058844
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5PeQm2OHsVVPBraX3UNFvDrUXaWFvjHovLnvRY7p0:MBp5WQmdH0VPBa0VOT12G7O
                                                                                                                                                                                                                                  MD5:17ACB888B597247CB0CA3CA191E51640
                                                                                                                                                                                                                                  SHA1:9C2668BF0288D277ED2FE5DBCD5C34F5931004A6
                                                                                                                                                                                                                                  SHA-256:719EA0BC1762078A405936791C65E4255B4250FB2B305342FE768A21D6AF34BE
                                                                                                                                                                                                                                  SHA-512:9D02F784F0CD2195AEDEAA59E3ECD64B27928D48DCBC3EA2651B36B3BE7F8C6D9CBB66ACDC76DC02D94DF19C0A29306DD8C2A15AD89C24188FC3E4BCFBE6D456
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Honolulu) {. {-9223372036854775808 -37886 0 LMT}. {-2334101314 -37800 0 HST}. {-1157283000 -34200 1 HDT}. {-1155436200 -34200 0 HST}. {-880201800 -34200 1 HWT}. {-769395600 -34200 1 HPT}. {-765376200 -37800 0 HST}. {-712150200 -36000 0 HST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):188
                                                                                                                                                                                                                                  Entropy (8bit):4.795254976384326
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG2fWGYFedVAIgObT2fWzvNnUDH0KNyFx/hpUDH2fe:SlSWB9IZaM3yc6e8dVAIgOb6ezvNNWya
                                                                                                                                                                                                                                  MD5:FA20CE420C5370C228EB169BBC083EFB
                                                                                                                                                                                                                                  SHA1:5B4C221AC97292D5002F6ABEB6BC66D7B8E2F01B
                                                                                                                                                                                                                                  SHA-256:83A14BF52D181B3229603393EA90B9535A2FF05E3538B8C9AD19F483E6447C09
                                                                                                                                                                                                                                  SHA-512:7E385FEBD148368F192FC6B1D5E4B8DD31F58EC4329BF9820D554E97402D0A582AB2EBCF46A5151D0167333349A83476BEB11C49BC0EBAADE5A297C42879E0C3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Honolulu)]} {. LoadTimeZoneFile Pacific/Honolulu.}.set TZData(:Pacific/Johnston) $TZData(:Pacific/Honolulu).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):211
                                                                                                                                                                                                                                  Entropy (8bit):4.684652862044272
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDH1meEXGm2OHjToevXmUBepRGFz4vQU8F/5f5vARVvVtQCn:SlSWB9X5iLm2OHjkePmLSz4YjRfSzvJn
                                                                                                                                                                                                                                  MD5:E22A2C0F847601F128986A48A4B72F90
                                                                                                                                                                                                                                  SHA1:4E1D047DC64AA57C311A22FB1DA8497CD7022192
                                                                                                                                                                                                                                  SHA-256:88260F34784960C229B2B282F8004FD1AF4BE1BC2883AAEE7D041A622933C3FE
                                                                                                                                                                                                                                  SHA-512:A80DAC1A2A3376A47E2A542DE92CCC733E440AF2F05A70823DA52A2490FC9D1762F35CE256E6D1F7CCD435EEFBD6B0FBC533459CD3AD79ACD52C7CA78C29317C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Kiritimati) {. {-9223372036854775808 -37760 0 LMT}. {-2177415040 -38400 0 -1040}. {307622400 -36000 0 -10}. {788868000 50400 0 +14}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):201
                                                                                                                                                                                                                                  Entropy (8bit):4.763096849699127
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDH1+AtFkXGm2OHHvvXmc03VLpCcfzvwX0UIv4Q9Hmv:SlSWB9X598Jm2OHHvPmb9fLYX01Yv
                                                                                                                                                                                                                                  MD5:96235B4DD81BA681216B74046A5A8780
                                                                                                                                                                                                                                  SHA1:24D682CE5D7C4A3DF8C860CB80ED262085CB965C
                                                                                                                                                                                                                                  SHA-256:BE400ED502FA7EC34B8DE44B2A3D0AF3033292EF08FD1F5F276147E15460CFF6
                                                                                                                                                                                                                                  SHA-512:4B30A0A1806D5D96FE5F9B1208490E23EABB498B634C98D89553059E68292AAAB6B182FE367E2923DBE0BC03D023D9EFC0EC25F5DD19AB8AE878B32478FF4B55
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Kosrae) {. {-9223372036854775808 39116 0 LMT}. {-2177491916 39600 0 +11}. {-7988400 43200 0 +12}. {915105600 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):205
                                                                                                                                                                                                                                  Entropy (8bit):4.788662012960935
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5yErm2OH4T2ePmvfL/XytdrH0a:MBp5XrmdHWPoL8rUa
                                                                                                                                                                                                                                  MD5:885C86BCE6B3D83D9CD715D75170AA81
                                                                                                                                                                                                                                  SHA1:9607AC6B1756FEBF2BEC2A78138AF12C11FD46F6
                                                                                                                                                                                                                                  SHA-256:2E636A3576119F2976D2029E75F26A060A5C0800BF7B719F1CB4562D896A6432
                                                                                                                                                                                                                                  SHA-512:410D32CBAB0C1B9D948C2C1416B6D158650600748F1C96D16121DB5F0A9D8384A14067E8603576ED1101BD62F6529C6E7A129428B77CBA1D185214D051F2C6B2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Kwajalein) {. {-9223372036854775808 40160 0 LMT}. {-2177492960 39600 0 +11}. {-7988400 -43200 0 -12}. {745848000 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):173
                                                                                                                                                                                                                                  Entropy (8bit):4.868505550342842
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHznHLXGm2OHy3HuxYvXmcQ/VpCcfzvwX0UIvYv:SlSWB9X5Qim2OHyexYPmf/ffLYX0a
                                                                                                                                                                                                                                  MD5:5664FAB6368844F8139F48C32A1486B9
                                                                                                                                                                                                                                  SHA1:55826443FB44D44B5331082568E2C46257A0F726
                                                                                                                                                                                                                                  SHA-256:CBBB814CE6E9F2FA1C8F485BBDB0B759FDA8C859BC989EC28D4756CC10B21A82
                                                                                                                                                                                                                                  SHA-512:1BD1D6C2224E0DCC7A1887ECEB38C64E8DEABF44BE52FE29C5A302BAD95C0EB9DBD20E5738F3916B8902FA084606E07BE3723C1BE62416EB1E6DC4AD215A56F0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Majuro) {. {-9223372036854775808 41088 0 LMT}. {-2177493888 39600 0 +11}. {-7988400 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):153
                                                                                                                                                                                                                                  Entropy (8bit):4.930595315407702
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHzrHeHkXGm2OHOx5vUdNpNFvvIVVCC:SlSWB9X5cHeLm2OHOnY/FvQVVL
                                                                                                                                                                                                                                  MD5:B41251BE6A78B9BA4F7859D344517738
                                                                                                                                                                                                                                  SHA1:8C0DFDD40B8AE1DFA6C3C1BDD44E8452F5EE49E1
                                                                                                                                                                                                                                  SHA-256:FC06B45FB8C5ED081BAFA999301354722AEF17DB2A9C58C6CDF81C758E63D899
                                                                                                                                                                                                                                  SHA-512:96D302EAA274BEE26325B8334DA8C3782B8DC0E279DDF464D281AF2B0CEE19E9254837A4B1D08F9B777BE892F639D205F6AB85C37C8F8B58A4867EA082FF054B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Marquesas) {. {-9223372036854775808 -33480 0 LMT}. {-1806676920 -34200 0 -0930}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):189
                                                                                                                                                                                                                                  Entropy (8bit):4.763101291800624
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQGurKeTIVAIgObTurKeUAtnUDHz0HvUDHurKeTv:SlSWB9IZaM3ycieZVAIgObieiZeg
                                                                                                                                                                                                                                  MD5:A5A67AC85621952E16528DD73C94346E
                                                                                                                                                                                                                                  SHA1:FB3D1AD833CD77B8FE68AC37FAA39FF4A9A69815
                                                                                                                                                                                                                                  SHA-256:B4C19E4D05CCBC73ABE5389EBCFCC5586036C1D2275434003949E1CF634B9C26
                                                                                                                                                                                                                                  SHA-512:5BB96561582BA3E9F2973322BCF76BD3F9023EC965A0CB504DFE13C127CA2ED562D040EC033DDB946FBB17E9FDD2EAB7532F88B2B0F1182CE880E41C920CFD36
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Pago_Pago)]} {. LoadTimeZoneFile Pacific/Pago_Pago.}.set TZData(:Pacific/Midway) $TZData(:Pacific/Pago_Pago).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):235
                                                                                                                                                                                                                                  Entropy (8bit):4.6089214752758965
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5Jem2OHceR6sCHST0ikvScCdpShcX0a:MBp5JemdH9sxZHCDEta
                                                                                                                                                                                                                                  MD5:CBC3FE6B512B0A3E96B7F47E4CD830EB
                                                                                                                                                                                                                                  SHA1:A1962DF38BED723F8F747B8931B57FAAC2E8291C
                                                                                                                                                                                                                                  SHA-256:8118062E25736A4672B11D6A603B5A8FE2ED1A82E1814261DF087EA3071A7DD7
                                                                                                                                                                                                                                  SHA-512:18E0975189794068033AD000D6A3DA8859EDAAE9D546969AB683399031888307D3F52909DCFEB637CF719782D4F5E87D49A73D6D4B53DEF6FD98041B7A046686
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Nauru) {. {-9223372036854775808 40060 0 LMT}. {-1545131260 41400 0 +1130}. {-877347000 32400 0 +09}. {-800960400 41400 0 +1130}. {294323400 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):209
                                                                                                                                                                                                                                  Entropy (8bit):4.680590339435768
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5Jm3Lm2OHJPm60jdFBJNsYv8FyGv7Kn:MBp5JmbmdHJPB0mYRGDKn
                                                                                                                                                                                                                                  MD5:54FD41634DDEAA58F9F9770DC82B3E5F
                                                                                                                                                                                                                                  SHA1:E5296ACE7239C4CD7E13D391676F910376556ACC
                                                                                                                                                                                                                                  SHA-256:9D4E202A1ED8609194A97ED0F58B3C36DF83F46AE92EAF09F8337317DCACA75F
                                                                                                                                                                                                                                  SHA-512:9A2192C1232368FA5D382062A2C48869155B727C970F5D5BCD5FE424FC9D15417394E637D77FCA793B633517A1BFED8D93E74F239A3BC1A6716615B6D877ADC6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Niue) {. {-9223372036854775808 -40780 0 LMT}. {-2177412020 -40800 0 -1120}. {-599575200 -41400 0 -1130}. {276089400 -39600 0 -11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):269
                                                                                                                                                                                                                                  Entropy (8bit):4.580350938236725
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5JJpkLm2OH6uToePmUOvJiQHSJE8Gy+xS7zzv:MBp5JJAmdH6SPIvVH787+xkv
                                                                                                                                                                                                                                  MD5:147E5FF4670F8551895B7B0EC1A66D46
                                                                                                                                                                                                                                  SHA1:83F0D4DC817ED61E7985CC7AB3268B3EBAD657A3
                                                                                                                                                                                                                                  SHA-256:A56472811F35D70F95E74A7366297BFAAFBC034CD10E9C0F3C59EFFA21A74223
                                                                                                                                                                                                                                  SHA-512:FE183CA00E7D2B79F8E81E1FAF5E8CE103E430B7159C14CA915FD2BFE6D4381BF42EDB217E9D99C13D728CD09BB0E67562E84D957E9606F6B6C1AB08657DDBF9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Norfolk) {. {-9223372036854775808 40312 0 LMT}. {-2177493112 40320 0 +1112}. {-599656320 41400 0 +1130}. {152029800 45000 1 +1230}. {162912600 41400 0 +1130}. {1443882600 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):314
                                                                                                                                                                                                                                  Entropy (8bit):4.468119357525684
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9X5JcdJm2OHTYAfIX2pVzOa9FxpZPS62pm+v:MBp5JcLmdHTYJX2fzFjb123v
                                                                                                                                                                                                                                  MD5:A966877A1BEBFE5125460233A5C26728
                                                                                                                                                                                                                                  SHA1:721103E2BFC0991CE80708D77C3FBEDCC2B3C9D3
                                                                                                                                                                                                                                  SHA-256:8C282AC6DA722858D8B1755C710BE3EC4BD8EFEF4832A415E772EED287899315
                                                                                                                                                                                                                                  SHA-512:51B5BD7834D4B3BAEEF3E1A2E6F469F6FFC354407182CA87AF67C4F4F26D4CB116A60BBB08BC178950CA3CFF978E2809EFC73002A4F8883B454024A2FFCBD732
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Noumea) {. {-9223372036854775808 39948 0 LMT}. {-1829387148 39600 0 +11}. {250002000 43200 1 +11}. {257342400 39600 0 +11}. {281451600 43200 1 +11}. {288878400 39600 0 +11}. {849366000 43200 1 +11}. {857228400 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.94008377236012
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHurKeTFwSXGm2OH2ivkevXUPi1TsYvUdfWTVvvL:SlSWB9X5XevJm2OH23ePWieYCWZvvL
                                                                                                                                                                                                                                  MD5:7ABD13E51C01A85468F6511B6710E4B5
                                                                                                                                                                                                                                  SHA1:9DC80A7BFD7028DB672A20EF32C31B11F083BA99
                                                                                                                                                                                                                                  SHA-256:AEE9D8FBCB7413536DA1CBDC4F28B7863B3DDD5E6A5AB2A90CE32038AC0EA2B8
                                                                                                                                                                                                                                  SHA-512:6F6BBEBB10FD6B3987D3076D93DC06F5F765FAC22A90C4184AAF33C1FFD4CBD98464C8A0B4C0C38808AA6D08F91F5060BCEC83E278B8BEF21124C7FE427A09AF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Pago_Pago) {. {-9223372036854775808 45432 0 LMT}. {-2445424632 -40968 0 LMT}. {-1861879032 -39600 0 SST}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):145
                                                                                                                                                                                                                                  Entropy (8bit):4.920441332270432
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHugEZFwcXGm2OHCAnvXmdQ4+vScCC:SlSWB9X5Xg2wTm2OHPnPmdQRvScCC
                                                                                                                                                                                                                                  MD5:4070C7A615EF7977537641B01FA46AD6
                                                                                                                                                                                                                                  SHA1:E80FF2BBD448B2399DBE56D279858D7D06EBA691
                                                                                                                                                                                                                                  SHA-256:F12CB444E9BA91385BED20E60E7DF1A0DB0CE76C6FC7ACA59EEF029BC56D5EA3
                                                                                                                                                                                                                                  SHA-512:5DD3FD1D0AA4D6DA3F274BEEC283A72B4532804AA9901AB4B1616D36C13CB8F5CC51DB8A6B89C019FAD875ABB567EFC8BD894AADC1E63E94A8CAC79F3E82CB6C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Palau) {. {-9223372036854775808 32276 0 LMT}. {-2177485076 32400 0 +09}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.757588870650609
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHuQTWLMWkXGm2OHUVFvvXmXUlgloRNycyf/vGRvn:SlSWB9X5XQyLMCm2OHUVVPmXUKmOhf/+
                                                                                                                                                                                                                                  MD5:AB8D0D9514FA6C5E995AE76D2DAEA6D4
                                                                                                                                                                                                                                  SHA1:3775349B3BE806AA005174D91597D6F2C54E8EC5
                                                                                                                                                                                                                                  SHA-256:3BB856B2C966211D7689CD303DFDDACB3C323F3C2DA0FF47148A8C5B7BC0E1C4
                                                                                                                                                                                                                                  SHA-512:AB5D2E00C820D36A2A8B198AAC9350BEFA235EA848A11B16B042EE8124975DCAFC737D30D7C1A01D874B0937E469C2364441FCA686B5EB66A48251F587F55DC5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Pitcairn) {. {-9223372036854775808 -31220 0 LMT}. {-2177421580 -30600 0 -0830}. {893665800 -28800 0 -08}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):147
                                                                                                                                                                                                                                  Entropy (8bit):4.9618148014469705
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHuy3EXGm2OH1/VvXmcrLmv:SlSWB9X5Xybm2OH1NPmSqv
                                                                                                                                                                                                                                  MD5:0D8489972CBD248971C83DA074C79030
                                                                                                                                                                                                                                  SHA1:3E390EDC1A2F678918220026F03E914BB6E8ED4B
                                                                                                                                                                                                                                  SHA-256:A85364C6E79EA16FD0C86A5CF74CCB84843009A6738AAED3B13A709F1BDF0DF7
                                                                                                                                                                                                                                  SHA-512:A43E459BAB47F133E27A67CFA448E94FBE796DDC23A2D6C3400437D3BC8F31AC2EF3541C4588CF494E1BBD55856C5FA8553A6CD92534E2243EFA31BE2BF5A4CC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Pohnpei) {. {-9223372036854775808 37972 0 LMT}. {-2177490772 39600 0 +11}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):183
                                                                                                                                                                                                                                  Entropy (8bit):4.735143778298082
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQGuySedVAIgObTuyvQnUDHu3HppUDHuyu:SlSWB9IZaM3yciySedVAIgObiyvQX3HP
                                                                                                                                                                                                                                  MD5:C963ECC06914E8E42F0B96504C1F041C
                                                                                                                                                                                                                                  SHA1:82D256793B22E9C07362708EE262A6B46AC13ACD
                                                                                                                                                                                                                                  SHA-256:86593D3A9DC648370A658D82DA7C410E26D818DB2749B79F57A802F8CED76BD3
                                                                                                                                                                                                                                  SHA-512:0F3691977F992A3FF281AD1577BA0BD4AAF7DB3F167E1A1FF139374C14B14F1A456BE7E7D362D698A8294A6AB906E69AC56E1EE0DAF77C13050553299FB6DAF5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Pohnpei)]} {. LoadTimeZoneFile Pacific/Pohnpei.}.set TZData(:Pacific/Ponape) $TZData(:Pacific/Pohnpei).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):183
                                                                                                                                                                                                                                  Entropy (8bit):4.8981931494123065
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHuwKXI3EXGm2OHwdvvXZUeQTnoowFZnqMVVMUJv:SlSWB9X5X/43Lm2OHwdvPZZQTnoDZDVN
                                                                                                                                                                                                                                  MD5:AF14EE836FE5D358C83568C5ACFA88C0
                                                                                                                                                                                                                                  SHA1:22026C7FE440E466193E6B6935C2047BD321F76B
                                                                                                                                                                                                                                  SHA-256:33E0A5DD919E02B7311A35E24DB37F86A20A394A195FE01F5A3BE7336F276665
                                                                                                                                                                                                                                  SHA-512:BEF151E1198D57328BA0FC01BB6F00AD51ADEEE99A97C30E0D08FFB3CFCB9E99B34DBAD03FCB3B19F17D60590FA0E6C5F2978954A3585CDFD31E32C93B05154D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Port_Moresby) {. {-9223372036854775808 35320 0 LMT}. {-2840176120 35312 0 PMMT}. {-2366790512 36000 0 +10}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):907
                                                                                                                                                                                                                                  Entropy (8bit):3.848488423299009
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:ccekzUF0tMUObNFnNUYWJYu+nkonSAOaJT/rbkoa5SBnLn:1zUuMUOnNUVJYxkonSAOaJTjbkoasRLn
                                                                                                                                                                                                                                  MD5:19F22E22F7B136EFCB45E83BC765E871
                                                                                                                                                                                                                                  SHA1:500CC7EA47902856727C2B6D23BF4DAFF6817EB4
                                                                                                                                                                                                                                  SHA-256:B1235ED60A50282E14F4B2B477F9936D15CAF91495CBB81971A2C9580209C420
                                                                                                                                                                                                                                  SHA-512:2FD667F105E57A62821B2BB301A1A31BB56FA6670AADC94F41337445335262FE40DA5DAE7113328E54379E45246B5419B94F8C8AFB73B1F2405E7F08F5D6FBCC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Rarotonga) {. {-9223372036854775808 -38344 0 LMT}. {-2177414456 -37800 0 -1030}. {279714600 -34200 0 -10}. {289387800 -36000 0 -10}. {309952800 -34200 1 -10}. {320837400 -36000 0 -10}. {341402400 -34200 1 -10}. {352287000 -36000 0 -10}. {372852000 -34200 1 -10}. {384341400 -36000 0 -10}. {404906400 -34200 1 -10}. {415791000 -36000 0 -10}. {436356000 -34200 1 -10}. {447240600 -36000 0 -10}. {467805600 -34200 1 -10}. {478690200 -36000 0 -10}. {499255200 -34200 1 -10}. {510139800 -36000 0 -10}. {530704800 -34200 1 -10}. {541589400 -36000 0 -10}. {562154400 -34200 1 -10}. {573643800 -36000 0 -10}. {594208800 -34200 1 -10}. {605093400 -36000 0 -10}. {625658400 -34200 1 -10}. {636543000 -36000 0 -10}. {657108000 -34200 1 -10}. {667992600 -36000 0 -10}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.8048918219164065
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG5RFedVAIgObT5RSQnUDHtluKpUDH5Rp:SlSWB9IZaM3ycdedVAIgObaQvKM
                                                                                                                                                                                                                                  MD5:BE50B3EE2BD083842CFFB7698DD04CDE
                                                                                                                                                                                                                                  SHA1:0B8C8AFC5F94E33226F148202EFFBD0787D61FA2
                                                                                                                                                                                                                                  SHA-256:74DD6FE03E3061CE301FF3E8E309CF1B10FC0216EEC52839D48B210BCBD8CF63
                                                                                                                                                                                                                                  SHA-512:136BCF692251B67CD3E6922AD0A200F0807018DC191CAE853F2192FD385F8150D5CCF36DF641ED9C09701E4DBBB105BF97C7540D7FA9D9FFC440682B770DF5BA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Guam)]} {. LoadTimeZoneFile Pacific/Guam.}.set TZData(:Pacific/Saipan) $TZData(:Pacific/Guam).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):188
                                                                                                                                                                                                                                  Entropy (8bit):4.729839728044672
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQGurKeTIVAIgObTurKeUAtnUDHthA5nUDHurKeTv:SlSWB9IZaM3ycieZVAIgObieiNXeg
                                                                                                                                                                                                                                  MD5:843BBE96C9590D69B09FD885B68DE65A
                                                                                                                                                                                                                                  SHA1:25BF176717A4578447E1D77F9BF0140AFF18625A
                                                                                                                                                                                                                                  SHA-256:4F031CB2C27A3E311CA4450C20FB5CF4211A168C39591AB02EEEC80A5A8BFB93
                                                                                                                                                                                                                                  SHA-512:B50301CFC8E5CF8C257728999B0D91C06E2F7C040D30F71B90BBC612959B519E8D27EE2DA9B8B9002483D3F4F173BB341A07898B4E4C98A146B3D988CA3BD5B2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Pago_Pago)]} {. LoadTimeZoneFile Pacific/Pago_Pago.}.set TZData(:Pacific/Samoa) $TZData(:Pacific/Pago_Pago).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):148
                                                                                                                                                                                                                                  Entropy (8bit):4.900317309402027
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHqhFtXGm2OHl/oevUdNqRU8Cn:SlSWB9X5TTEm2OHloeYqRQn
                                                                                                                                                                                                                                  MD5:DDF599B7659B88603DF80E390471CB10
                                                                                                                                                                                                                                  SHA1:80FF5E0E99483CB8952EC137A261D034B6759D07
                                                                                                                                                                                                                                  SHA-256:B8282EC1E5BFA5E116C7DC5DC974B0605C85D423519F124754126E8F8FE439EC
                                                                                                                                                                                                                                  SHA-512:28F15CB6310190066936B7B21024205EC87A54D081415B1E46E72982814E1E2A41A2CE8B808D02E705100CE5ACBB1E69F1859E40A04F629B7004FBD89DD37899
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Tahiti) {. {-9223372036854775808 -35896 0 LMT}. {-1806674504 -36000 0 -10}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):146
                                                                                                                                                                                                                                  Entropy (8bit):4.924466748251822
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHqQwcXGm2OHyyFpoevXmciRrWFN0UIvYv:SlSWB9X5TbTm2OHyyFGePmbu0a
                                                                                                                                                                                                                                  MD5:AE5E0FFFEEFD0A8E77233CB0E59DE352
                                                                                                                                                                                                                                  SHA1:7B7CC1095FB919946F3315C4A28994AEB1ECD51A
                                                                                                                                                                                                                                  SHA-256:1FCC6C0CC48538EDB5B8290465156B2D919DFA487C740EB85A1DF472C460B0E6
                                                                                                                                                                                                                                  SHA-512:1693FA5DE78FDCF79993CB137EE0568A4B8245D0177DF845356B3C2418641C8AA23CAA7069707C0E180FF9F5345D380A3575EEFFE0C8BC08E18E40ED0E1F6FA3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Tarawa) {. {-9223372036854775808 41524 0 LMT}. {-2177494324 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):436
                                                                                                                                                                                                                                  Entropy (8bit):4.271209640478309
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12:MBp5kJmdHmLP72Dcw8UtnKbUtrtAUt54bUtjg:cOem77il2eQ
                                                                                                                                                                                                                                  MD5:C32CDBF9C696134870351ABB80920E08
                                                                                                                                                                                                                                  SHA1:43918B7BF46EF2B574D684D36901592E43A45A8A
                                                                                                                                                                                                                                  SHA-256:8FE5EF266C660C4A25827BE9C2C4081A206D946DD46EBC1095F8D18F41536399
                                                                                                                                                                                                                                  SHA-512:1E10C548659A9CE0A9F0C7E6FD86EAD8627C07A8C9842933E7C6CD28EACDE3735DBFDCF7DD1DE5DDE7F2F102F7D584B3C44B1350AFDF7E1621FE9F565CD32362
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Tongatapu) {. {-9223372036854775808 44360 0 LMT}. {-2177497160 44400 0 +1220}. {-915193200 46800 0 +13}. {915102000 46800 0 +13}. {939214800 50400 1 +13}. {953384400 46800 0 +13}. {973342800 50400 1 +13}. {980596800 46800 0 +13}. {1004792400 50400 1 +13}. {1012046400 46800 0 +13}. {1478350800 50400 1 +13}. {1484398800 46800 0 +13}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.865414495402954
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG9CovedVAIgObT9CknUDHqAOsvUDH9Cov:SlSWB9IZaM3yckGedVAIgObkkTAOmy
                                                                                                                                                                                                                                  MD5:3282C08FE7BC3A5F4585E97906904AE1
                                                                                                                                                                                                                                  SHA1:09497114D1EC149FB5CF167CBB4BE2B5E7FFA982
                                                                                                                                                                                                                                  SHA-256:DC6263DCC96F0EB1B6709693B9455CB229C8601A9A0B96A4594A03AF42515633
                                                                                                                                                                                                                                  SHA-512:077924E93AC9F610CD9FE158655B631186198BD96995428EB9EE2082449BD36CBF6C214D86E51A6D9A83329FCD5E931C343AA14DBB286C53071D46692B81BC0D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Chuuk)]} {. LoadTimeZoneFile Pacific/Chuuk.}.set TZData(:Pacific/Truk) $TZData(:Pacific/Chuuk).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):144
                                                                                                                                                                                                                                  Entropy (8bit):4.9366125478034935
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHp8FkXGm2OH4VkxYvXmcDVv0UIvYv:SlSWB9X5PJm2OHYkxYPmyv0a
                                                                                                                                                                                                                                  MD5:AD4044C0F87566AA5265DA84CD3DABBA
                                                                                                                                                                                                                                  SHA1:15ED1B5960B3E70B23C430B0281B108506BBE76C
                                                                                                                                                                                                                                  SHA-256:2C273BA8F8324E1B414B40DC356C78E0FD3C02D5E8158EA5753CA51E1185FC11
                                                                                                                                                                                                                                  SHA-512:AD4758B01038BCAA519776226B43D90CED89292BA47988F639D45FD5B5436ED4E3B16C27F9145EC973DCC242FF6ADC514D7CDD6660E7CE8DD8E92A96CDACD947
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Wake) {. {-9223372036854775808 39988 0 LMT}. {-2177492788 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):146
                                                                                                                                                                                                                                  Entropy (8bit):4.932023172694197
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFx5nUDHpEf/kXGm2OH3UPvXmcCRQH0UIvYv:SlSWB9X5tfTm2OHkPPmiH0a
                                                                                                                                                                                                                                  MD5:9FBFA7A7556A081F2352250B44EB0CB6
                                                                                                                                                                                                                                  SHA1:CB16A38A9E51FEFC803C4E119395B9BCDBA1CF95
                                                                                                                                                                                                                                  SHA-256:29ABBA5D792FB1D754347DED8E17423D12E07231015D5A65A5873BFC0CE474C7
                                                                                                                                                                                                                                  SHA-512:CD0FA19597D7188F1D05E8FE9DD9B650DDD30CBBEF3F16646715D5DEF5A261C1E92ADE781DEA609B163808D7A59A0F7AF168332D0134D87DADE42447ABE7E431
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:Pacific/Wallis) {. {-9223372036854775808 44120 0 LMT}. {-2177496920 43200 0 +12}.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):174
                                                                                                                                                                                                                                  Entropy (8bit):4.887747451136248
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG9CovedVAIgObT9CknUDHnHPUDH9Cov:SlSWB9IZaM3yckGedVAIgObkkeBy
                                                                                                                                                                                                                                  MD5:63594F45385660A04D21C11B5F203FF4
                                                                                                                                                                                                                                  SHA1:CEEC55B952B8EBA952E0965D92220C8EF001E59E
                                                                                                                                                                                                                                  SHA-256:4418559478B5881DFAF3FE3246A4BFE2E62C46C1D3D452EE4CF5D9651C4F92B5
                                                                                                                                                                                                                                  SHA-512:B9B55B027EFB7E87D44E89191C03A8409A16FA19A52032E29210161AE8FED528A6504B7B487181847125AF2C7C129A0687323CDDC6D5454199229897F97F0AB0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Chuuk)]} {. LoadTimeZoneFile Pacific/Chuuk.}.set TZData(:Pacific/Yap) $TZData(:Pacific/Chuuk).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):169
                                                                                                                                                                                                                                  Entropy (8bit):4.89278153269951
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVqEGIVyVAIgoqpEGuHtnSi67x/yQa0EGIv:SlSWB9IZaM3ymczVAIgocuN27x6qS
                                                                                                                                                                                                                                  MD5:975F22C426CE931547D50A239259609A
                                                                                                                                                                                                                                  SHA1:77D68DF6203E3A2C1A2ADD6B6F8E573EF849AE2E
                                                                                                                                                                                                                                  SHA-256:309DE0FBCCDAE21114322BD4BE5A8D1375CD95F5FC5A998B3F743E904DC1A131
                                                                                                                                                                                                                                  SHA-512:ABDF01FCD0D34B5A8E97C604F3976E199773886E87A13B3CDD2319A92BD34D76533D4BA41978F8AAA134D200B6E87F26CB8C223C2760A4D7A78CD7D889DB79BE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Warsaw)]} {. LoadTimeZoneFile Europe/Warsaw.}.set TZData(:Poland) $TZData(:Europe/Warsaw).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):171
                                                                                                                                                                                                                                  Entropy (8bit):4.887895128079745
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVxMvLSwFVAIgoqyMvLN6nM24h8QavMvLu:SlSWB9IZaM3ymvMv2wFVAIgovMvUe81B
                                                                                                                                                                                                                                  MD5:31202B87B7352110A03D740D66DCD967
                                                                                                                                                                                                                                  SHA1:439A3700721D4304FA81282E70F6305BB3706C8D
                                                                                                                                                                                                                                  SHA-256:8288E9E5FC25549D6240021BFB569ED8EB07FF8610AAA2D39CD45A025EBD2853
                                                                                                                                                                                                                                  SHA-512:AB95D3990DC99F6A06BF3384D98D42481E198B2C4D1B2C85E869A2F95B651DDF64406AB15C485698E24F26D1A081E22371CE74809915A7CCA02F2946FB8607BF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Lisbon)]} {. LoadTimeZoneFile Europe/Lisbon.}.set TZData(:Portugal) $TZData(:Europe/Lisbon).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):160
                                                                                                                                                                                                                                  Entropy (8bit):4.743612967973961
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8qMvedVAIgNqBolOr4WFKfMv:SlSWB9IZaM3yKMvedVAIgcBoS4wKfMv
                                                                                                                                                                                                                                  MD5:A0C5022166493D766E827B88F806CA32
                                                                                                                                                                                                                                  SHA1:2A679A391C810122DDD6A7EF722C35328FC09D9C
                                                                                                                                                                                                                                  SHA-256:537EA39AFBA7CFC059DE58D484EF450BEE73C7903D36F09A16CA983CB5B8F686
                                                                                                                                                                                                                                  SHA-512:85FEF0A89087D2196EC817A6444F9D94A8D315A64EAE9615C615DBB79B30320CED0D49A1A6C2CD566C722971FA8908A675B1C8F7E64D6875505C60400219F938
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Taipei)]} {. LoadTimeZoneFile Asia/Taipei.}.set TZData(:ROC) $TZData(:Asia/Taipei).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):157
                                                                                                                                                                                                                                  Entropy (8bit):4.851755466867201
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq8ZQckvFVAIgNtvQstlmFeWFKKQs:SlSWB9IZaM3yJmFVAIgztpwKg
                                                                                                                                                                                                                                  MD5:48E7BE02E802A47C0D2F87E633010F38
                                                                                                                                                                                                                                  SHA1:A547853A7ED03CE9C07FC3BAA0F57F5ABB4B636B
                                                                                                                                                                                                                                  SHA-256:2F362169FD628D6E0CB32507F69AD64177BC812E7E961E5A738F4F492B105128
                                                                                                                                                                                                                                  SHA-512:BCBE9BC1C08CFF97B09F8D566EC3B42B9CE8442FA4BECE37A18446CBBF0ECEDA66BA18ABFA5E52E7677B18FB5DABF00DF9E28DE17B094A690B097AFC7130EA89
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Seoul)]} {. LoadTimeZoneFile Asia/Seoul.}.set TZData(:ROK) $TZData(:Asia/Seoul).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.80663340464643
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyq801cwFVAIgNtK1ERLkZ8O5h4WFKf1E:SlSWB9IZaM3yUpFVAIgWWLkth4wKfK
                                                                                                                                                                                                                                  MD5:9E2902F20F33CA25B142B6AA51D4D54F
                                                                                                                                                                                                                                  SHA1:C1933081F30ABB7780646576D7D0F54DC6F1BC51
                                                                                                                                                                                                                                  SHA-256:FCF394D598EC397E1FFEED5282874408D75A9C3FFB260C55EF00F30A80935CA4
                                                                                                                                                                                                                                  SHA-512:D56AF44C4E4D5D3E6FC31D56B9BA36BD8499683D1A3C9BC48EEE392C4AC5ACAA10E3E82282F5BDA9586AF26F4B6C0C5649C454399144F040CC94EA35BBB53B48
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Asia/Singapore)]} {. LoadTimeZoneFile Asia/Singapore.}.set TZData(:Singapore) $TZData(:Asia/Singapore).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):196
                                                                                                                                                                                                                                  Entropy (8bit):4.951561086936219
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSNJB9IZaM3y7p5oedVAIgppKNkjx+90pu:JBaIMYYpgN8+90M
                                                                                                                                                                                                                                  MD5:A1D42EC950DE9178058EAA95CCFBAA09
                                                                                                                                                                                                                                  SHA1:55BE1FAF85F0D5D5604685F9AC19286142FC7133
                                                                                                                                                                                                                                  SHA-256:888A93210241F6639FB9A1DB0519407047CB7F5955F0D5382F2A85C0C473D9A5
                                                                                                                                                                                                                                  SHA-512:3C6033D1C84B75871B8E37E71BFEE26549900C555D03F8EC20A31076319E2FEBB0240EC075C2CAFC948D629A32023281166A7C69AFEA3586DEE7A2F585CB5E82
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Puerto_Rico)]} {. LoadTimeZoneFile America/Puerto_Rico.}.set TZData(:SystemV/AST4) $TZData(:America/Puerto_Rico).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):187
                                                                                                                                                                                                                                  Entropy (8bit):4.900537547414888
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqx02NEO4FVAIg202NEtYFkRDwh4IAcGE2NEOv:SlSNJB9IZaM3y7UEO4FVAIgpUEqFk+4b
                                                                                                                                                                                                                                  MD5:CFDB782F87A616B89203623B9D6E3DBF
                                                                                                                                                                                                                                  SHA1:1BB9F75215A172B25D3AE27AAAD6F1D74F837FE6
                                                                                                                                                                                                                                  SHA-256:62C72CF0A80A5821663EC5923B3F17C12CE5D6BE1E449874744463BF64BCC3D7
                                                                                                                                                                                                                                  SHA-512:085E5B6E81E65BC781B5BC635C6FA1E7BF5DC69295CF739C739F6361BF9EB67F36F7124A2D3E5ADA5F854149C84B9C8A7FB22E5C6E8FF57576EBDEA0E4D6560B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Halifax)]} {. LoadTimeZoneFile America/Halifax.}.set TZData(:SystemV/AST4ADT) $TZData(:America/Halifax).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.911352504536709
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqx0sAzE5YyVAIg20sAzEvYvW6kR/eIAcGEsAzEun:SlSNJB9IZaM3y7hzipVAIgphzGCW6kcQ
                                                                                                                                                                                                                                  MD5:01215B5D234C433552A3BF0A440B38F6
                                                                                                                                                                                                                                  SHA1:B3A469977D38E1156B81A93D90E638693CFDBEEF
                                                                                                                                                                                                                                  SHA-256:2199E7DD20502C4AF25D57A58B11B16BA3173DB47EFA7AD2B33FDB72793C4DDB
                                                                                                                                                                                                                                  SHA-512:35D3BDE235FF40C563C7CEDD8A2CCBB4BAC2E2AA24A8E072EA0572BB231295D705EA9F84EEAA9FD2C735B1203332D8D97C3592A2B702BCFE9C81828D4F635205
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Regina)]} {. LoadTimeZoneFile America/Regina.}.set TZData(:SystemV/CST6) $TZData(:America/Regina).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):187
                                                                                                                                                                                                                                  Entropy (8bit):4.929669998131187
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqx096dVAIg2096zAtkRwx/h4IAcGE96s:SlSNJB9IZaM3y796dVAIgp96Wkyxp49c
                                                                                                                                                                                                                                  MD5:CDE40B5897D89E19A3F2241912B96826
                                                                                                                                                                                                                                  SHA1:00DE53DC7AA97F26B1A8BF83315635FBF634ABB3
                                                                                                                                                                                                                                  SHA-256:3C83D3DB23862D9CA221109975B414555809C27D45D1ED8B9456919F8BA3BF25
                                                                                                                                                                                                                                  SHA-512:69DFC06ACF544B7F95DEF2928C1DFE4D95FAD48EE753AD994921E1967F27A3AF891A9F31DDEA547E1BED81C5D2ECF5FC93E75019F2327DE1E73A009422BE52EC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Chicago)]} {. LoadTimeZoneFile America/Chicago.}.set TZData(:SystemV/CST6CDT) $TZData(:America/Chicago).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):199
                                                                                                                                                                                                                                  Entropy (8bit):4.881715127736134
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSNJB9IZaM3y73G7mFVAIgp3GBLkkp4903G1:JBaIMY3G7Hp3GBLVp4903G1
                                                                                                                                                                                                                                  MD5:87FEA19F6D7D08F44F93870F7CBBD456
                                                                                                                                                                                                                                  SHA1:EB768ECB0B1B119560D2ACBB10017A8B3DC77FDD
                                                                                                                                                                                                                                  SHA-256:2B5887460D6FB393DED5273D1AA87A6A9E1F9E7196A8FA11B4DEB31FAD8922C8
                                                                                                                                                                                                                                  SHA-512:00DA47594E80D2DB6F2BE6E482A1140780B71F8BBE966987821249984627C5D8C31AA1F2F6251B4D5084C33C66C007A47AFF4F379FA5DA4A112BA028B982A85A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Indianapolis)]} {. LoadTimeZoneFile America/Indianapolis.}.set TZData(:SystemV/EST5) $TZData(:America/Indianapolis).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):190
                                                                                                                                                                                                                                  Entropy (8bit):5.071686349792137
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqx0wAy0vwVAIg20wAyatkR5ghxEH/h4IAcGEwAy0v:SlSNJB9IZaM3y71KVAIgp1Bkrp4901h
                                                                                                                                                                                                                                  MD5:5C43C828D9460B9DF370F0D155B03A5C
                                                                                                                                                                                                                                  SHA1:92F92CD64937703D4829C42FE5656C7CCBA22F4E
                                                                                                                                                                                                                                  SHA-256:3F833E2C2E03EF1C3CC9E37B92DBFBA429E73449E288BEBE19302E23EB07C78B
                                                                                                                                                                                                                                  SHA-512:A88EAA9DAAD9AC622B75BC6C89EB44A2E4855261A2F7077D8D4018F00FC82E5E1EA364E3D1C08754701A545F5EC74752B9F3657BF589CF76E5A3931F81E99BBF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/New_York)]} {. LoadTimeZoneFile America/New_York.}.set TZData(:SystemV/EST5EDT) $TZData(:America/New_York).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):188
                                                                                                                                                                                                                                  Entropy (8bit):4.927529755640769
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqTQG2fWGYFedVAIgObT2fWzvNkRSm1hpUDH2fWRn:SlSNJB9IZaM3yc6e8dVAIgOb6ezvNkQN
                                                                                                                                                                                                                                  MD5:1A50997B6F22E36D2E1849D1D95D0882
                                                                                                                                                                                                                                  SHA1:F4AC3ABBEA4A67013F4DC52A04616152C4C639A9
                                                                                                                                                                                                                                  SHA-256:C94C64BF06FDE0A88F24C435A52BDDE0C5C70F383CD09C62D7E42EAB2C54DD2C
                                                                                                                                                                                                                                  SHA-512:CCBD66449983844B3DB440442892004D070E5F0DFF454B25C681E13EB2F25F6359D0221CE5FF7800AC794A32D4474FE1126EA2465DB83707FF7496A1B39E6E1A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Honolulu)]} {. LoadTimeZoneFile Pacific/Honolulu.}.set TZData(:SystemV/HST10) $TZData(:Pacific/Honolulu).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.953801751537501
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqx0utLaDvFVAIg20utLPtkRgFfh4IAcGEutLNn:SlSNJB9IZaM3y7O+FVAIgpObtkch490u
                                                                                                                                                                                                                                  MD5:2B415F2251BE08F1035962CE2A04149F
                                                                                                                                                                                                                                  SHA1:EFF5CE7CD0A0CBCF366AC531D168CCB2B7C46734
                                                                                                                                                                                                                                  SHA-256:569819420F44D127693C6E536CAC77410D751A331268D0C059A1898C0E219CF4
                                                                                                                                                                                                                                  SHA-512:971F1763558D8AC17753C01B7BB64E947C448AA29951064ED7C5997D4B4A652C7F5D7C2CB4F8040F73AD83D7E49B491B93047A06D8C699F33B08F4A064BE0DCC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Phoenix)]} {. LoadTimeZoneFile America/Phoenix.}.set TZData(:SystemV/MST7) $TZData(:America/Phoenix).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.909831110037175
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqx06RGFwVAIg206RAO0LkRMMFfh4IAcGE6Ru:SlSNJB9IZaM3y7+SwVAIgp+iLkD490+u
                                                                                                                                                                                                                                  MD5:895E9BAF5EDF0928D4962C3E6650D843
                                                                                                                                                                                                                                  SHA1:52513BFA267CA2E84FDDF3C252A4E8FD059F2847
                                                                                                                                                                                                                                  SHA-256:465A4DE93F2B103981A54827CDEBB10350A385515BB8648D493FD376AABD40AF
                                                                                                                                                                                                                                  SHA-512:CAF19320F0F507160E024C37E26987A99F2276622F2A6D8D1B7E3068E5459960840F4202FF8A98738B9BCA0F42451304FC136CBD36BBFE39F616622217AD89A3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Denver)]} {. LoadTimeZoneFile America/Denver.}.set TZData(:SystemV/MST7MDT) $TZData(:America/Denver).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):187
                                                                                                                                                                                                                                  Entropy (8bit):4.782387645904801
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqTQGuQTWLM4YkvFVAIgObTuQTWLvqtkRQB5nUDHuQTWi:SlSNJB9IZaM3yciQyLM4YmFVAIgObiQq
                                                                                                                                                                                                                                  MD5:67AE3FD76B2202F3B1CF0BBC664DE8D0
                                                                                                                                                                                                                                  SHA1:4603DE0753B684A8D7ACB78A6164D5686542EE8E
                                                                                                                                                                                                                                  SHA-256:30B3FC95A7CB0A6AC586BADF47E9EFA4498995C58B80A03DA2F1F3E8A2F3553B
                                                                                                                                                                                                                                  SHA-512:BF45D0CA674DD631D3E8442DFB333812B5B31DE61576B8BE33B94E0433936BC1CD568D9FC522C84551E770660BE2A98F45FE3DB4B6577968DF57071795B53AD9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Pitcairn)]} {. LoadTimeZoneFile Pacific/Pitcairn.}.set TZData(:SystemV/PST8) $TZData(:Pacific/Pitcairn).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):199
                                                                                                                                                                                                                                  Entropy (8bit):4.959254419324467
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSNJB9IZaM3y7DvwFVAIgpdJLkQ1p490Dvn:JBaIMYFpdJLh090z
                                                                                                                                                                                                                                  MD5:DFB48E0E2CE5D55DC60B3E95B7D12813
                                                                                                                                                                                                                                  SHA1:535E0BF050E41DCFCE08686AFDFAFF9AAFEF220C
                                                                                                                                                                                                                                  SHA-256:74096A41C38F6E0641934C84563277EBA33C5159C7C564C7FF316D050083DD6D
                                                                                                                                                                                                                                  SHA-512:3ECDF3950ED3FB3123D6C1389A2A877842B90F677873A0C106C4CA6B180EEC38A26C74E21E8A3036DA8980FF7CA9E1578B0E1D1A3EA364A4175772F468747425
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Los_Angeles)]} {. LoadTimeZoneFile America/Los_Angeles.}.set TZData(:SystemV/PST8PDT) $TZData(:America/Los_Angeles).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.905971098884841
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFLLJJT8QFCZaMuUyqTQG5hB5pVAIgObT5hBiLkRKlUDH5hBun:SlSNJB9IZaM3ycTpVAIgOb4LkK
                                                                                                                                                                                                                                  MD5:CED0A343EF3A316902A10467B2F66B9B
                                                                                                                                                                                                                                  SHA1:5884E6BA28FD71A944CA2ED9CB118B9E108EF7CB
                                                                                                                                                                                                                                  SHA-256:1BB5A98B80989539135EAB3885BBA20B1E113C19CB664FB2DA6B150DD1F44F68
                                                                                                                                                                                                                                  SHA-512:903D1DC6D1E192D4A98B84247037AE171804D250BB5CB84D2C5E145A0BDC50FCD543B70BAFF8440AFF59DA14084C8CEEFB2F912A02B36B7571B0EEEC154983B3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Gambier)]} {. LoadTimeZoneFile Pacific/Gambier.}.set TZData(:SystemV/YST9) $TZData(:Pacific/Gambier).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):193
                                                                                                                                                                                                                                  Entropy (8bit):4.949109665596263
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSNJB9IZaM3y7/9EtDvFVAIgp/9EmLkB490/9E6:JBaIMY/944p/9xLN90/9F
                                                                                                                                                                                                                                  MD5:D588930E34CF0A03EFEE7BFBC5022BC3
                                                                                                                                                                                                                                  SHA1:0714C6ECAAF7B4D23272443E5E401CE141735E78
                                                                                                                                                                                                                                  SHA-256:4D1CAE3C453090667549AB83A8DE6F9B654AAC5F540192886E5756A01D21A253
                                                                                                                                                                                                                                  SHA-512:ABE69BEF808D7B0BEF9F49804D4A753E033D7C99A7EA57745FE4C3CBE2C26114A8845A219ED6DEAB8FA009FDB86E384687068C1BCF8B704CCF24DA7029455802
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by ../tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Anchorage)]} {. LoadTimeZoneFile America/Anchorage.}.set TZData(:SystemV/YST9YDT) $TZData(:America/Anchorage).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):175
                                                                                                                                                                                                                                  Entropy (8bit):4.882090609090058
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxV0XaDvFVAIgoq3XPHtjCl1yQaqXNn:SlSWB9IZaM3ymQazFVAIgoQPHtSymN
                                                                                                                                                                                                                                  MD5:41703ED241199F0588E1FC6FF0F33E90
                                                                                                                                                                                                                                  SHA1:08B4785E21E21DFE333766A7198C325CD062347B
                                                                                                                                                                                                                                  SHA-256:4B8A8CE69EE94D7E1D49A2E00E2944675B66BD16302FE90E9020845767B0509B
                                                                                                                                                                                                                                  SHA-512:F90F6B0002274AF57B2749262E1530E21906162E4D1F3BE89639B5449269F3026A7F710C24765E913BC23DEC5A6BF97FC0DD465972892D851B6EAEEF025846CA
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Istanbul)]} {. LoadTimeZoneFile Europe/Istanbul.}.set TZData(:Turkey) $TZData(:Europe/Istanbul).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):148
                                                                                                                                                                                                                                  Entropy (8bit):4.792993822845485
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqAmMwFVAIghO6iGMFfh8RS:SlSWB9IZaM3y1wFVAIghFiP8RS
                                                                                                                                                                                                                                  MD5:1921CC58408AD2D7ED3B5308C71B1A28
                                                                                                                                                                                                                                  SHA1:12F832D7B3682DC28A49481B8FBA8C55DCDC60D0
                                                                                                                                                                                                                                  SHA-256:92FC6E3AA418F94C486CE5BF6861FAA4E85047189E98B90DA78D814810E88CE7
                                                                                                                                                                                                                                  SHA-512:EB134E2E7F7A811BFA8223EB4E98A94905EA24891FD95AB29B52DE2F683C97E086AA2F7B2EA93FBA2451AAEDD22F01219D700812DABC7D6670028ACF9AAB8367
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/UCT)]} {. LoadTimeZoneFile Etc/UCT.}.set TZData(:UCT) $TZData(:Etc/UCT).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):184
                                                                                                                                                                                                                                  Entropy (8bit):4.864166947846424
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0/VXEtDvFVAIg20/VXE0JLiOGl0IAcGE/VXE6n:SlSWB9IZaM3y7/9EtDvFVAIgp/9EmLiB
                                                                                                                                                                                                                                  MD5:0763082FF8721616592350D8372D59FF
                                                                                                                                                                                                                                  SHA1:CEBB03EB7F44530CF52DCA7D55DC912015604D94
                                                                                                                                                                                                                                  SHA-256:94FDFE2901596FC5DCE74A5560431F3E777AE1EBEEE59712393AE2323F17ADFA
                                                                                                                                                                                                                                  SHA-512:DFE8AAA009C28C209A925BBE5509589C0087F6CC78F94763BFA9F1F311427E3FF2E377EB340590383D790D3578C1BB37D41525408D027763EA96ECB3A3AAD65D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Anchorage)]} {. LoadTimeZoneFile America/Anchorage.}.set TZData(:US/Alaska) $TZData(:America/Anchorage).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):171
                                                                                                                                                                                                                                  Entropy (8bit):4.839824852896375
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0/yO5pVAIg20/yOvYvtiObMEIB/4IAcGE/yOun:SlSWB9IZaM3y7/ykVAIgp/y9FitE8/47
                                                                                                                                                                                                                                  MD5:01142938A2E5F30FADE20294C829C116
                                                                                                                                                                                                                                  SHA1:8F9317E0D3836AF916ED5530176C2BF7A929C3C7
                                                                                                                                                                                                                                  SHA-256:1DD79263FB253217C36A9E7DDCB2B3F35F208E2CE812DCDE5FD924593472E4FE
                                                                                                                                                                                                                                  SHA-512:2C47FE8E8ED0833F4724EF353A9A6DFCE3B6614DA744E64364E9AB423EC92565FEF1E8940CB12A0BCCFE0BD6B44583AF230A4ABCC0BAE3D9DC43FBB2C7941CFF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Adak)]} {. LoadTimeZoneFile America/Adak.}.set TZData(:US/Aleutian) $TZData(:America/Adak).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.886225611026426
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0utLaDvFVAIg20utLPtiQMfQfBx+IAcGEutLNn:SlSWB9IZaM3y7O+FVAIgpObtiZfQfH+v
                                                                                                                                                                                                                                  MD5:090DC30F7914D5A5B0033586F3158384
                                                                                                                                                                                                                                  SHA1:2F526A63A1C47F88E320BE1C12CA8887DA2DC989
                                                                                                                                                                                                                                  SHA-256:47D25266ABBD752D61903C903ED3E9CB485A7C01BD2AA354C5B50DEBC253E01A
                                                                                                                                                                                                                                  SHA-512:5FE75328595B5DECDAC8D318BEE89EAD744A881898A4B45DD2ABB5344B13D8AFB180E4A8F8D098A9589488D9379B0153CBC5CF638AF7011DE89C57B554F42757
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Phoenix)]} {. LoadTimeZoneFile America/Phoenix.}.set TZData(:US/Arizona) $TZData(:America/Phoenix).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):179
                                                                                                                                                                                                                                  Entropy (8bit):4.854450230853601
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx096dVAIg2096zAtibXgox/h4IAcGE96s:SlSWB9IZaM3y796dVAIgp96WiB49096s
                                                                                                                                                                                                                                  MD5:E0801B5A57F40D42E8AF6D48C2A41467
                                                                                                                                                                                                                                  SHA1:A49456A1BF1B73C6B284E0764AEAFD1464E70DDC
                                                                                                                                                                                                                                  SHA-256:16C7FFCE60495E5B0CB65D6D5A0C3C5AA9E62BD6BC067ABD3CD0F691DA41C952
                                                                                                                                                                                                                                  SHA-512:3DE6A41B88D6485FD1DED2DB9AB9DAD87B9F9F95AA929D38BF6498FC0FD76A1048CE1B68F24CD22C487073F59BD955AFCB9B7BF3B20090F81FA250A5E7674A53
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Chicago)]} {. LoadTimeZoneFile America/Chicago.}.set TZData(:US/Central) $TZData(:America/Chicago).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):223
                                                                                                                                                                                                                                  Entropy (8bit):4.715837665658945
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y73GK7mFVAIgp3GKBLi3E0903GK1:MBaIMY3GK7Hp3GKBLi3t903GK1
                                                                                                                                                                                                                                  MD5:1A27644D1BF2299B7CDDED7F405D6570
                                                                                                                                                                                                                                  SHA1:BD03290A6E7A967152E2E4F95A82E01E7C35F63C
                                                                                                                                                                                                                                  SHA-256:1C46FAEDFACEB862B2E4D5BD6AC63E5182E1E2CFD2E1CDFA2661D698CC8B0072
                                                                                                                                                                                                                                  SHA-512:9D6F3E945656DD97A7E956886C1123B298A87704D4F5671E4D1E94531C01F8BE377D83239D8BE78E2B3E1C0C20E5779BA3978F817A6982FE607A18A7FDCF57FB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Indiana/Indianapolis)]} {. LoadTimeZoneFile America/Indiana/Indianapolis.}.set TZData(:US/East-Indiana) $TZData(:America/Indiana/Indianapolis).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):182
                                                                                                                                                                                                                                  Entropy (8bit):4.990255962392122
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0wAy0vwVAIg20wAyati37oxp4IAcGEwAy0v:SlSWB9IZaM3y71KVAIgp1Bi37oxp490n
                                                                                                                                                                                                                                  MD5:3FE03D768F8E535506D92A6BC3C03FD2
                                                                                                                                                                                                                                  SHA1:F82BF149CE203B5A4A1E106A495D3409AF7A07AC
                                                                                                                                                                                                                                  SHA-256:9F46C0E46F6FE26719E2CF1FA05C7646530B65FB17D4101258D357568C489D77
                                                                                                                                                                                                                                  SHA-512:ADFDBB270113A192B2378CC347DD8A57FDBDC776B06F9E16033EE8D5EAB49E16234CA2523580EEBB4DCDD27F33222EDD5514F0D7D85723597F059C5D6131E1B0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/New_York)]} {. LoadTimeZoneFile America/New_York.}.set TZData(:US/Eastern) $TZData(:America/New_York).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):181
                                                                                                                                                                                                                                  Entropy (8bit):4.832149382727646
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQG2fWGYFedVAIgObT2fWzvNioMN75nUDH2fWRn:SlSWB9IZaM3yc6e8dVAIgOb6ezvNioEe
                                                                                                                                                                                                                                  MD5:347E51049A05224D18F264D08F360CBB
                                                                                                                                                                                                                                  SHA1:A801725A9B01B5E08C63BD2568C8F5D084F0EB02
                                                                                                                                                                                                                                  SHA-256:EA5D18E4A7505406D6027AD34395297BCF5E3290283C7CC28B4A34DB8AFBDD97
                                                                                                                                                                                                                                  SHA-512:C9B96C005D90DD8F317A697F59393D20663DE74D6E4D0B45BCE109B31A328D7AA62C51FAA8D00C728C0342940EF3B0F0921814B31BD7FE128A6E95F92CF50E06
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Honolulu)]} {. LoadTimeZoneFile Pacific/Honolulu.}.set TZData(:US/Hawaii) $TZData(:Pacific/Honolulu).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):201
                                                                                                                                                                                                                                  Entropy (8bit):4.825742972037525
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y73GKXFVAIgp3GK4NiGIfh4903GKk:MBaIMY3GKXQp3GKeiBfh4903GKk
                                                                                                                                                                                                                                  MD5:E111813F4C9B888427B8363949C87C72
                                                                                                                                                                                                                                  SHA1:96B6692DCD932DCC856804BE0C2145538C4B2B33
                                                                                                                                                                                                                                  SHA-256:4E896634F3A400786BBD996D1FE0D5C9A346E337027B240F1671A7E4B38C8F69
                                                                                                                                                                                                                                  SHA-512:97726D7EDB7D7A1F6E815A0B875CAF9E2D2D27F50ECC866FBC6CB1B88836E8C2D64A9C108CD917C9D641B30822397664A2AC8010EADF0FF2A6C205AE4D5E7A2F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Indiana/Knox)]} {. LoadTimeZoneFile America/Indiana/Knox.}.set TZData(:US/Indiana-Starke) $TZData(:America/Indiana/Knox).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):180
                                                                                                                                                                                                                                  Entropy (8bit):4.7846496799669405
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx06FQGFwVAIg206FQN6iHaMCELMr4IAcGE6FQu:SlSWB9IZaM3y74PFwVAIgp4xiHaMHL+U
                                                                                                                                                                                                                                  MD5:80A9A00EC1C5904A67DC3E8B2FDC3150
                                                                                                                                                                                                                                  SHA1:8E79FBEB49D9620E793E4976D0B9085E32C57E83
                                                                                                                                                                                                                                  SHA-256:8DB76FC871DD334DA87297660B145F8692AD053B352A19C2EFCD74AF923D762D
                                                                                                                                                                                                                                  SHA-512:0A5662E33C60030265ECAD1FF683B18F6B99543CA5FE22F88BCE597702FBEA20358BCB9A568D7F8B32158D9E6A3D294081D183644AD49C22AC3512F97BE480D4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Detroit)]} {. LoadTimeZoneFile America/Detroit.}.set TZData(:US/Michigan) $TZData(:America/Detroit).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):177
                                                                                                                                                                                                                                  Entropy (8bit):4.84430947557215
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx06RGFwVAIg206RAO0LiBOlLo/4IAcGE6Ru:SlSWB9IZaM3y7+SwVAIgp+iLiBY8/49G
                                                                                                                                                                                                                                  MD5:13D6C7CF459995691E37741ACAF0A18D
                                                                                                                                                                                                                                  SHA1:A0626763930C282DF21ED3AA8F1B35033BA2F9DC
                                                                                                                                                                                                                                  SHA-256:223B5C8E34F459D7B221B83C45DBB2827ABE376653BAA1BC56D09D50DF136B08
                                                                                                                                                                                                                                  SHA-512:9076DFECC5D02DB38ECE3D2512D52566675D98A857711676E891D8741EA588153954357FE19F4C69305FF05D0F99286F1D496DF0C7FDBC8D59803D1B1CFA5F07
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Denver)]} {. LoadTimeZoneFile America/Denver.}.set TZData(:US/Mountain) $TZData(:America/Denver).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):191
                                                                                                                                                                                                                                  Entropy (8bit):4.885594237758327
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqx0ydJg4owFVAIg20ydJEvRLiP+e2IAcGEydJgvn:SlSWB9IZaM3y7DvwFVAIgpdJLip290Dv
                                                                                                                                                                                                                                  MD5:EBF51CD015BD387FA2BB30DE8806BDDA
                                                                                                                                                                                                                                  SHA1:63C2E2F4CD8BC719A06D59EF4CE4C31F17F53EA0
                                                                                                                                                                                                                                  SHA-256:B7AD78FB955E267C0D75B5F7279071EE17B6DD2842DAD61ADA0165129ADE6A86
                                                                                                                                                                                                                                  SHA-512:22BECE2AEAD66D921F38B04FDC5A41F2627FCC532A171EA1C9C9457C22CD79EFD1EC3C7CC62BC016751208AD1D064B0F03C2185F096982F73740D8426495F5ED
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Los_Angeles)]} {. LoadTimeZoneFile America/Los_Angeles.}.set TZData(:US/Pacific) $TZData(:America/Los_Angeles).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):195
                                                                                                                                                                                                                                  Entropy (8bit):4.931883193402467
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:SlSWB9IZaM3y7DvwFVAIgpdJLi0Q90Dvn:MBaIMYFpdJLix90z
                                                                                                                                                                                                                                  MD5:01CD3EBFDB7715805572CDA3F81AC78A
                                                                                                                                                                                                                                  SHA1:C013C38D2FB9E649EE43FED6910382150C2B3DF5
                                                                                                                                                                                                                                  SHA-256:DEFE67C520303EF85B381EBEAED4511C0ACF8C49922519023C525E6A1B09B9DD
                                                                                                                                                                                                                                  SHA-512:266F35C34001CD4FF00F51F5CDF05E1F4D0B037F276EFD2D124C8AE3391D00128416D16D886B3ECDF9E9EFC81C66B2FD4ED55F154437ED5AA32876B855289190
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(America/Los_Angeles)]} {. LoadTimeZoneFile America/Los_Angeles.}.set TZData(:US/Pacific-New) $TZData(:America/Los_Angeles).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):183
                                                                                                                                                                                                                                  Entropy (8bit):4.789322986138067
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqTQGurKeTIVAIgObTurKeUAti6A5nUDHurKeTv:SlSWB9IZaM3ycieZVAIgObieiidXeg
                                                                                                                                                                                                                                  MD5:E883D478518F6DAF8173361A8D308D34
                                                                                                                                                                                                                                  SHA1:ABD97858655B0069BFD5E11DD95BF6D7C2109AEA
                                                                                                                                                                                                                                  SHA-256:DD4B1812A309F90ABBD001C3C73CC2AF1D4116128787DE961453CCBE53EC9B6A
                                                                                                                                                                                                                                  SHA-512:DA1FE6D92424404111CBB18CA39C8E29FA1F9D2FD262D46231FB7A1A78D79D00F92F5D1DEBB9B92565D1E3BA03EF20D2A44B76BA0FC8B257A601EED5976386CC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Pacific/Pago_Pago)]} {. LoadTimeZoneFile Pacific/Pago_Pago.}.set TZData(:US/Samoa) $TZData(:Pacific/Pago_Pago).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):148
                                                                                                                                                                                                                                  Entropy (8bit):4.792993822845485
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqAxmSwFVAIgESRLiLB5h8RFu:SlSWB9IZaM3yzUFVAIgBLiLfh8RI
                                                                                                                                                                                                                                  MD5:530F5381F9CD8542ED5690E47FC83358
                                                                                                                                                                                                                                  SHA1:29A065F004F23A5E3606C2DB50DC0AB28CAFC785
                                                                                                                                                                                                                                  SHA-256:AC0FF734DA267E5F20AB573DBD8C0BD7613B84D86FDA3C0809832F848E142BC8
                                                                                                                                                                                                                                  SHA-512:4328BDFD6AA935FD539EE2D4A3EBA8DD2A1BD9F44BA0CF30AA0C4EA57B0A58E3CDFAA312366A0F93766AE445E6E210EE57CD5ED60F74173EDF67C1C5CB987C68
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/UTC)]} {. LoadTimeZoneFile Etc/UTC.}.set TZData(:UTC) $TZData(:Etc/UTC).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):154
                                                                                                                                                                                                                                  Entropy (8bit):4.829496870339919
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqAxmSwFVAIgESRLiL7DJMFfh8RFu:SlSWB9IZaM3yzUFVAIgBLiL7VMr8RI
                                                                                                                                                                                                                                  MD5:60878BB8E8BE290911CAB2A16AAFAEF7
                                                                                                                                                                                                                                  SHA1:15C01523EDA134D3E38ECC0A5909A4579BD2A00D
                                                                                                                                                                                                                                  SHA-256:9324B6C871AC55771C44B82BF4A92AE0BE3B2CC64EBA9FE878571225FD38F818
                                                                                                                                                                                                                                  SHA-512:C697401F1C979F5A4D33E1026DCE5C77603E56A48405511A09D8CE178F1BF47D60F217E7897061F71CFEA63CC041E64340EF6BAEE0EB037AFD34C71BF0591E3E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/UTC)]} {. LoadTimeZoneFile Etc/UTC.}.set TZData(:Universal) $TZData(:Etc/UTC).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):167
                                                                                                                                                                                                                                  Entropy (8bit):4.9534620854837295
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqxVwTwpVAIgoqzTcYFgIuyQauTnn:SlSWB9IZaM3ymdVAIgohYFgXymn
                                                                                                                                                                                                                                  MD5:58FBF79D86DBCFF53F74BF7FE5C12DD6
                                                                                                                                                                                                                                  SHA1:EA8B3317B012A661B3BA4A1FAE0DC5DEDC03BC26
                                                                                                                                                                                                                                  SHA-256:0DECFEACCE2E2D88C29CB696E7974F89A687084B3DB9564CDED6FC97BCD74E1F
                                                                                                                                                                                                                                  SHA-512:083B449DE987A634F7199666F9C685EADD643C2C2DD9C8F6C188388266729CE0179F9DC0CD432D713E5FB1649D0AA1A066FE616FC43DA65C4CD787D8E0DE00A6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Europe/Moscow)]} {. LoadTimeZoneFile Europe/Moscow.}.set TZData(:W-SU) $TZData(:Europe/Moscow).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6694
                                                                                                                                                                                                                                  Entropy (8bit):3.6896780927557495
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:D6U5vo30NSfAewvtj544IrvfMS4pBs6nLUxZlJFXmA3SG7iL8malvkUEYo4Q:5PIMj544IrvfMsbxZTH7qwQ
                                                                                                                                                                                                                                  MD5:CD86A6ED164FEB33535D74DF52DC49A5
                                                                                                                                                                                                                                  SHA1:89843BF23AB113847DCC576990A4FF2CABCA03FE
                                                                                                                                                                                                                                  SHA-256:AF28754C77BA41712E9C49EF3C9E08F7D43812E3317AD4E2192E971AD2C9B02D
                                                                                                                                                                                                                                  SHA-512:80C0A7C3BDD458CA4C1505B2144A3AD969F7B2F2732CCBE4E773FBB6ED446C2961E0B5AFFBC124D43CE9AB530C42C8AEC7100E7817566629CE9D01AC057E3549
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit..set TZData(:WET) {. {-9223372036854775808 0 0 WET}. {228877200 3600 1 WEST}. {243997200 0 0 WET}. {260326800 3600 1 WEST}. {276051600 0 0 WET}. {291776400 3600 1 WEST}. {307501200 0 0 WET}. {323830800 3600 1 WEST}. {338950800 0 0 WET}. {354675600 3600 1 WEST}. {370400400 0 0 WET}. {386125200 3600 1 WEST}. {401850000 0 0 WET}. {417574800 3600 1 WEST}. {433299600 0 0 WET}. {449024400 3600 1 WEST}. {465354000 0 0 WET}. {481078800 3600 1 WEST}. {496803600 0 0 WET}. {512528400 3600 1 WEST}. {528253200 0 0 WET}. {543978000 3600 1 WEST}. {559702800 0 0 WET}. {575427600 3600 1 WEST}. {591152400 0 0 WET}. {606877200 3600 1 WEST}. {622602000 0 0 WET}. {638326800 3600 1 WEST}. {654656400 0 0 WET}. {670381200 3600 1 WEST}. {686106000 0 0 WET}. {701830800 3600 1 WEST}. {717555600 0 0 WET}. {733280400 3600 1 WEST}. {749005200 0 0 WET}. {764730000 36
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):149
                                                                                                                                                                                                                                  Entropy (8bit):4.830292555237936
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:SlEVFRKvJT8QFCZaMuUyqAxmSwFVAIgESRLtaFBURFu:SlSWB9IZaM3yzUFVAIgBLYFaRI
                                                                                                                                                                                                                                  MD5:6C7C2CE174DB462A3E66D9A8B67A28EB
                                                                                                                                                                                                                                  SHA1:73B74BEBCDAEBDA4F46748BCA149BC4C7FE82722
                                                                                                                                                                                                                                  SHA-256:4472453E5346AAA1E1D4E22B87FDC5F3170AA013F894546087D0DC96D4B6EC43
                                                                                                                                                                                                                                  SHA-512:07209059E5E5EB5EE12821C1AC46922DA2715EB7D7196A478F0FA6866594D3C69F4C50006B0EE517CBF6DB07164915F976398EBBD88717A070D750D5D106BA5D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# created by tools/tclZIC.tcl - do not edit.if {![info exists TZData(Etc/UTC)]} {. LoadTimeZoneFile Etc/UTC.}.set TZData(:Zulu) $TZData(:Etc/UTC).
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4860
                                                                                                                                                                                                                                  Entropy (8bit):4.7851008522116585
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:Le+U54W37GWdh85qWdhAjgr9a+1FeS9D/CkXg6gvF9D/CYjX16AyyrGuA11/JRJZ:q+W/7GW85qW9a+P39DCd6gt9DC+6AjGN
                                                                                                                                                                                                                                  MD5:C5DA264DC0CE5669F81702170B2CDC59
                                                                                                                                                                                                                                  SHA1:FED571B893EE2DC93DAF8907195503885FFACBB6
                                                                                                                                                                                                                                  SHA-256:A5311E3640E42F7EFF5CC1A0D8AD6956F738F093B037155674D46B634542FE5F
                                                                                                                                                                                                                                  SHA-512:1F1993F1F19455F87EC9952BF7CEA00A5082BD2F2E1A417FBC4F239835F3CED6C8D5E09CDA6D1A4CD9F8A24AF174F9AB1DC7BD5E94C7A6DEE2DD9F8FE7F690FF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# word.tcl --.#.# This file defines various procedures for computing word boundaries in.# strings. This file is primarily needed so Tk text and entry widgets behave.# properly for different platforms..#.# Copyright (c) 1996 by Sun Microsystems, Inc..# Copyright (c) 1998 by Scritpics Corporation..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES...# The following variables are used to determine which characters are.# interpreted as white space...if {$::tcl_platform(platform) eq "windows"} {. # Windows style - any but a unicode space char. if {![info exists ::tcl_wordchars]} {..set ::tcl_wordchars {\S}. }. if {![info exists ::tcl_nonwordchars]} {..set ::tcl_nonwordchars {\s}. }.} else {. # Motif style - any unicode word char (number, letter, or underscore). if {![info exists ::tcl_wordchars]} {..set ::tcl_wordchars {\w}. }. if {![info exists ::tcl_nonwordchars]} {..set ::tcl_nonwo
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1468064
                                                                                                                                                                                                                                  Entropy (8bit):6.165850680457804
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24576:J7+Vm6O8hbcrckTNrkhaJVQhWnmb7u/DSe9qT03ZjLmFMoERDY5TUT/tXzddGyIK:JCQ69cYY9JVQWx/DSe9qTqJLUMPsJUT/
                                                                                                                                                                                                                                  MD5:FDC8A5D96F9576BD70AA1CADC2F21748
                                                                                                                                                                                                                                  SHA1:BAE145525A18CE7E5BC69C5F43C6044DE7B6E004
                                                                                                                                                                                                                                  SHA-256:1A6D0871BE2FA7153DE22BE008A20A5257B721657E6D4B24DA8B1F940345D0D5
                                                                                                                                                                                                                                  SHA-512:816ADA61C1FD941D10E6BB4350BAA77F520E2476058249B269802BE826BAB294A9C18EDC5D590F5ED6F8DAFED502AB7FFB29DB2F44292CB5BEDF2F5FA609F49C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........................................B................R..................Rich..................PE..d......\.........." .........J......@........................................p.......f....`.............................................@@..P>..|........{......,....L.......0...?..`................................................ ..P............................text...c........................... ..`.rdata...?... ...@..................@..@.data........`.......N..............@....pdata..,...........................@..@.rsrc....{.......|..................@..@.reloc...?...0...@..................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8246
                                                                                                                                                                                                                                  Entropy (8bit):4.8180558683809425
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:tKrjbDL5//nNFn0rBnDQQ2d4YGpFAImoYyMxZ34wNsf9GnEF5SpcJV+H//iNx:tIjL5//zC/8HLx4XKKv
                                                                                                                                                                                                                                  MD5:11D758CEF126C5C2EDFC911237DF80F2
                                                                                                                                                                                                                                  SHA1:7911EAA0A8B6630D016D15730310935909632389
                                                                                                                                                                                                                                  SHA-256:DA84D32D1B447F7FFE7BBCAC0F7586B0B6DD204717C7AE1F182C6A91510EC77B
                                                                                                                                                                                                                                  SHA-512:9E2A767FBC62622C34F468958C861EE3AFE2A63005BAD80F1637045D045E1A82FB1D2698D948D375222EBD0B92514ACE99C12DF6D9CACF75ACD03EC8057494A7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# bgerror.tcl --.#.#.Implementation of the bgerror procedure. It posts a dialog box with.#.the error message and gives the user a chance to see a more detailed.#.stack trace, and possible do something more interesting with that.#.trace (like save it to a log). This is adapted from work done by.#.Donal K. Fellows..#.# Copyright (c) 1998-2000 by Ajuba Solutions..# Copyright (c) 2007 by ActiveState Software Inc..# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>.# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>..namespace eval ::tk::dialog::error {. namespace import -force ::tk::msgcat::*. namespace export bgerror. option add *ErrorDialog.function.text [mc "Save To Log"] \..widgetDefault. option add *ErrorDialog.function.command [namespace code SaveToLog]. option add *ErrorDialog*Label.font TkCaptionFont widgetDefault. if {[tk windowingsystem] eq "aqua"} {..option add *ErrorDialog*background systemAlertBackgroundActive \...widgetDefault.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):20642
                                                                                                                                                                                                                                  Entropy (8bit):4.903366631227966
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:8zVtoY3wFnq+j4SpEdPmVmZ6/IVKuzmSaox2ESo+VtocUP5wFnq+j4SpEdPmV8ZQ:coahPSFMmfoz4oFXhPovzmToQBy0zm2m
                                                                                                                                                                                                                                  MD5:309AB5B70F664648774453BCCBE5D3CE
                                                                                                                                                                                                                                  SHA1:51BF685DEDD21DE3786FE97BC674AB85F34BD061
                                                                                                                                                                                                                                  SHA-256:0D95949CFACF0DF135A851F7330ACC9480B965DAC7361151AC67A6C667C6276D
                                                                                                                                                                                                                                  SHA-512:D5139752BD7175747A5C912761916EFB63B3C193DD133AD25D020A28883A1DEA6B04310B751F5FCBE579F392A8F5F18AE556116283B3E137B4EA11A2C536EC6B
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# button.tcl --.#.# This file defines the default bindings for Tk label, button,.# checkbutton, and radiobutton widgets and provides procedures.# that help in implementing those bindings..#.# Copyright (c) 1992-1994 The Regents of the University of California..# Copyright (c) 1994-1996 Sun Microsystems, Inc..# Copyright (c) 2002 ActiveState Corporation..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#-------------------------------------------------------------------------.# The code below creates the default class bindings for buttons..#-------------------------------------------------------------------------..if {[tk windowingsystem] eq "aqua"} {.. bind Radiobutton <Enter> {..tk::ButtonEnter %W. }. bind Radiobutton <1> {..tk::ButtonDown %W. }. bind Radiobutton <ButtonRelease-1> {..tk::ButtonUp %W. }. bind Checkbutton <Enter> {..tk::ButtonEnter %W. }. bind Checkbutton <1
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Nim source code, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9652
                                                                                                                                                                                                                                  Entropy (8bit):4.750454352074374
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:MvjK3vpIKU7JBhpZofNAieYemp8U3wNV97oZQWpopePXUsyWjocIegf6tq9jJKT4:M4viKeBQ+3M3wNwvwsFyoIegf6wO70fN
                                                                                                                                                                                                                                  MD5:E703C16058E7F783E9BB4357F81B564D
                                                                                                                                                                                                                                  SHA1:1EDA07870078FC4C3690B54BB5330A722C75AA05
                                                                                                                                                                                                                                  SHA-256:30CE631CB1CCCD20570018162C6FFEF31BAD378EF5B2DE2D982C96E65EB62EF6
                                                                                                                                                                                                                                  SHA-512:28617F8553766CA7A66F438624AFA5FD7780F93DC9EBDF9BEE865B5649228AA56A69189218FC436CEDF2E5FE3162AD88839CBF49C9CC051238A7559B5C3BA726
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# choosedir.tcl --.#.#.Choose directory dialog implementation for Unix/Mac..#.# Copyright (c) 1998-2000 by Scriptics Corporation..# All rights reserved...# Make sure the tk::dialog namespace, in which all dialogs should live, exists.namespace eval ::tk::dialog {}.namespace eval ::tk::dialog::file {}..# Make the chooseDir namespace inside the dialog namespace.namespace eval ::tk::dialog::file::chooseDir {. namespace import -force ::tk::msgcat::*.}..# ::tk::dialog::file::chooseDir:: --.#.#.Implements the TK directory selection dialog..#.# Arguments:.#.args..Options parsed by the procedure..#.proc ::tk::dialog::file::chooseDir:: {args} {. variable ::tk::Priv. set dataName __tk_choosedir. upvar ::tk::dialog::file::$dataName data. Config $dataName $args.. if {$data(-parent) eq "."} {. set w .$dataName. } else {. set w $data(-parent).$dataName. }.. # (re)create the dialog box if necessary. #. if {![winfo exists $w]} {..::tk::dialog::file::Create
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):21432
                                                                                                                                                                                                                                  Entropy (8bit):4.987740767386718
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:HDJsgeqJelEu6i1T26UYdTVDyPHxQlufbSIjVjrdOqAQBxhKN2zD5Ed9bmqU/FC6:jagJJnBfxQef9
                                                                                                                                                                                                                                  MD5:E5E462E0EE0C57B31DAEECB07D038488
                                                                                                                                                                                                                                  SHA1:E67B3410A7BCECE8B5159AB5327910038096A67B
                                                                                                                                                                                                                                  SHA-256:823F6E4BAF5D10185D990B3FBCB8BFB4D5F4B6ED62203EE229922B6B32FE39D4
                                                                                                                                                                                                                                  SHA-512:F8442F21E389FF9A3FC5BECCE8811F8554DEF94FBB8F184026396A87AEA37E8108A3E1B3C76FEA2CFBE4E81B2C5FC2BB8A60BE2B9831CC96CB25DAB177616238
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# clrpick.tcl --.#.#.Color selection dialog for platforms that do not support a.#.standard color selection dialog..#.# Copyright (c) 1996 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#.# ToDo:.#.#.(1): Find out how many free colors are left in the colormap and.#. don't allocate too many colors..#.(2): Implement HSV color selection..#..# Make sure namespaces exist.namespace eval ::tk {}.namespace eval ::tk::dialog {}.namespace eval ::tk::dialog::color {. namespace import ::tk::msgcat::*.}..# ::tk::dialog::color:: --.#.#.Create a color dialog and let the user choose a color. This function.#.should not be called directly. It is called by the tk_chooseColor.#.function when a native color selector widget does not exist.#.proc ::tk::dialog::color:: {args} {. variable ::tk::Priv. set dataName __tk__color. upvar ::tk::dialog::color::$dataName data. set w .$dataName.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8229
                                                                                                                                                                                                                                  Entropy (8bit):5.0540566175865
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:Aq7cPy5HEOjKU8QHyWpSWNRYs50asAZ5QWlO+W0WvHv/3WvWHwV7vWKpTTk:Aq7c6HJjKCyWpZNRYEVVET1rvveuHSOT
                                                                                                                                                                                                                                  MD5:427CCBD25BB1559B9B21A80131658140
                                                                                                                                                                                                                                  SHA1:B675C0C1B02A527B13AA5DE2AE5A1AA754E9815D
                                                                                                                                                                                                                                  SHA-256:586CB7A3C32566EFEB46036A19D07E91194CE8EDAF0D47F3C93BCC974E6EE3E1
                                                                                                                                                                                                                                  SHA-512:FEA82D6D7DBAF52EE1883241170BA95396EC282CDD4F682077A238B4FD9A47C4CE6F84B1B4829A86580A4AB794820E6CD4C1E98CFB7BDCE23E09B54566BD6443
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# comdlg.tcl --.#.#.Some functions needed for the common dialog boxes. Probably need to go.#.in a different file..#.# Copyright (c) 1996 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# tclParseConfigSpec --.#.#.Parses a list of "-option value" pairs. If all options and.#.values are legal, the values are stored in.#.$data($option). Otherwise an error message is returned. When.#.an error happens, the data() array may have been partially.#.modified, but all the modified members of the data(0 array are.#.guaranteed to have valid values. This is different than.#.Tk_ConfigureWidget() which does not modify the value of a.#.widget record if any error occurs..#.# Arguments:.#.# w = widget record to modify. Must be the pathname of a widget..#.# specs = {.# {-commandlineswitch resourceName ResourceClass defaultValue verifier}.# {....}.# }.#.# flags = currently unused..#.# argList
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):32784
                                                                                                                                                                                                                                  Entropy (8bit):4.906598115585926
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:GkptctbjWz4xjtyU/W1ZQWSLEwYGl7nZH5J+ry3+uQlLW44qvRHRJStCO2FfB25b:GkpeZWz4miZeG7J+rMYXaGGWFOYoV
                                                                                                                                                                                                                                  MD5:8B5B8B6D49F4CA36B8662923DCF9A46C
                                                                                                                                                                                                                                  SHA1:BCD6CA7451BDFB22311D9D54FBABB116D4A7A687
                                                                                                                                                                                                                                  SHA-256:7E1EAA998B1D661E9B4B72A4598A534B8311AB75D444525DD613EC73F8126750
                                                                                                                                                                                                                                  SHA-512:D7E20377E2FBD147A68E4B647D4F09A1894A203F2FA5435B09AD2B6998FFC2F70222BD2808B6A1D1B6A96271F04E7C7A4E6AB0EAE4C97C7C728A6645C499391F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# console.tcl --.#.# This code constructs the console window for an application. It.# can be used by non-unix systems that do not have built-in support.# for shells..#.# Copyright (c) 1995-1997 Sun Microsystems, Inc..# Copyright (c) 1998-2000 Ajuba Solutions..# Copyright (c) 2007-2008 Daniel A. Steffen <das@users.sourceforge.net>.#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# TODO: history - remember partially written command..namespace eval ::tk::console {. variable blinkTime 500 ; # msecs to blink braced range for. variable blinkRange 1 ; # enable blinking of the entire braced range. variable magicKeys 1 ; # enable brace matching and proc/var recognition. variable maxLines 600 ; # maximum # of lines buffered in console. variable showMatches 1 ; # show multiple expand matches. variable useFontchooser [llength [info command ::tk::fontchooser]]. variable inPlugi
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):6025
                                                                                                                                                                                                                                  Entropy (8bit):4.79563398407639
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:WfPQCAV8OgciKHKKcmQH+DmlYm4Kapo9mBc//IWxIb:WfPQCAVviKHKK4H+DmT4Kapo4cnDOb
                                                                                                                                                                                                                                  MD5:EAC165BD7EA915B44FAEC016250E0B06
                                                                                                                                                                                                                                  SHA1:7D205F2720E00FBDA5C0AA908CAC3F66BBC84E56
                                                                                                                                                                                                                                  SHA-256:6D7BD4A280272E7A2748555CFFFF4FCA7CC57CE611AEB2382E3C80CDD1868D22
                                                                                                                                                                                                                                  SHA-512:22D5794E1FF3B94365C560A310CC17B4A27BEA87DBF423DFB44273443477372013B19ED33E170EAB15A1F06BA9186BA2FC184A3751449E7EDC760D23A12B1666
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# dialog.tcl --.#.# This file defines the procedure tk_dialog, which creates a dialog.# box containing a bitmap, a message, and one or more buttons..#.# Copyright (c) 1992-1993 The Regents of the University of California..# Copyright (c) 1994-1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#.# ::tk_dialog:.#.# This procedure displays a dialog box, waits for a button in the dialog.# to be invoked, then returns the index of the selected button. If the.# dialog somehow gets destroyed, -1 is returned..#.# Arguments:.# w -..Window to use for dialog top-level..# title -.Title to display in dialog's decorative frame..# text -.Message to display in dialog..# bitmap -.Bitmap to display in dialog (empty string means none)..# default -.Index of button that is to display the default ring.#..(-1 means none)..# args -.One or more strings to display in buttons across the.#..bottom of t
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):16950
                                                                                                                                                                                                                                  Entropy (8bit):4.934745561122632
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:P/eFkH2fRdOnOeQod3tCAERebMIDlXVQgXwVviw:P2FDqUy8V
                                                                                                                                                                                                                                  MD5:BE28D16510EE78ECC048B2446EE9A11A
                                                                                                                                                                                                                                  SHA1:4829D6E8AB8A283209FB4738134B03B7BD768BAD
                                                                                                                                                                                                                                  SHA-256:8F57A23C5190B50FAD00BDEE9430A615EBEBFC47843E702374AE21BEB2AD8B06
                                                                                                                                                                                                                                  SHA-512:F56AF7020531249BC26D88B977BAFFC612B6566146730A681A798FF40BE9EBC04D7F80729BAFE0B9D4FAC5B0582B76F9530F3FE376D42A738C9BC4B3B442DF1F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# entry.tcl --.#.# This file defines the default bindings for Tk entry widgets and provides.# procedures that help in implementing those bindings..#.# Copyright (c) 1992-1994 The Regents of the University of California..# Copyright (c) 1994-1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#-------------------------------------------------------------------------.# Elements of tk::Priv that are used in this file:.#.# afterId -..If non-null, it means that auto-scanning is underway.#...and it gives the "after" id for the next auto-scan.#...command to be executed..# mouseMoved -..Non-zero means the mouse has moved a significant.#...amount since the button went down (so, for example,.#...start dragging out a selection)..# pressX -..X-coordinate at which the mouse button was pressed..# selectMode -..The style of selection currently underway:.#...char, word, or line..# x, y -..La
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4857
                                                                                                                                                                                                                                  Entropy (8bit):4.7675047842795895
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:mumhRUI7F2WyHm6BUyNhEf6jUHKRUI7F2WyQe6L763AcnK0/61sk2ko5AgEplauw:ERUQFU52CNRUQFpLOQIG1sk2TCLplauw
                                                                                                                                                                                                                                  MD5:7EA007F00BF194722FF144BE274C2176
                                                                                                                                                                                                                                  SHA1:6835A515E85A9E55D5A27073DAE1F1A5D7424513
                                                                                                                                                                                                                                  SHA-256:40D4E101A64B75361F763479B01207AE71535337E79CE6E162265842F6471EED
                                                                                                                                                                                                                                  SHA-512:E2520EB065296C431C71DBBD5503709CF61F93E74FE324F4F8F3FE13131D62435B1E124D38E2EC84939B92198A54B8A71DFC0A8D32F0DD94139C54068FBCAAF2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# focus.tcl --.#.# This file defines several procedures for managing the input.# focus..#.# Copyright (c) 1994-1995 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# ::tk_focusNext --.# This procedure returns the name of the next window after "w" in.# "focus order" (the window that should receive the focus next if.# Tab is typed in w). "Next" is defined by a pre-order search.# of a top-level and its non-top-level descendants, with the stacking.# order determining the order of siblings. The "-takefocus" options.# on windows determine whether or not they should be skipped..#.# Arguments:.# w -..Name of a window...proc ::tk_focusNext w {. set cur $w. while {1} {...# Descend to just before the first child of the current widget....set parent $cur..set children [winfo children $cur]..set i -1...# Look for the next sibling that isn't a top-level....while {1} {.. incr i..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):15840
                                                                                                                                                                                                                                  Entropy (8bit):4.7139053935905535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:hrAVUJgzMAP2Xg7V5M8Zyc8Ck/YN9G4EM8CPo:hrAVUJgzMAP2Xg7V5MgycO/YpEX
                                                                                                                                                                                                                                  MD5:9324DBBE37502E149474E05A3448B6E3
                                                                                                                                                                                                                                  SHA1:5584B4EE3BF25E95EE6919437D066586060B6E36
                                                                                                                                                                                                                                  SHA-256:CEB558FB76A2C85924CD5F7D3A64E77582E1D461DD9A3C10FEDB4608AD440F5B
                                                                                                                                                                                                                                  SHA-512:C688676452F89EC432E93A64AC369CC0B82B19D8D38D2C4034888551591F59D87548FAE12A98EE7735540779566DEB400C27BEAD2C141A9F971BAF9E61C218C6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# fontchooser.tcl -.#.#.A themeable Tk font selection dialog. See TIP #324..#.# Copyright (C) 2008 Keith Vetter.# Copyright (C) 2008 Pat Thoyts <patthoyts@users.sourceforge.net>.#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES...namespace eval ::tk::fontchooser {. variable S.. set S(W) .__tk__fontchooser. set S(fonts) [lsort -dictionary [font families]]. set S(styles) [list \. [::msgcat::mc "Regular"] \. [::msgcat::mc "Italic"] \. [::msgcat::mc "Bold"] \. [::msgcat::mc "Bold Italic"] \. ].. set S(sizes) {8 9 10 11 12 14 16 18 20 22 24 26 28 36 48 72}. set S(strike) 0. set S(under) 0. set S(first) 1. set S(sampletext) [::msgcat::mc "AaBbYyZz01"]. set S(-parent) .. set S(-title) [::msgcat::mc "Font"]. set S(-command) "". set S(-font) TkDefaultFont.}..proc ::tk:
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Tcl script, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):15978
                                                                                                                                                                                                                                  Entropy (8bit):4.8947909611129905
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:xj0OECzN+8JERNLKZhbgIDx3VM5BxBTSgvpn8WYYW5Xb50To3u8PYHPtJYa5PWDx:xrDJE36a7BegvV8hFI8gvXaSn9HqD/U0
                                                                                                                                                                                                                                  MD5:105529990CEE968AA5EE3BC827A81A0F
                                                                                                                                                                                                                                  SHA1:559BD1AABD1D4719EDB60448CF111F78365A57A9
                                                                                                                                                                                                                                  SHA-256:DE0195CCFB6482CCA390C94E91B7877F47742E7A9468CAF362B39AA36305D33C
                                                                                                                                                                                                                                  SHA-512:03CB42DFF7AC4F801AA7FFE8A4F07555CCE6874AA1B7F568ACF0299E4DD7F440179838485777F15183EE7C057CCB35868672B1783FBFE67B51D97DBBDAC85281
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# iconlist.tcl.#.#.Implements the icon-list megawidget used in the "Tk" standard file.#.selection dialog boxes..#.# Copyright (c) 1994-1998 Sun Microsystems, Inc..# Copyright (c) 2009 Donal K. Fellows.#.# See the file "license.terms" for information on usage and redistribution of.# this file, and for a DISCLAIMER OF ALL WARRANTIES..#.# API Summary:.#.tk::IconList <path> ?<option> <value>? ....#.<path> add <imageName> <itemList>.#.<path> cget <option>.#.<path> configure ?<option>? ?<value>? ....#.<path> deleteall.#.<path> destroy.#.<path> get <itemIndex>.#.<path> index <index>.#.<path> invoke.#.<path> see <index>.#.<path> selection anchor ?<int>?.#.<path> selection clear <first> ?<last>?.#.<path> selection get.#.<path> selection includes <item>.#.<path> selection set <first> ?<last>?...package require Tk 8.6..::tk::Megawidget create ::tk::IconList ::tk::FocusableWidget {. variable w canvas sbar accel accelCB fill font index \..itemList itemsPerColumn list maxIH maxIW maxTH maxTW noSc
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10883
                                                                                                                                                                                                                                  Entropy (8bit):6.026473720997027
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:TJjPyYK20kt4zHIXM2MxGwwOw0ac5lCssUOixDgzAjTXBHVXPZmEhr:pO2gz6MioacR2iBgzsFHX5r
                                                                                                                                                                                                                                  MD5:2652AAD862E8FE06A4EEDFB521E42B75
                                                                                                                                                                                                                                  SHA1:ED22459AD3D192AB05A01A25AF07247B89DC6440
                                                                                                                                                                                                                                  SHA-256:A78388D68600331D06BB14A4289BC1A46295F48CEC31CEFF5AE783846EA4D161
                                                                                                                                                                                                                                  SHA-512:6ECFBB8D136444A5C0DBBCE2D8A4206F1558BDD95F111D3587B095904769AC10782A9EA125D85033AD6532EDF3190E86E255AC0C0C81DC314E02D95CCA86B596
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# icons.tcl --.#.#.A set of stock icons for use in Tk dialogs. The icons used here.#.were provided by the Tango Desktop project which provides a.#.unified set of high quality icons licensed under the.#.Creative Commons Attribution Share-Alike license.#.(http://creativecommons.org/licenses/by-sa/3.0/).#.#.See http://tango.freedesktop.org/Tango_Desktop_Project.#.# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>..namespace eval ::tk::icons {}..image create photo ::tk::icons::warning -data {. iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAABHNCSVQICAgIfAhkiAAABSZJREFU. WIXll1toVEcYgL+Zc87u2Yu7MYmrWRuTJuvdiMuqiJd4yYKXgMQKVkSjFR80kFIVJfWCWlvpg4h9. 8sXGWGof8iKNICYSo6JgkCBEJRG8ImYThNrNxmaTeM7pQ5IlJkabi0/9YZhhZv7///4z/8zPgf+7. KCNRLgdlJijXwRyuDTlcxV9hbzv8nQmxMjg+XDtiOEplkG9PSfkztGmTgmFQd+FCVzwa3fYN/PHZ. AcpBaReicW5xcbb64IEQqko8Lc26d/58cxS+/BY6hmJvyEfQBoUpwWCmW1FErKaGWHU13uRk4QkE. UtxQNFR7QwIoB4eiKD9PWbVKbb10CZmaCqmpxCormRYO26QQx85B0mcD+AeK0xYvHqu1tNDx+DH6. g
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:GIF image data, version 89a, 130 x 200
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3491
                                                                                                                                                                                                                                  Entropy (8bit):7.790611381196208
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:ROGuxkQ9mcV7RXcECEtqCa+6GK8WseNXhewFIp9ZmL4u:ROGwpVOEbqCrWsUhtIk4u
                                                                                                                                                                                                                                  MD5:A5E4284D75C457F7A33587E7CE0D1D99
                                                                                                                                                                                                                                  SHA1:FA98A0FD8910DF2EFB14EDAEC038B4E391FEAB3C
                                                                                                                                                                                                                                  SHA-256:BAD9116386343F4A4C394BDB87146E49F674F687D52BB847BD9E8198FDA382CC
                                                                                                                                                                                                                                  SHA-512:4448664925D1C1D9269567905D044BBA48163745646344E08203FCEF5BA1524BA7E03A8903A53DAF7D73FE0D9D820CC9063D4DA2AA1E08EFBF58524B1D69D359
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:GIF89a................................f.................f...ff.f3.f..33.3............f..ff.3f.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,...........@.pH,...r.l:..T..F$XIe..V$.x..V.Z.z..F.pxd~..........{....o....l..{.b...hi[}P.k...y.....y.f.._R.\...............m.....y.....x......^.Q...j.....\S.....^.......l......]...[.......).....{....7...`..<...`..">..i.?/..@............>..Z.z@....0B..r...j.V.I.@..;%R...*...J.p.A.t.*..$A*...>`.....@g5BP.A..p.x.............q..8...... ...(.Q..#..@...F..YSK..M..#o.....D.m..-.....k}...BT..V......'.....`.d..~;..9+..6...<b.eZ..y^0]0..I...=.6.....}.0<.Z...M...Y1*35.e.....b...U0F~.-.HT......l2.s.q`-....y...e....dPZ....~.zT.M.... "r.E/k. ...*..Lj@'........Pcd&.(..mxF_w.."K..x!..--Y`..A.....Be.jH.A..\..j.....du#.....]^...>......].i.FMO..].9n1",Y...F...EW.9.....0TY.T...Cv!i`%...Hz@.]..U.!Y...#Dv&pi.z(.mn.A....@Q.0.%...&.4.v.cw(.`cd'|..M9..."...,*.......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:GIF image data, version 89a, 48 x 75
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1171
                                                                                                                                                                                                                                  Entropy (8bit):7.289201491091023
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:DOfHIzP8hqiF+oyPOmp3XHhPBlMVvG0ffWLpfc:DGoPM+o0OmZXHhOv5WRc
                                                                                                                                                                                                                                  MD5:7013CFC23ED23BFF3BDA4952266FA7F4
                                                                                                                                                                                                                                  SHA1:E5B1DED49095332236439538ECD9DD0B1FD4934B
                                                                                                                                                                                                                                  SHA-256:462A8FF8FD051A8100E8C6C086F497E4056ACE5B20B44791F4AAB964B010A448
                                                                                                                                                                                                                                  SHA-512:A887A5EC33B82E4DE412564E86632D9A984E8498F02D8FE081CC4AC091A68DF6CC1A82F4BF99906CFB6EA9D0EF47ADAC2D1B0778DCB997FB24E62FC7A6D77D41
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:GIF89a0.K.............................f.................f...ff.f3.f..33.3.........f..ff.f3.3f.33.3.f..ff.ff.f3ff333f.3f.33.33f.3......................................................................!.. -dl-.!.......,....0.K....@.pH,...GD.<:..%SR.Z......<.V.$l.....z......:.. .|v[D..f...z.W.G.Vr...NgsU.yl..qU..`.......`fe`.......Fg....(.&...g.Y.. .."..q.V.$.'.Ez.W....y...Y.U...(#Xrf.........Xux.U..........(U.4...X....G.B..t..1S...R..Y. ...l ..".>.h......,%K....A.....<s....#..8.iK.....a.y$h..DQh.PE)....6.....MyL.qzF..... ."..Y0..a......2..*t..Ma..b...M..R.....\..st..=....Q......,>s`....Qt.,..B.R.....!.$..%.....(...s...B.T...`,".h(. D....8..dC..\Q.p.......x.#A.....:..du..(D.XV......7....S.#n8a....2`...f.:G,...==(......`!..$...t....b..../N|...f..J.x... P&.|.d._!N...].1w.3D.0!....@o&H...N.B.J....pz8..w.i....=r.............@5.-!.......H."..[.j.AB<..p....h...V.D..6.h...ab1F.g...I !.V~.H..V.........:.G..|c...,.....TD5..c[.W.....LC.....FJ..71[..lH.M.....8.:$......
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:GIF image data, version 89a, 100 x 100
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5473
                                                                                                                                                                                                                                  Entropy (8bit):7.754239979431754
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:+EqG96vSGfyJZ26G6U1LI7nTD2enhjc+2VBnOqcUERVIim:+46KcyJI6G6uU7/LhjlkhQR7m
                                                                                                                                                                                                                                  MD5:048AFE69735F6974D2CA7384B879820C
                                                                                                                                                                                                                                  SHA1:267A9520C4390221DCE50177E789A4EBD590F484
                                                                                                                                                                                                                                  SHA-256:E538F8F4934CA6E1CE29416D292171F28E67DA6C72ED9D236BA42F37445EA41E
                                                                                                                                                                                                                                  SHA-512:201DA67A52DADA3AE7C533DE49D3C08A9465F7AA12317A0AE90A8C9C04AA69A85EC00AF2D0069023CD255DDA8768977C03C73516E4848376250E8D0D53D232CB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:GIF89ad.d...................RJJ...B99.......RBB..B11ZBB!....R991!!...)....{{B!!R)).JJ.ss.ZZ.BB.kk.RR.JJ.BB9...JJR!!.ZZ.BB.11.99.{s.sk.kc.cZ.ZR.JB.ZR.JB.JB.RJ.B9.91.B9...{.JB.91.B9.B9.1){)!.)!.9)..ZR.JB{91.cR{1).ZJ.ZJ.RB.J9.B1.B1.9).1!....{B9.{k.scc1).kZZ)!c)!.9).B1.9).9).1!.1!.1!.B).9!.9!.1..).....{.sZ1)R)!.B1.B1.ZBR!..9).ZB.9).R9.R9.1!.J1.J1.B).B).9!.9!.1..1..).....sZ.J9.ZB.cJJ!.{1!.B).9!{)..9!.J).B!.B!.9..R1).kJ)!.B1{9).R9.cB.Z9.Z9.B).Z9.B).R1.9!.R1.J).J).B!.1..9....{.s.J9.{Z.ZB.sR.kJk1!.cB.cB.R1.R).1..B!.J!.B.....R91.J1).c.kJ.J).Z1.B!.B!..9!..{R.sJ.Z9.R1{9!..s.R9.Z...J91Z9){B)...............B91..1)!..............................RJR............B)1......R19........BJ.9B..{..s{......!.......,....d.d.@............0@PHa....*.p...7.8.y...C.s6Z.%Q.#s.`:B.N....4jd.K.0..|y....F@.......1~ ......'Y.B"C&R.V.R.4$k.3...D.......Ef*Y3..M........BDV._.....\..).]..>s..$H\%y0WL...d.......D..'..v..1Kz.Zp$;S
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2267
                                                                                                                                                                                                                                  Entropy (8bit):5.097909341674822
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:JlZuZcRTvy3DauG4+bHnr32s3eGw8YKxPiOXR3ojdS+mFf:JScFaz+bL3e8n3XR3ojdtOf
                                                                                                                                                                                                                                  MD5:C88F99DECEC11AFA967AD33D314F87FE
                                                                                                                                                                                                                                  SHA1:58769F631EB2C8DED0C274AB1D399085CC7AA845
                                                                                                                                                                                                                                  SHA-256:2CDE822B93CA16AE535C954B7DFE658B4AD10DF2A193628D1B358F1765E8B198
                                                                                                                                                                                                                                  SHA-512:4CD59971A2614891B2F0E24FD8A42A706AE10A2E54402D774E5DAA5F6A37DE186F1A45B1722A7C0174F9F80625B13D7C9F48FDB03A7DDBC6E6881F56537B5478
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:This software is copyrighted by the Regents of the University of.California, Sun Microsystems, Inc., Scriptics Corporation, ActiveState.Corporation, Apple Inc. and other parties. The following terms apply to.all files associated with the software unless explicitly disclaimed in.individual files...The authors hereby grant permission to use, copy, modify, distribute,.and license this software and its documentation for any purpose, provided.that existing copyright notices are retained in all copies and that this.notice is included verbatim in any distributions. No written agreement,.license, or royalty fee is required for any of the authorized uses..Modifications to this software may be copyrighted by their authors.and need not follow the licensing terms described here, provided that.the new terms are clearly indicated on the first page of each file where.they apply...IN NO EVENT SHALL THE AUTHORS OR DISTRIBUTORS BE LIABLE TO ANY PARTY.FOR DIRECT, INDIRECT, SPECIAL, INCIDENTAL, OR CONSEQ
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):14594
                                                                                                                                                                                                                                  Entropy (8bit):4.895853767062079
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:ZBjtAc4YusFvbg36UFchqHjNw8wSdy+1a22YDE/q:ZFgqUBjW8RQcf
                                                                                                                                                                                                                                  MD5:C33963D3A512F2E728F722E584C21552
                                                                                                                                                                                                                                  SHA1:75499CFA62F2DA316915FADA2580122DC3318BAD
                                                                                                                                                                                                                                  SHA-256:39721233855E97BFA508959B6DD91E1924456E381D36FDFC845E589D82B1B0CC
                                                                                                                                                                                                                                  SHA-512:EA01D8CB36D446ACE31C5D7E50DFAE575576FD69FD5D413941EEBBA7CCC1075F6774AF3C69469CD7BAF6E1068AA5E5B4C560F550EDD2A8679124E48C55C8E8D7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# listbox.tcl --.#.# This file defines the default bindings for Tk listbox widgets.# and provides procedures that help in implementing those bindings..#.# Copyright (c) 1994 The Regents of the University of California..# Copyright (c) 1994-1995 Sun Microsystems, Inc..# Copyright (c) 1998 by Scriptics Corporation..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#--------------------------------------------------------------------------.# tk::Priv elements used in this file:.#.# afterId -..Token returned by "after" for autoscanning..# listboxPrev -.The last element to be selected or deselected.#...during a selection operation..# listboxSelection -.All of the items that were selected before the.#...current selection operation (such as a mouse.#...drag) started; used to cancel an operation..#--------------------------------------------------------------------------..#-------------------------------------
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Tcl script, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9569
                                                                                                                                                                                                                                  Entropy (8bit):4.736161258754494
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:cp4NSZKF/bcaQTViJ8pox8tJRd/v0tAANQSLkROOp+4BQjBC:jSZKF/Iaarpocdn07NQS34ao
                                                                                                                                                                                                                                  MD5:7176A4FE8EC3EA648854F1FC1BB2EA89
                                                                                                                                                                                                                                  SHA1:28D96419585881C6222BC917EDB9A5863E7C519B
                                                                                                                                                                                                                                  SHA-256:D454FC4E25D9DFC704556A689A17AA6F3D726F99592995952BC6492FC8F19F6E
                                                                                                                                                                                                                                  SHA-512:8C33E1CD3490945DDC5DA0585E655A7FC78C9950886F68C096D103AE510C1024632AB3D41E9573937BB4359D365FFB8F5A10B1CA7BFBD37442F40985107C1C8D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# megawidget.tcl.#.#.Basic megawidget support classes. Experimental for any use other than.#.the ::tk::IconList megawdget, which is itself only designed for use in.#.the Unix file dialogs..#.# Copyright (c) 2009-2010 Donal K. Fellows.#.# See the file "license.terms" for information on usage and redistribution of.# this file, and for a DISCLAIMER OF ALL WARRANTIES..#..package require Tk 8.6...::oo::class create ::tk::Megawidget {. superclass ::oo::class. method unknown {w args} {..if {[string match .* $w]} {.. [self] create $w {*}$args.. return $w..}..next $w {*}$args. }. unexport new unknown. self method create {name superclasses body} {..next $name [list \...superclass ::tk::MegawidgetClass {*}$superclasses]\;$body. }.}..::oo::class create ::tk::MegawidgetClass {. variable w hull options IdleCallbacks. constructor args {..# Extract the "widget name" from the object name..set w [namespace tail [self]]...# Configure things..tclParseConfigSpec [my varname op
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):38077
                                                                                                                                                                                                                                  Entropy (8bit):4.872052715667624
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:0K5IzCPGH0a9tVbQDBTo06DpSCeihpzuxdyQYEuH9DAe1:0K5i1HDE6AWuxdRYxHS8
                                                                                                                                                                                                                                  MD5:181ED74919F081EEB34269500E228470
                                                                                                                                                                                                                                  SHA1:953EB429F6D98562468327858ED0967BDC21B5AD
                                                                                                                                                                                                                                  SHA-256:564AC0040176CC5744E3860ABC36B5FFBC648DA20B26A710DC3414EAE487299B
                                                                                                                                                                                                                                  SHA-512:220E496B464575115BAF1DEDE838E70D5DDD6D199B5B8ACC1763E66D66801021B2D7CD0E1E1846868782116AD8A1F127682073D6EACD7E73F91BCED89F620109
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# menu.tcl --.#.# This file defines the default bindings for Tk menus and menubuttons..# It also implements keyboard traversal of menus and implements a few.# other utility procedures related to menus..#.# Copyright (c) 1992-1994 The Regents of the University of California..# Copyright (c) 1994-1997 Sun Microsystems, Inc..# Copyright (c) 1998-1999 by Scriptics Corporation..# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>.#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#-------------------------------------------------------------------------.# Elements of tk::Priv that are used in this file:.#.# cursor -..Saves the -cursor option for the posted menubutton..# focus -..Saves the focus during a menu selection operation..#...Focus gets restored here when the menu is unposted..# grabGlobal -..Used in conjunction with tk::Priv(oldGrab): if.#...tk::Priv(oldGrab) is non-empty, then tk::Pr
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):29352
                                                                                                                                                                                                                                  Entropy (8bit):5.110577585375791
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:hmie+xwcBO/SHAqFySrhkvQueYpx8DPF52qdREXXZ2/OODi:I+xwcBO/SHAqFySrhAQueYD8D95TOL
                                                                                                                                                                                                                                  MD5:5F3793E7E582111C17C85E23194AEFD5
                                                                                                                                                                                                                                  SHA1:925D973B70252384D1DE9B388C6C2038E646FDDF
                                                                                                                                                                                                                                  SHA-256:0AC9D11D4046EF4D8E6D219F6941BF69C6AE448C6A1C2F7FC382F84B5786F660
                                                                                                                                                                                                                                  SHA-512:2922546BA69232DBC205FE83EF54916E334E7AC93B7A26A208341F9C101209DA84C73F48C52BDB8E63E71A545853652B86378EBEB88F000BC16FCFB0EF5D8517
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# mkpsenc.tcl --.#.# This file generates the postscript prolog used by Tk...namespace eval ::tk {. # Creates Postscript encoding vector for ISO-8859-1 (could theoretically. # handle any 8-bit encoding, but Tk never generates characters outside. # ASCII).. #. proc CreatePostscriptEncoding {} {..variable psglyphs..# Now check for known. Even if it is known, it can be other than we..# need. GhostScript seems to be happy with such approach..set result "\[\n"..for {set i 0} {$i<256} {incr i 8} {.. for {set j 0} {$j<8} {incr j} {...set enc [encoding convertfrom "iso8859-1" \....[format %c [expr {$i+$j}]]]...catch {... set hexcode {}... set hexcode [format %04X [scan $enc %c]]...}...if {[info exists psglyphs($hexcode)]} {... append result "/$psglyphs($hexcode)"...} else {... append result "/space"...}.. }.. append result "\n"..}..append result "\]"..return $result. }.. # List of adobe glyph names. Converted from glyphlist.txt, downloaded from. # Ad
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:xbm image (32x, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):16527
                                                                                                                                                                                                                                  Entropy (8bit):4.679051291122852
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:aWsDPYblrrfcRcfjAwnAVDTS3ifQjvwMXEcjY:aTRcfjAwGTfQjvPXt0
                                                                                                                                                                                                                                  MD5:C93F295967350F7010207874992E01A5
                                                                                                                                                                                                                                  SHA1:CAE8EF749F7618326B3307DA7ED6DEBB380286DD
                                                                                                                                                                                                                                  SHA-256:52C5B87C99C142D5FC77E0C22B78B7CD63A4861756FD6B39648A2E9A8EDDE953
                                                                                                                                                                                                                                  SHA-512:F7E60211C0BC1ECEDE03022D622C5B9AAEAE3C203A60B6B034E1886F857C8FAD6BA6B1F7BA1EE7D733720775E7108F1BFD4C5B54A0F4919CE4EB43851D1190F8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# msgbox.tcl --.#.#.Implements messageboxes for platforms that do not have native.#.messagebox support..#.# Copyright (c) 1994-1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# Ensure existence of ::tk::dialog namespace.#.namespace eval ::tk::dialog {}..image create bitmap ::tk::dialog::b1 -foreground black \.-data "#define b1_width 32\n#define b1_height 32.static unsigned char q1_bits[] = {. 0x00, 0xf8, 0x1f, 0x00, 0x00, 0x07, 0xe0, 0x00, 0xc0, 0x00, 0x00, 0x03,. 0x20, 0x00, 0x00, 0x04, 0x10, 0x00, 0x00, 0x08, 0x08, 0x00, 0x00, 0x10,. 0x04, 0x00, 0x00, 0x20, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,. 0x01, 0x00, 0x00, 0x80, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,. 0x04, 0x00, 0x00, 0x20, 0x08, 0x00,
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4158
                                                                                                                                                                                                                                  Entropy (8bit):4.744283779865612
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:RC98Kz+4GgKafRXwSl51gmJnANlsgPVG5QOFWQfl5:RC98/4PGi51gmAsgPVjm5
                                                                                                                                                                                                                                  MD5:EBAFA3EE899EBB06D52C204493CEE27A
                                                                                                                                                                                                                                  SHA1:95E6C71E4525A8DD91E488B952665AE9C5FBDDED
                                                                                                                                                                                                                                  SHA-256:D1B0FED0BEA51B3FAF08D8634034C7388BE7148F9B807460B7D185706DB8416F
                                                                                                                                                                                                                                  SHA-512:ADDE3C85A7A4148BAFD6C8B8902FC8C229F1D1AAF118BE85F44E4667237E66938864E2B7B4486B7C68C89EB4559F1D8367F9F563B9C6C8BCAB66118B36E670B8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset cs "&Abort" "&P\u0159eru\u0161it". ::msgcat::mcset cs "&About..." "&O programu...". ::msgcat::mcset cs "All Files" "V\u0161echny soubory". ::msgcat::mcset cs "Application Error" "Chyba programu". ::msgcat::mcset cs "Bold Italic". ::msgcat::mcset cs "&Blue" "&Modr\341". ::msgcat::mcset cs "Cancel" "Zru\u0161it". ::msgcat::mcset cs "&Cancel" "&Zru\u0161it". ::msgcat::mcset cs "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nemohu zm\u011bnit atku\341ln\355 adres\341\u0159 na \"%1\$s\".\nP\u0159\355stup odm\355tnut.". ::msgcat::mcset cs "Choose Directory" "V\375b\u011br adres\341\u0159e". ::msgcat::mcset cs "Cl&ear" "Sma&zat". ::msgcat::mcset cs "&Clear Console" "&Smazat konzolu". ::msgcat::mcset cs "Color" "Barva". ::msgcat::mcset cs "Console" "Konzole". ::msgcat::mcset cs "&Copy" "&Kop\355rovat". ::msgcat::mcset cs "Cu&t" "V&y\u0159\355znout". ::msgcat::mcset cs "&Delete" "&Smazat"
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3909
                                                                                                                                                                                                                                  Entropy (8bit):4.6030170761850915
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:G8ONjSf5s80vWCUx5kTvgXTfODYE9lAUt:G8OmB0ZUx5kTv4sbt
                                                                                                                                                                                                                                  MD5:C414C6972F0AAD5DFA31297919D0587F
                                                                                                                                                                                                                                  SHA1:529AE0B0CB9D1DBC7F8844F346149E151DE0A36B
                                                                                                                                                                                                                                  SHA-256:85E6CEE6001927376725F91EAA55D17B3D9E38643E17755A42C05FE491C63BDE
                                                                                                                                                                                                                                  SHA-512:0F2A777B9C3D6C525097E19D1CC4525E9BAF78E0CABF54DD693C64BC1FD4EA75402D906A8302489997BA83ABA5AFD7CA1DE30FFE0888CD19950F56A9D38B018A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset da "&Abort" "&Afbryd". ::msgcat::mcset da "&About..." "&Om...". ::msgcat::mcset da "All Files" "Alle filer". ::msgcat::mcset da "Application Error" "Programfejl". ::msgcat::mcset da "&Blue" "&Bl\u00E5". ::msgcat::mcset da "Cancel" "Annuller". ::msgcat::mcset da "&Cancel" "&Annuller". ::msgcat::mcset da "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ikke skifte til katalog \"%1\$s\".\nIngen rettigheder.". ::msgcat::mcset da "Choose Directory" "V\u00E6lg katalog". ::msgcat::mcset da "Cl&ear" "&Ryd". ::msgcat::mcset da "&Clear Console" "&Ryd konsolen". ::msgcat::mcset da "Color" "Farve". ::msgcat::mcset da "Console" "Konsol". ::msgcat::mcset da "&Copy" "&Kopier". ::msgcat::mcset da "Cu&t" "Kli&p". ::msgcat::mcset da "&Delete" "&Slet". ::msgcat::mcset da "Details >>" "Detailer". ::msgcat::mcset da "Directory \"%1\$s\" does not exist." "Katalog \"%1\$s\" findes ikke.". ::msg
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4823
                                                                                                                                                                                                                                  Entropy (8bit):4.5738552657551566
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:13LquGgagtG6vz8MFi9dDvbwKAN92qqMXg07Qt:L1/w5jwKYH1Et
                                                                                                                                                                                                                                  MD5:07DF877A1166E81256273F1183B5BDC9
                                                                                                                                                                                                                                  SHA1:CB455F910208E2E55B27A96ABD845FEEDA88711A
                                                                                                                                                                                                                                  SHA-256:06DD7572626DF5CB0A8D3AFFBAC9BB74CB12469076836D66FD19AE5B5FAB42C7
                                                                                                                                                                                                                                  SHA-512:197B09F37647D1D5130A084EA1D99D0CC16C815EC0AC31EC07875BEB2DFAE2197E2AF3E323FE8CB35F90912D76D3EB88D1E56F6E026F87AEDFADB7534BA2675A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset de "&Abort" "&Abbruch". ::msgcat::mcset de "&About..." "&\u00dcber...". ::msgcat::mcset de "All Files" "Alle Dateien". ::msgcat::mcset de "Application Error" "Applikationsfehler". ::msgcat::mcset de "&Apply" "&Anwenden". ::msgcat::mcset de "Bold" "Fett". ::msgcat::mcset de "Bold Italic" "Fett kursiv". ::msgcat::mcset de "&Blue" "&Blau". ::msgcat::mcset de "Cancel" "Abbruch". ::msgcat::mcset de "&Cancel" "&Abbruch". ::msgcat::mcset de "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kann nicht in das Verzeichnis \"%1\$s\" wechseln.\nKeine Rechte vorhanden.". ::msgcat::mcset de "Choose Directory" "W\u00e4hle Verzeichnis". ::msgcat::mcset de "Cl&ear" "&R\u00fccksetzen". ::msgcat::mcset de "&Clear Console" "&Konsole l\u00f6schen". ::msgcat::mcset de "Color" "Farbe". ::msgcat::mcset de "Console" "Konsole". ::msgcat::mcset de "&Copy" "&Kopieren". ::msgcat::mcset de "Cu&t" "Aus&schneid
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (355)
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8698
                                                                                                                                                                                                                                  Entropy (8bit):4.296709418881547
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:tCrF5o/cmSHbkI8+ETnFI3mC2hk9I+c6M30UPfMNDz91yBFkm5w+kGR8MOFiL0xu:wp5RmSHlsFerVIfM5Loam5VOMAkV
                                                                                                                                                                                                                                  MD5:C802EA5388476451CD76934417761AA6
                                                                                                                                                                                                                                  SHA1:25531DF6262E3B1170055735C5A874B9124FEA83
                                                                                                                                                                                                                                  SHA-256:1D56D0A7C07D34BB8165CBA47FA49351B8BC5A9DB244290B9601C5885D16155C
                                                                                                                                                                                                                                  SHA-512:251FABBE8B596C74BC1231823C60F5F99CF55A29212327723F5DBE604F678E8E464F2D604D1049754B7C02350712B83BCF4D9542D8167F3CAB9C9B7E5C88EC7D
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:## Messages for the Greek (Hellenic - "el") language..## Please report any changes/suggestions to:.## petasis@iit.demokritos.gr..namespace eval ::tk {. ::msgcat::mcset el "&Abort" "\u03a4\u03b5\u03c1\u03bc\u03b1\u03c4\u03b9\u03c3\u03bc\u03cc\u03c2". ::msgcat::mcset el "About..." "\u03a3\u03c7\u03b5\u03c4\u03b9\u03ba\u03ac...". ::msgcat::mcset el "All Files" "\u038c\u03bb\u03b1 \u03c4\u03b1 \u0391\u03c1\u03c7\u03b5\u03af\u03b1". ::msgcat::mcset el "Application Error" "\u039b\u03ac\u03b8\u03bf\u03c2 \u0395\u03c6\u03b1\u03c1\u03bc\u03bf\u03b3\u03ae\u03c2". ::msgcat::mcset el "&Blue" "\u039c\u03c0\u03bb\u03b5". ::msgcat::mcset el "&Cancel" "\u0391\u03ba\u03cd\u03c1\u03c9\u03c3\u03b7". ::msgcat::mcset el \."Cannot change to the directory \"%1\$s\".\nPermission denied." \."\u0394\u03b5\u03bd \u03b5\u03af\u03bd\u03b1\u03b9 \u03b4\u03c5\u03bd\u03b1\u03c4\u03ae \u03b7 \u03b1\u03bb\u03bb\u03b1\u03b3\u03ae \u03ba\u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3286
                                                                                                                                                                                                                                  Entropy (8bit):4.214322279125194
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:sqHa4IUXCtvLPgyq1+1ylnJzqFtC2NAXSxFFRRTDubLorIlnB:d64I5tDPgDNnH2SXSZRRTDuPZlB
                                                                                                                                                                                                                                  MD5:64725ED622DBF1CB3F00479BA84157D7
                                                                                                                                                                                                                                  SHA1:575429AEABAF6640425AC1BC397B3382C1ED1122
                                                                                                                                                                                                                                  SHA-256:673C76A48ADA09A154CB038534BF90E3B9C0BA5FD6B1619DB33507DE65553362
                                                                                                                                                                                                                                  SHA-512:4EBDCAB20D095789BB8D94476CCFD29DEE8DFCF96F1C2030387F0521827A140E22BBB0DAD4B73EABE26D70E1642C9981BC5CBBF0045FEABB9EF98C7CDB67795E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset en "&Abort". ::msgcat::mcset en "&About...". ::msgcat::mcset en "All Files". ::msgcat::mcset en "Application Error". ::msgcat::mcset en "&Apply". ::msgcat::mcset en "Bold". ::msgcat::mcset en "Bold Italic". ::msgcat::mcset en "&Blue". ::msgcat::mcset en "Cancel". ::msgcat::mcset en "&Cancel". ::msgcat::mcset en "Cannot change to the directory \"%1\$s\".\nPermission denied.". ::msgcat::mcset en "Choose Directory". ::msgcat::mcset en "Cl&ear". ::msgcat::mcset en "&Clear Console". ::msgcat::mcset en "Color". ::msgcat::mcset en "Console". ::msgcat::mcset en "&Copy". ::msgcat::mcset en "Cu&t". ::msgcat::mcset en "&Delete". ::msgcat::mcset en "Details >>". ::msgcat::mcset en "Directory \"%1\$s\" does not exist.". ::msgcat::mcset en "&Directory:". ::msgcat::mcset en "&Edit". ::msgcat::mcset en "Effects". ::msgcat::mcset en "Error: %1\$s". ::msgcat::mcset en "E&xit". ::msgcat
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):63
                                                                                                                                                                                                                                  Entropy (8bit):4.185724027617087
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:fEGp6fR1FAGoW8vMKEQXK:sooLoQO6
                                                                                                                                                                                                                                  MD5:EC6A7E69AB0B8B767367DB54CC0499A8
                                                                                                                                                                                                                                  SHA1:6C2D6B622429AB8C17E07C2E0F546469823ABE57
                                                                                                                                                                                                                                  SHA-256:FB93D455A9D9CF3F822C968DFB273ED931E433F2494D71D6B5F8D83DDE7EACC2
                                                                                                                                                                                                                                  SHA-512:72077EAB988979EB2EE292ACDB72537172A5E96B4262CE7278B76F0FEBD7E850D18221DB551D1DE3C6EB520985B5E9642936BEEB66032F920593276784525702
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset en_gb Color Colour.}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3916
                                                                                                                                                                                                                                  Entropy (8bit):4.556739397782912
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:9714zhrzeU10xrFf+/eR0Mqp+cIFIXd/KcrtCcuUc6Sq4Pe:97145eFrF2GSMqgcIFIXdyAene
                                                                                                                                                                                                                                  MD5:09EF4B30B49A71FD4DEA931E334896E1
                                                                                                                                                                                                                                  SHA1:6C2366CE5961CFDA53259A43E087A813CEE41841
                                                                                                                                                                                                                                  SHA-256:5DE113DC4CE0DF0D8C54D4812C15EC31387127BF9AFEA028D20C6A5AA8E3AB85
                                                                                                                                                                                                                                  SHA-512:9DB3BB6B76B1299AE4612DF2A2872ECEE6642FC7DF971BE3A22437154AD25E81E1B1F3E1AA7A281CB3F48F8F8198A846BCB008CCFF91A9720440AFE5BAB7DE84
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset eo "&Abort" "&\u0108esigo". ::msgcat::mcset eo "&About..." "Pri...". ::msgcat::mcset eo "All Files" "\u0108ioj dosieroj". ::msgcat::mcset eo "Application Error" "Aplikoerraro". ::msgcat::mcset eo "&Blue" "&Blua". ::msgcat::mcset eo "Cancel" "Rezignu". ::msgcat::mcset eo "&Cancel" "&Rezignu". ::msgcat::mcset eo "Cannot change to the directory \"%1\$s\".\nPermission denied." "Neeble \u0109angi al dosierulon \"%1\$s\".\nVi ne rajtas tion.". ::msgcat::mcset eo "Choose Directory" "Elektu Dosierujo". ::msgcat::mcset eo "Cl&ear" "&Klaru". ::msgcat::mcset eo "&Clear Console" "&Klaru konzolon". ::msgcat::mcset eo "Color" "Farbo". ::msgcat::mcset eo "Console" "Konzolo". ::msgcat::mcset eo "&Copy" "&Kopiu". ::msgcat::mcset eo "Cu&t" "&Enpo\u015digu". ::msgcat::mcset eo "&Delete" "&Forprenu". ::msgcat::mcset eo "Details >>" "Detaloj >>". ::msgcat::mcset eo "Directory \"%1\$s\" does not exist." "La dosieruj
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3948
                                                                                                                                                                                                                                  Entropy (8bit):4.486102294561867
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:vTaZD2XRgGiWXirZe0uoH02QyTaBi2DcDmQ/jY33l4TCyFv:vmZaXhFbyGB3ELjDV
                                                                                                                                                                                                                                  MD5:93FFA957E3DCF851DD7EBE587A38F2D5
                                                                                                                                                                                                                                  SHA1:8C3516F79FB72F32848B40091DA67C81E40FDEFE
                                                                                                                                                                                                                                  SHA-256:91DC4718DC8566C36E4BCD0C292C01F467CA7661EFF601B870ABCDFE4A94ECBB
                                                                                                                                                                                                                                  SHA-512:8EC7048DDFF521DE444F697EAB305777BAC24AEA37716DA4FE5374E93CEF66DDD58D535BE8FCBCD2636D623337643B1242798BB8AC7292EA2D81AE030C3A605C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset es "&Abort" "&Abortar". ::msgcat::mcset es "&About..." "&Acerca de ...". ::msgcat::mcset es "All Files" "Todos los archivos". ::msgcat::mcset es "Application Error" "Error de la aplicaci\u00f3n". ::msgcat::mcset es "&Blue" "&Azul". ::msgcat::mcset es "Cancel" "Cancelar". ::msgcat::mcset es "&Cancel" "&Cancelar". ::msgcat::mcset es "Cannot change to the directory \"%1\$s\".\nPermission denied." "No es posible acceder al directorio \"%1\$s\".\nPermiso denegado.". ::msgcat::mcset es "Choose Directory" "Elegir directorio". ::msgcat::mcset es "Cl&ear" "&Borrar". ::msgcat::mcset es "&Clear Console" "&Borrar consola". ::msgcat::mcset es "Color". ::msgcat::mcset es "Console" "Consola". ::msgcat::mcset es "&Copy" "&Copiar". ::msgcat::mcset es "Cu&t" "Cor&tar". ::msgcat::mcset es "&Delete" "&Borrar". ::msgcat::mcset es "Details >>" "Detalles >>". ::msgcat::mcset es "Directory \"%1\$s\" does not exist." "
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3805
                                                                                                                                                                                                                                  Entropy (8bit):4.582498923493114
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:fiESNtfQIFBqFHjUp4KiOzbgRuhzSAEFlBGr3jd:fiESP1aVdKiHRXcN
                                                                                                                                                                                                                                  MD5:9FC55235C334F6F6026D5B38AFFB9E10
                                                                                                                                                                                                                                  SHA1:CAD3805900E860B9491E3EE5C2C0F52ADCA67065
                                                                                                                                                                                                                                  SHA-256:0A8BBB4D1FD87BF7A90DDFA50F4724994C9CE78D1F3E91CF40C1177DB7941DC5
                                                                                                                                                                                                                                  SHA-512:FBB5E72BC376DDB9F43B8C79398CA287AFAAAF8292A8CB3AF63241973B1748FD578D49075A1287DA054BA81D3ED61A723F3DE9E10855D5E85620B371D70D9BBD
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset fr "&Abort" "&Annuler". ::msgcat::mcset fr "About..." "\u00c0 propos...". ::msgcat::mcset fr "All Files" "Tous les fichiers". ::msgcat::mcset fr "Application Error" "Erreur d'application". ::msgcat::mcset fr "&Blue" "&Bleu". ::msgcat::mcset fr "Cancel" "Annuler". ::msgcat::mcset fr "&Cancel" "&Annuler". ::msgcat::mcset fr "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossible d'acc\u00e9der au r\u00e9pertoire \"%1\$s\".\nPermission refus\u00e9e.". ::msgcat::mcset fr "Choose Directory" "Choisir r\u00e9pertoire". ::msgcat::mcset fr "Cl&ear" "Effacer". ::msgcat::mcset fr "Color" "Couleur". ::msgcat::mcset fr "Console". ::msgcat::mcset fr "Copy" "Copier". ::msgcat::mcset fr "Cu&t" "Couper". ::msgcat::mcset fr "Delete" "Effacer". ::msgcat::mcset fr "Details >>" "D\u00e9tails >>". ::msgcat::mcset fr "Directory \"%1\$s\" does not exist." "Le r\u00e9pertoire \"%1\$s\" n'existe pas.".
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4600
                                                                                                                                                                                                                                  Entropy (8bit):4.752507976327236
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:IYIzxGy0Kt9C81y/HSzVqUaJf9q/x5a/mETsN:IB1FCt/4vZM+EA
                                                                                                                                                                                                                                  MD5:E1BA9C40A350BAD78611839A59065BF0
                                                                                                                                                                                                                                  SHA1:1A148D230C9F8D748D96A79CD4E261AF264D6524
                                                                                                                                                                                                                                  SHA-256:C8134EAD129E44E9C5043E1DAD81A6A900F0DE71DB3468E2603840038687F1D8
                                                                                                                                                                                                                                  SHA-512:17EC7F14C708C4D8C77731C26D0CE8AF6EBAB3D1CA878FB9682F15F0546031E39EF601683832631CA329549A630F2C9A3A69B1CC6E3CC927353605834FC62CAE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset hu "&Abort" "&Megszak\u00edt\u00e1s". ::msgcat::mcset hu "&About..." "N\u00e9vjegy...". ::msgcat::mcset hu "All Files" "Minden f\u00e1jl". ::msgcat::mcset hu "Application Error" "Alkalmaz\u00e1s hiba". ::msgcat::mcset hu "&Blue" "&K\u00e9k". ::msgcat::mcset hu "Cancel" "M\u00e9gsem". ::msgcat::mcset hu "&Cancel" "M\u00e9g&sem". ::msgcat::mcset hu "Cannot change to the directory \"%1\$s\".\nPermission denied." "A k\u00f6nyvt\u00e1rv\u00e1lt\u00e1s nem siker\u00fclt: \"%1\$s\".\nHozz\u00e1f\u00e9r\u00e9s megtagadva.". ::msgcat::mcset hu "Choose Directory" "K\u00f6nyvt\u00e1r kiv\u00e1laszt\u00e1sa". ::msgcat::mcset hu "Cl&ear" "T\u00f6rl\u00e9s". ::msgcat::mcset hu "&Clear Console" "&T\u00f6rl\u00e9s Konzol". ::msgcat::mcset hu "Color" "Sz\u00edn". ::msgcat::mcset hu "Console" "Konzol". ::msgcat::mcset hu "&Copy" "&M\u00e1sol\u00e1s". ::msgcat::mcset hu "Cu&t" "&Kiv\u00e1g\u00e1s". ::msgcat::mcset hu "
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3692
                                                                                                                                                                                                                                  Entropy (8bit):4.444986253861924
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:rtcxronR9zvjZ3hWsH9TYT/dllvOr80nC2dnGHc839kUqg:xcxoXBhlHiT/dlcY0HpVg
                                                                                                                                                                                                                                  MD5:ADB80EC5B23FC906A1A3313A30D789E6
                                                                                                                                                                                                                                  SHA1:5FB163BC1086D3366228204078F219FE4BB67CB3
                                                                                                                                                                                                                                  SHA-256:9F83DD0309ED621100F3187FFCDAE50B75F5973BBE74AF550A78EF0010495DED
                                                                                                                                                                                                                                  SHA-512:BA6E0C165561CDAEAB565EF1FED4087AB3B41EC3C18432C1BDA9B011E5C7C2E12F6B2CFC9F5C0CFAC1134AE53D80459D8E5B638739C61A851232047DEA7F3BA2
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset it "&Abort" "&Interrompi". ::msgcat::mcset it "&About..." "Informazioni...". ::msgcat::mcset it "All Files" "Tutti i file". ::msgcat::mcset it "Application Error" "Errore dell' applicazione". ::msgcat::mcset it "&Blue" "&Blu". ::msgcat::mcset it "Cancel" "Annulla". ::msgcat::mcset it "&Cancel" "&Annulla". ::msgcat::mcset it "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossibile accedere alla directory \"%1\$s\".\nPermesso negato.". ::msgcat::mcset it "Choose Directory" "Scegli una directory". ::msgcat::mcset it "Cl&ear" "Azzera". ::msgcat::mcset it "&Clear Console" "Azzera Console". ::msgcat::mcset it "Color" "Colore". ::msgcat::mcset it "Console". ::msgcat::mcset it "&Copy" "Copia". ::msgcat::mcset it "Cu&t" "Taglia". ::msgcat::mcset it "Delete" "Cancella". ::msgcat::mcset it "Details >>" "Dettagli >>". ::msgcat::mcset it "Directory \"%1\$s\" does not exist." "La director
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4466
                                                                                                                                                                                                                                  Entropy (8bit):4.472386382725933
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:791wMjS3Md15YNISfTMEu5KIXTLLBIafWUuvfbLnZj4gT7VT4k7BLyslwI6Blb4t:DVe3MX8ISUKYuXbLnZj4MRJhjSIO4t
                                                                                                                                                                                                                                  MD5:B628EAFD489335ED620014B56821B792
                                                                                                                                                                                                                                  SHA1:8F6AFF68B42B747D30870D6DA7E058294921406A
                                                                                                                                                                                                                                  SHA-256:D3D07AAD792C0E83F4704B304931EA549D12CBB3D99A573D9815E954A5710707
                                                                                                                                                                                                                                  SHA-512:C33D097D2897D20F75A197E30B859DC83C8B4E42F260150BC7205918779D77A8C2390BE65376622F6705C38ECDF6F14B6ABAD29EDE3DE79603025BBBC39BEBC7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset nl "&Abort" "&Afbreken". ::msgcat::mcset nl "&About..." "Over...". ::msgcat::mcset nl "All Files" "Alle Bestanden". ::msgcat::mcset nl "Application Error" "Toepassingsfout". ::msgcat::mcset nl "&Apply" "Toepassen". ::msgcat::mcset nl "Bold" "Vet". ::msgcat::mcset nl "Bold Italic" "Vet Cursief". ::msgcat::mcset nl "&Blue" "&Blauw". ::msgcat::mcset nl "Cancel" "Annuleren". ::msgcat::mcset nl "&Cancel" "&Annuleren". ::msgcat::mcset nl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan niet naar map \"%1\$s\" gaan.\nU heeft hiervoor geen toestemming.". ::msgcat::mcset nl "Choose Directory" "Kies map". ::msgcat::mcset nl "Cl&ear" "Wissen". ::msgcat::mcset nl "&Clear Console" "&Wis Console". ::msgcat::mcset nl "Color" "Kleur". ::msgcat::mcset nl "Console". ::msgcat::mcset nl "&Copy" "Kopi\u00ebren". ::msgcat::mcset nl "Cu&t" "Knippen". ::msgcat::mcset nl "&Delete" "Wissen". ::
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4841
                                                                                                                                                                                                                                  Entropy (8bit):4.754441208797498
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:mYpnddv1H+BBv5vVXKjB+y7ldBU63XQ3DGHolytTzEQdWaz0ybBaKG:zpdzH+3vLKnG63XdHoMpYYaL
                                                                                                                                                                                                                                  MD5:17B63EFE0A99F44D27DD41C4CC0A8A7B
                                                                                                                                                                                                                                  SHA1:3E45C0102B287908D770A31D1906678E785088C2
                                                                                                                                                                                                                                  SHA-256:1993B4EC2DC009D2E6CA185D0BD565D3F33A4EFA79BACA39E4F97F574D63F305
                                                                                                                                                                                                                                  SHA-512:F8B9E7BC76A4ED5F948A9E505F3B1A321E322DD57CF88BEF36B6A9AF793462E45432709402151B4BB520B12B089A043CA23FF86106ED7B5C73DFBB6E233907F4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset pl "&Abort" "&Przerwij". ::msgcat::mcset pl "&About..." "O programie...". ::msgcat::mcset pl "All Files" "Wszystkie pliki". ::msgcat::mcset pl "Application Error" "B\u0142\u0105d w programie". ::msgcat::mcset pl "&Apply" "Zastosuj". ::msgcat::mcset pl "Bold" "Pogrubienie". ::msgcat::mcset pl "Bold Italic" "Pogrubiona kursywa". ::msgcat::mcset pl "&Blue" "&Niebieski". ::msgcat::mcset pl "Cancel" "Anuluj". ::msgcat::mcset pl "&Cancel" "&Anuluj". ::msgcat::mcset pl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nie mo\u017cna otworzy\u0107 katalogu \"%1\$s\".\nOdmowa dost\u0119pu.". ::msgcat::mcset pl "Choose Directory" "Wybierz katalog". ::msgcat::mcset pl "Cl&ear" "&Wyczy\u015b\u0107". ::msgcat::mcset pl "&Clear Console" "&Wyczy\u015b\u0107 konsol\u0119". ::msgcat::mcset pl "Color" "Kolor". ::msgcat::mcset pl "Console" "Konsola". ::msgcat::mcset pl "&Copy" "&Kopiuj". ::msgcat::
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3913
                                                                                                                                                                                                                                  Entropy (8bit):4.5841256573492135
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:k82mOQNHHouc2Ib2dxwj0Hpn4KeJ4iFHh29wDPK8+i92M5L:k82mOenox2x5Hp47mi3ZUMB
                                                                                                                                                                                                                                  MD5:236356817E391D8871EA59667F47DA0C
                                                                                                                                                                                                                                  SHA1:948EE95F4549DA8C7D412911D17B4B62CBA22ADD
                                                                                                                                                                                                                                  SHA-256:AD0E466131D3789DE321D9D0588E19E4647BA82EDE41EEE6EBEF464786F8BDBE
                                                                                                                                                                                                                                  SHA-512:3AB10D1980D4C1367EA0BB54E50709DF32A870E851EDE80F30F66DA4B09C1ACFFF4E77C462BD815DD67F485DDFF77FEBD09CA29D77EEE55FE8A00D115D600C32
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset pt "&Abort" "&Abortar". ::msgcat::mcset pt "About..." "Sobre ...". ::msgcat::mcset pt "All Files" "Todos os arquivos". ::msgcat::mcset pt "Application Error" "Erro de aplica\u00e7\u00e3o". ::msgcat::mcset pt "&Blue" "&Azul". ::msgcat::mcset pt "Cancel" "Cancelar". ::msgcat::mcset pt "&Cancel" "&Cancelar". ::msgcat::mcset pt "Cannot change to the directory \"%1\$s\".\nPermission denied." "N\u00e3o foi poss\u00edvel mudar para o diret\u00f3rio \"%1\$s\".\nPermiss\u00e3o negada.". ::msgcat::mcset pt "Choose Directory" "Escolha um diret\u00f3rio". ::msgcat::mcset pt "Cl&ear" "Apagar". ::msgcat::mcset pt "&Clear Console" "Apagar Console". ::msgcat::mcset pt "Color" "Cor". ::msgcat::mcset pt "Console". ::msgcat::mcset pt "&Copy" "Copiar". ::msgcat::mcset pt "Cu&t" "Recortar". ::msgcat::mcset pt "&Delete" "Excluir". ::msgcat::mcset pt "Details >>" "Detalhes >>". ::msgcat::mcset pt "Directory \"%1\$s\"
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7214
                                                                                                                                                                                                                                  Entropy (8bit):4.358559144448363
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:ZUEBGTT4Ys7LT3xXkhF2xSrwFlOzFAn9E/j49cDRqRjGSQvN8Nfo5hgV9aWTRtaa:SraFGImk+4RKOGqRyRu
                                                                                                                                                                                                                                  MD5:D7C27DBDF7B349BE13E09F35BA61A5F8
                                                                                                                                                                                                                                  SHA1:40A52544B557F19736EA1767BFBF5708A9BBC318
                                                                                                                                                                                                                                  SHA-256:C863DEBAB79F9682FD0D52D864E328E7333D03F4E9A75DBB342C30807EFDCFFB
                                                                                                                                                                                                                                  SHA-512:DAF10336096B0574F060757CB6DD24049692F81B969B01BB8FA212035D955B8DA53F5ECDE3613E6AEF3C47165F075CC14363E4B854B2407EA452EAB4D4D31955
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset ru "&Abort" "&\u041e\u0442\u043c\u0435\u043d\u0438\u0442\u044c". ::msgcat::mcset ru "&About..." "\u041f\u0440\u043e...". ::msgcat::mcset ru "All Files" "\u0412\u0441\u0435 \u0444\u0430\u0439\u043b\u044b". ::msgcat::mcset ru "Application Error" "\u041e\u0448\u0438\u0431\u043a\u0430 \u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435". ::msgcat::mcset ru "&Blue" " &\u0413\u043e\u043b\u0443\u0431\u043e\u0439". ::msgcat::mcset ru "Cancel" "\u041e\u0442&\u043c\u0435\u043d\u0430". ::msgcat::mcset ru "&Cancel" "\u041e\u0442&\u043c\u0435\u043d\u0430". ::msgcat::mcset ru "Cannot change to the directory \"%1\$s\".\nPermission denied." \...."\u041d\u0435 \u043c\u043e\u0433\u0443 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0432 \u043a\u0430\u0442\u0430\u043b\u043e\u0433 \"%1\$s\".\n\u041d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e \u043f\u0440\u0430\u0432 \u0434\u043e\u0441\u0442\u0443\u043f\u0430".
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3832
                                                                                                                                                                                                                                  Entropy (8bit):4.609382297476727
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:g4HXcfWBJdE10M4/00li6z8XIxTB2iDxypdmmZbWxOt:FXcf6H00li9IxTEbQsb7t
                                                                                                                                                                                                                                  MD5:DB1712B1C1FF0E3A46F8E86FBB78AA4D
                                                                                                                                                                                                                                  SHA1:28D9DB9CBEE791C09BD272D9C2A6C3DA80EB89EA
                                                                                                                                                                                                                                  SHA-256:B76EBFA21BC1E937A04A04E5122BE64B5CDEE1F47C7058B71D8B923D70C3B17B
                                                                                                                                                                                                                                  SHA-512:F79CD72DCD6D1B4212A5058DA5A020E8A157E72E6D84CAFB96463E76C1CED5AC367A2295EF743FDE70C9AB1CF2F4D88A4A73300DFD4F799AA3ECDA6FBF04E588
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:namespace eval ::tk {. ::msgcat::mcset sv "&Abort" "&Avsluta". ::msgcat::mcset sv "&About..." "&Om...". ::msgcat::mcset sv "All Files" "Samtliga filer". ::msgcat::mcset sv "Application Error" "Programfel". ::msgcat::mcset sv "&Blue" "&Bl\u00e5". ::msgcat::mcset sv "Cancel" "Avbryt". ::msgcat::mcset sv "&Cancel" "&Avbryt". ::msgcat::mcset sv "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ej n\u00e5 mappen \"%1\$s\".\nSaknar r\u00e4ttigheter.". ::msgcat::mcset sv "Choose Directory" "V\u00e4lj mapp". ::msgcat::mcset sv "Cl&ear" "&Radera". ::msgcat::mcset sv "&Clear Console" "&Radera konsollen". ::msgcat::mcset sv "Color" "F\u00e4rg". ::msgcat::mcset sv "Console" "Konsoll". ::msgcat::mcset sv "&Copy" "&Kopiera". ::msgcat::mcset sv "Cu&t" "Klipp u&t". ::msgcat::mcset sv "&Delete" "&Radera". ::msgcat::mcset sv "Details >>" "Detaljer >>". ::msgcat::mcset sv "Directory \"%1\$s\" does not exist." "Mappen \"%1\$s\" finns
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5594
                                                                                                                                                                                                                                  Entropy (8bit):4.9941618573215525
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:oz4CrtmsXVwM3Er4VAEQ93NZB1o+IFF5ZYi4GUoLf33yLLddzA:oUCrtmsFREEs999o7FF5ZYi4GjLfS/d2
                                                                                                                                                                                                                                  MD5:7763C90F811620A6C1F0A36BAF9B89CA
                                                                                                                                                                                                                                  SHA1:30E24595DD683E470FE9F12814D27D6D266B511E
                                                                                                                                                                                                                                  SHA-256:F6929A5E0D18BC4C6666206C63AC4AAA66EDC4B9F456DFC083300CFA95A44BCD
                                                                                                                                                                                                                                  SHA-512:2E2887392C67D05EA85DB2E6BFD4AA27779BC82D3B607A7DD221A99EFF0D2A21A6BA47A4F2D2CDFC7CFECD7E93B2B38064C4D5A51406471AE142EC9CC71F5C48
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# obsolete.tcl --.#.# This file contains obsolete procedures that people really shouldn't.# be using anymore, but which are kept around for backward compatibility..#.# Copyright (c) 1994 The Regents of the University of California..# Copyright (c) 1994 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# The procedures below are here strictly for backward compatibility with.# Tk version 3.6 and earlier. The procedures are no longer needed, so.# they are no-ops. You should not use these procedures anymore, since.# they may be removed in some future release...proc tk_menuBar args {}.proc tk_bindForTraversal args {}..# ::tk::classic::restore --.#.# Restore the pre-8.5 (Tk classic) look as the widget defaults for classic.# Tk widgets..#.# The value following an 'option add' call is the new 8.5 value..#.namespace eval ::tk::classic {. # This may need to be adjusted for some windo
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1586
                                                                                                                                                                                                                                  Entropy (8bit):4.733749898743743
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:k2hguC4Zxk+Z0cIWR3afbR1EIC+KtVa+6WX13jZQl9:k6T9N3atqIkeS9FQD
                                                                                                                                                                                                                                  MD5:D17FE676A057F373B44C9197114F5A69
                                                                                                                                                                                                                                  SHA1:9745C83EEC8565602F8D74610424848009FFA670
                                                                                                                                                                                                                                  SHA-256:76DBDBF9216678D48D1640F8FD1E278E7140482E1CAC7680127A9A425CC61DEE
                                                                                                                                                                                                                                  SHA-512:FF7D9EB64D4367BB11C567E64837CB1DAAA9BE0C8A498CAD00BF63AF45C1826632BC3A09E65D6F51B26EBF2D07285802813ED55C5D697460FC95AF30A943EF8F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# optMenu.tcl --.#.# This file defines the procedure tk_optionMenu, which creates.# an option button and its associated menu..#.# Copyright (c) 1994 The Regents of the University of California..# Copyright (c) 1994 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# ::tk_optionMenu --.# This procedure creates an option button named $w and an associated.# menu. Together they provide the functionality of Motif option menus:.# they can be used to select one of many values, and the current value.# appears in the global variable varName, as well as in the text of.# the option menubutton. The name of the menu is returned as the.# procedure's result, so that the caller can use it to change configuration.# options on the menu or otherwise manipulate it..#.# Arguments:.# w -...The name to use for the menubutton..# varName -..Global variable to hold the currently selected value..# first
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8174
                                                                                                                                                                                                                                  Entropy (8bit):4.9180898441277705
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:ZUW5yUd51URCJWgWWWuWVWUKoDOdnAjLDlJymGH91QOW86vkQI:ZLXaCI3dFUlPdnAP69W89
                                                                                                                                                                                                                                  MD5:ABE618A0891CD6909B945A2098C77D75
                                                                                                                                                                                                                                  SHA1:A322CCFB33FF73E4A4730B5B21DE4290F9D94622
                                                                                                                                                                                                                                  SHA-256:60B8579368BB3063F16D25F007385111E0EF8D97BB296B03656DC176E351E3CA
                                                                                                                                                                                                                                  SHA-512:2DF5A50F3CA7D21F43651651879BCAE1433FF44B0A7ECE349CCF73BECC4780160125B21F69348C97DCD60503FC79A6525DB723962197E8550B42D0AE257FD8E7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# palette.tcl --.#.# This file contains procedures that change the color palette used.# by Tk..#.# Copyright (c) 1995-1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# ::tk_setPalette --.# Changes the default color scheme for a Tk application by setting.# default colors in the option database and by modifying all of the.# color options for existing widgets that have the default value..#.# Arguments:.# The arguments consist of either a single color name, which.# will be used as the new background color (all other colors will.# be computed from this) or an even number of values consisting of.# option names and values. The name for an option is the one used.# for the option database, such as activeForeground, not -activeforeground...proc ::tk_setPalette {args} {. if {[winfo depth .] == 1} {..# Just return on monochrome displays, otherwise errors will occur..return. }.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5176
                                                                                                                                                                                                                                  Entropy (8bit):4.933519639131517
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:PmpWHrga3awUrH6kdX3pBz6tkm71cHXYV23EmkiYlgfY8:+pWHrP36r6kJ3pBetkm6HXVUmPYlgfY8
                                                                                                                                                                                                                                  MD5:2DA0A23CC9D6FD970FE00915EA39D8A2
                                                                                                                                                                                                                                  SHA1:DFE3DC663C19E9A50526A513043D2393869D8F90
                                                                                                                                                                                                                                  SHA-256:4ADF738B17691489C71C4B9D9A64B12961ADA8667B81856F7ADBC61DFFEADF29
                                                                                                                                                                                                                                  SHA-512:B458F3D391DF9522D4E7EAE8640AF308B4209CE0D64FD490BFC0177FDE970192295C1EA7229CE36D14FC3E582C7649460B8B7B0214E0FF5629B2B430A99307D4
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# panedwindow.tcl --.#.# This file defines the default bindings for Tk panedwindow widgets and.# provides procedures that help in implementing those bindings...bind Panedwindow <Button-1> { ::tk::panedwindow::MarkSash %W %x %y 1 }.bind Panedwindow <Button-2> { ::tk::panedwindow::MarkSash %W %x %y 0 }..bind Panedwindow <B1-Motion> { ::tk::panedwindow::DragSash %W %x %y 1 }.bind Panedwindow <B2-Motion> { ::tk::panedwindow::DragSash %W %x %y 0 }..bind Panedwindow <ButtonRelease-1> {::tk::panedwindow::ReleaseSash %W 1}.bind Panedwindow <ButtonRelease-2> {::tk::panedwindow::ReleaseSash %W 0}..bind Panedwindow <Motion> { ::tk::panedwindow::Motion %W %x %y }..bind Panedwindow <Leave> { ::tk::panedwindow::Leave %W }..# Initialize namespace.namespace eval ::tk::panedwindow {}..# ::tk::panedwindow::MarkSash --.#.# Handle marking the correct sash for possible dragging.#.# Arguments:.# w..the widget.# x..widget local x coord.# y..widget local y coord.# proxy.whether this should be a prox
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):363
                                                                                                                                                                                                                                  Entropy (8bit):4.977735142707899
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6:Cjtl17nOJRVxTc6ynID/cL44ncleXNyLMQ9HECJBIQ08PbDMQ9HECJBIQem8:ot7rOJdg6LYUlVfBIUjjfBIFF
                                                                                                                                                                                                                                  MD5:A6448AF2C8FAFC9A4F42EACA6BF6AB2E
                                                                                                                                                                                                                                  SHA1:0B295B46B6DF906E89F40A907022068BC6219302
                                                                                                                                                                                                                                  SHA-256:CD44EE7F76C37C0C522BD0CFCA41C38CDEDDC74392B2191A3AF1A63D9D18888E
                                                                                                                                                                                                                                  SHA-512:5B1A8CA5B09B7281DE55460D21D5195C4EE086BEBDC35FA561001181490669FFC67D261F99EAA900467FE97E980EB733C5FFBF9D8C541EDE18992BF4A435C749
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:if {[catch {package present Tcl 8.6.0}]} { return }.if {($::tcl_platform(platform) eq "unix") && ([info exists ::env(DISPLAY)]..|| ([info exists ::argv] && ("-display" in $::argv)))} {. package ifneeded Tk 8.6.9 [list load [file join $dir .. .. bin libtk8.6.dll] Tk].} else {. package ifneeded Tk 8.6.9 [list load [file join $dir .. .. bin tk86t.dll] Tk].}.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Tcl script, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7381
                                                                                                                                                                                                                                  Entropy (8bit):4.833263771361282
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:keEoaa0QfsimXZrjpgj47e5QeO9uMfUKvLAN6Zo:keEoRHsiWddgkoiUeG
                                                                                                                                                                                                                                  MD5:EFC567E407C48BF2BE4E09CB18DEFC11
                                                                                                                                                                                                                                  SHA1:EDEDB6776963B7D629C6ACE9440D24EB78DEA878
                                                                                                                                                                                                                                  SHA-256:9708F5A1E81E1C3FEAF189020105BE28D27AA8808FF9FB2DCCA040500CF2642A
                                                                                                                                                                                                                                  SHA-512:BDA5F92BD2F7B9CD29C5A732EC77A71291778A0EC3EABE81575C55DE3E207F663BA28DA4C95174045A74EFFF71B95D907C9D056BAA9E585E6F6DC14A133760BC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# safetk.tcl --.#.# Support procs to use Tk in safe interpreters..#.# Copyright (c) 1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES...# see safetk.n for documentation..#.#.# Note: It is now ok to let untrusted code being executed.# between the creation of the interp and the actual loading.# of Tk in that interp because the C side Tk_Init will.# now look up the master interp and ask its safe::TkInit.# for the actual parameters to use for it's initialization (if allowed),.# not relying on the slave state..#..# We use opt (optional arguments parsing).package require opt 0.4.1;..namespace eval ::safe {.. # counter for safe toplevels. variable tkSafeId 0.}..#.# tkInterpInit : prepare the slave interpreter for tk loading.# most of the real job is done by loadTk.# returns the slave name (tkInterpInit does).#.proc ::safe::tkInterpIni
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):7766
                                                                                                                                                                                                                                  Entropy (8bit):4.933555104215445
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:q1xTLI9LUAp8cZIQ+Umuy9vYE2dLTaQfiwHZeABypyTtB:HUN1Umn2dKuHIpCB
                                                                                                                                                                                                                                  MD5:1CE32CDAEB04C75BFCEEA5FB94B8A9F0
                                                                                                                                                                                                                                  SHA1:CC7614C9EADE999963EE78B422157B7B0739894C
                                                                                                                                                                                                                                  SHA-256:58C662DD3D2C653786B05AA2C88831F4E971B9105E4869D866FB6186E83ED365
                                                                                                                                                                                                                                  SHA-512:1EE5A187615AE32F17936931B30FEA9551F9E3022C1F45A2BCA81624404F4E68022FCF0B03FBD61820EC6958983A8F2FBFC3AD2EC158433F8E8DE9B8FCF48476
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# scale.tcl --.#.# This file defines the default bindings for Tk scale widgets and provides.# procedures that help in implementing the bindings..#.# Copyright (c) 1994 The Regents of the University of California..# Copyright (c) 1994-1995 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#-------------------------------------------------------------------------.# The code below creates the default class bindings for entries..#-------------------------------------------------------------------------..# Standard Motif bindings:..bind Scale <Enter> {. if {$tk_strictMotif} {..set tk::Priv(activeBg) [%W cget -activebackground]..%W configure -activebackground [%W cget -background]. }. tk::ScaleActivate %W %x %y.}.bind Scale <Motion> {. tk::ScaleActivate %W %x %y.}.bind Scale <Leave> {. if {$tk_strictMotif} {..%W configure -activebackground $tk::Priv(activeBg). }.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):12748
                                                                                                                                                                                                                                  Entropy (8bit):5.026700023745507
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:AfVS+eV9fKbBevrpQQtfJMZqSwiXEfY4yhIa7yLIVNpIgdWmD3T1gFpN:Pf4wTGOfmkSwORVqaGcV4q7kpN
                                                                                                                                                                                                                                  MD5:4CBFFC4E6B3F56A5890E3F7C31C6C378
                                                                                                                                                                                                                                  SHA1:75DB5205B311F55D1CA1D863B8688A628BF6012A
                                                                                                                                                                                                                                  SHA-256:6BA3E2D62BD4856D7D7AE87709FCAA23D81EFC38C375C6C5D91639555A84C35D
                                                                                                                                                                                                                                  SHA-512:65DF7AE09E06C200A8456748DC89095BB8417253E01EC4FDAFB28A84483147DDC77AAF6B49BE9E18A326A94972086A99044BEE3CE5CF8026337DFC6972C92C04
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# scrlbar.tcl --.#.# This file defines the default bindings for Tk scrollbar widgets..# It also provides procedures that help in implementing the bindings..#.# Copyright (c) 1994 The Regents of the University of California..# Copyright (c) 1994-1996 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#-------------------------------------------------------------------------.# The code below creates the default class bindings for scrollbars..#-------------------------------------------------------------------------..# Standard Motif bindings:.if {[tk windowingsystem] eq "x11" || [tk windowingsystem] eq "aqua"} {..bind Scrollbar <Enter> {. if {$tk_strictMotif} {..set tk::Priv(activeBg) [%W cget -activebackground]..%W configure -activebackground [%W cget -background]. }. %W activate [%W identify %x %y].}.bind Scrollbar <Motion> {. %W activate [%W identify %x %y].}..# The
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):15640
                                                                                                                                                                                                                                  Entropy (8bit):5.001694129885997
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:aR1yvxxVRQRrclOniQ14Yvg5bbVFMio1UF9w9P75uaMY+c6RhO1ON6Ql4qRiZ0NO:MyF5XVF61iwZ75/YRhO464z8wdEt
                                                                                                                                                                                                                                  MD5:9971530F110AC2FB7D7EC91789EA2364
                                                                                                                                                                                                                                  SHA1:AB553213C092EF077524ED56FC37DA29404C79A7
                                                                                                                                                                                                                                  SHA-256:5D6E939B44F630A29C4FCB1E2503690C453118607FF301BEF3C07FA980D5075A
                                                                                                                                                                                                                                  SHA-512:81B4CEC39B03FBECA59781AA54960F0A10A09733634F401D5553E1AAA3EBF12A110C9D555946FCDD70A9CC897514663840745241AD741DC440BB081A12DCF411
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# spinbox.tcl --.#.# This file defines the default bindings for Tk spinbox widgets and provides.# procedures that help in implementing those bindings. The spinbox builds.# off the entry widget, so it can reuse Entry bindings and procedures..#.# Copyright (c) 1992-1994 The Regents of the University of California..# Copyright (c) 1994-1997 Sun Microsystems, Inc..# Copyright (c) 1999-2000 Jeffrey Hobbs.# Copyright (c) 2000 Ajuba Solutions.#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#-------------------------------------------------------------------------.# Elements of tk::Priv that are used in this file:.#.# afterId -..If non-null, it means that auto-scanning is underway.#...and it gives the "after" id for the next auto-scan.#...command to be executed..# mouseMoved -..Non-zero means the mouse has moved a significant.#...amount since the button went down (so, for example,.#...start dragging out a
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):20270
                                                                                                                                                                                                                                  Entropy (8bit):4.749624735829406
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:edtm3fv2ZzffGIgowSDxD7n2s7AcBnaUuFyLWFot5gzSG3k96vNTWuoJnfOvWhbk:eds3fv2ZzffGIgowSDxD7nd7AcBnahFN
                                                                                                                                                                                                                                  MD5:4AD192C43972A6A4834D1D5A7C511750
                                                                                                                                                                                                                                  SHA1:09CA39647AA1C14DB16014055E48A9B0237639BA
                                                                                                                                                                                                                                  SHA-256:8E8ECECFD6046FE413F37A91933EEA086E31959B3FBEB127AFDD05CD9141BE9A
                                                                                                                                                                                                                                  SHA-512:287FAADBC6F65FCC3EA9C1EC10B190712BB36A06D28E59F8D268EA585B4E6B13494BA111DFF6AC2EBF998578999C9C36965C714510FC21A9ACB65FF9B75097CB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Tcl autoload index file, version 2.0.# This file is generated by the "auto_mkindex" command.# and sourced to set up indexing information for one or.# more commands. Typically each line is a command that.# sets an element in the auto_index array, where the.# element name is the name of a command and the value is.# a script that loads the command...set auto_index(::tk::dialog::error::Return) [list source [file join $dir bgerror.tcl]].set auto_index(::tk::dialog::error::Details) [list source [file join $dir bgerror.tcl]].set auto_index(::tk::dialog::error::SaveToLog) [list source [file join $dir bgerror.tcl]].set auto_index(::tk::dialog::error::Destroy) [list source [file join $dir bgerror.tcl]].set auto_index(::tk::dialog::error::bgerror) [list source [file join $dir bgerror.tcl]].set auto_index(bgerror) [list source [file join $dir bgerror.tcl]].set auto_index(::tk::ButtonInvoke) [list source [file join $dir button.tcl]].set auto_index(::tk::ButtonAutoInvoke) [list source [file join
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5142
                                                                                                                                                                                                                                  Entropy (8bit):4.672280480827932
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:MgPXEnPQcTtD7zxeHK7ijhgdhAhbbjymL/KK2pLQY4QYNHL43EwzS6ejW:MgPUnPtTtFeqmjhgdhIbbjymL/KKeLQW
                                                                                                                                                                                                                                  MD5:214FA0731A27E33826F2303750B64784
                                                                                                                                                                                                                                  SHA1:C2DA41761FB7BAE38DDDEFA22AB57B337F54F5D8
                                                                                                                                                                                                                                  SHA-256:FB6B35ECB1438BB8A2D816B86FB0C55500C6EA8D24AECB359CC3C7D3B3C54DE0
                                                                                                                                                                                                                                  SHA-512:2E2A2412CBB090C0728333480B0E07C85087ED932974A235D5BC8C9725DE937520205D988872E1B5BEFA1E80201E046C500BC875A5CBD584A5099930EBBD115A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# tearoff.tcl --.#.# This file contains procedures that implement tear-off menus..#.# Copyright (c) 1994 The Regents of the University of California..# Copyright (c) 1994-1997 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..# ::tk::TearoffMenu --.# Given the name of a menu, this procedure creates a torn-off menu.# that is identical to the given menu (including nested submenus)..# The new torn-off menu exists as a toplevel window managed by the.# window manager. The return value is the name of the new menu..# The window is created at the point specified by x and y.#.# Arguments:.# w -...The menu to be torn-off (duplicated)..# x -...x coordinate where window is created.# y -...y coordinate where window is created..proc ::tk::TearOffMenu {w {x 0} {y 0}} {. # Find a unique name to use for the torn-off menu. Find the first. # ancestor of w that is a toplevel but not a menu,
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):33155
                                                                                                                                                                                                                                  Entropy (8bit):4.908284262811967
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:ThZXGSuWlNGbyBFFRzGagUNKEFx8wredkG/gVVFaO/9bembFWaHnla98ffRiqiPp:TYaNGKF6uNdyO4Ona98ffRUAlde
                                                                                                                                                                                                                                  MD5:03CC27E28E0CFCE1B003C3E936797AB0
                                                                                                                                                                                                                                  SHA1:C7FE5AE7F35C86EC3724F6A111EAAF2C1A18ABE9
                                                                                                                                                                                                                                  SHA-256:BCCC1039F0EB331C4BB6BD5848051BB745F242016952723478C93B009F63D254
                                                                                                                                                                                                                                  SHA-512:5091B10EE8446E6853EF7060EC13AB8CADA0D6448F9081FEBD07546C061F69FC273BBF23BA7AF05D8359E618DD68A5C27F0453480FE3F26E744DB19BFCD115C7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# text.tcl --.#.# This file defines the default bindings for Tk text widgets and provides.# procedures that help in implementing the bindings..#.# Copyright (c) 1992-1994 The Regents of the University of California..# Copyright (c) 1994-1997 Sun Microsystems, Inc..# Copyright (c) 1998 by Scriptics Corporation..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..#-------------------------------------------------------------------------.# Elements of ::tk::Priv that are used in this file:.#.# afterId -..If non-null, it means that auto-scanning is underway.#...and it gives the "after" id for the next auto-scan.#...command to be executed..# char -..Character position on the line; kept in order.#...to allow moving up or down past short lines while.#...still remembering the desired position..# mouseMoved -..Non-zero means the mouse has moved a significant.#...amount since the button went down (so, for exampl
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:Tcl script, ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):23142
                                                                                                                                                                                                                                  Entropy (8bit):5.097142507145225
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:dmAlIQ7ylH462gngqeObubqLwvoGah0QSA4jLGn3WB0MCdPAWD+g190K5TzMSW4d:dmOIQulHokh0QzMemB0MCD+g1bk+
                                                                                                                                                                                                                                  MD5:3250EC5B2EFE5BBE4D3EC271F94E5359
                                                                                                                                                                                                                                  SHA1:6A0FE910041C8DF4F3CDC19871813792E8CC4E4C
                                                                                                                                                                                                                                  SHA-256:E1067A0668DEBB2D8E8EC3B7BC1AEC3723627649832B20333F9369F28E4DFDBF
                                                                                                                                                                                                                                  SHA-512:F8E403F3D59D44333BCE2AA7917E6D8115BEC0FE5AE9A1306F215018B05056467643B7AA228154DDCED176072BC903DFB556CB2638F5C55C1285C376079E8FE3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# tk.tcl --.#.# Initialization script normally executed in the interpreter for each Tk-based.# application. Arranges class bindings for widgets..#.# Copyright (c) 1992-1994 The Regents of the University of California..# Copyright (c) 1994-1996 Sun Microsystems, Inc..# Copyright (c) 1998-2000 Ajuba Solutions..#.# See the file "license.terms" for information on usage and redistribution of.# this file, and for a DISCLAIMER OF ALL WARRANTIES...# Verify that we have Tk binary and script components from the same release.package require -exact Tk 8.6.9...# Create a ::tk namespace.namespace eval ::tk {. # Set up the msgcat commands. namespace eval msgcat {..namespace export mc mcmax. if {[interp issafe] || [catch {package require msgcat}]} {. # The msgcat package is not available. Supply our own. # minimal replacement.. proc mc {src args} {. return [format $src {*}$args]. }. proc mcmax {args} {.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):38373
                                                                                                                                                                                                                                  Entropy (8bit):5.143151103117394
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:a6NFLvIIaE2wCpxQYt/rJTkA3NN5YAGnk1c6gHZZgkO0Z6INfdpsaUpWz8ZlhL5S:akJ2wKFXuNzClMGH87f12Vb4
                                                                                                                                                                                                                                  MD5:21985684C432CB918A3E862517842F75
                                                                                                                                                                                                                                  SHA1:4DBACAEEF8454C1B08993D76857C5F09AA75405A
                                                                                                                                                                                                                                  SHA-256:AE448DF6FDBBA45D450ABEFEF12799F8362177B0B9FE06F3CA3CB0EDA5E6AA58
                                                                                                                                                                                                                                  SHA-512:AFEA6C47001455D7E40A5A7728FA4DFAD7BB66B02191E807BB15355847F5B265DEEE6015516807B10E1273710A3D03FAAC7856CB16EFA773813105B23A11960F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# tkfbox.tcl --.#.#.Implements the "TK" standard file selection dialog box. This dialog.#.box is used on the Unix platforms whenever the tk_strictMotif flag is.#.not set..#.#.The "TK" standard file selection dialog box is similar to the file.#.selection dialog box on Win95(TM). The user can navigate the.#.directories by clicking on the folder icons or by selecting the.#."Directory" option menu. The user can select files by clicking on the.#.file icons or by entering a filename in the "Filename:" entry..#.# Copyright (c) 1994-1998 Sun Microsystems, Inc..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..namespace eval ::tk::dialog {}.namespace eval ::tk::dialog::file {. namespace import -force ::tk::msgcat::*. variable showHiddenBtn 0. variable showHiddenVar 1.. # Create the images if they did not already exist.. if {![info exists ::tk::Priv(updirImage)]} {..set ::tk::Priv(updirImage)
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3683
                                                                                                                                                                                                                                  Entropy (8bit):4.872530668776095
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:xICsIX5RupDdMrwuQb8BQEQWQEQK9FVGQJFVGDusxzUFIG0usf2kGKQH+n5dvW8m:h7oFAzfphta9DwuTa
                                                                                                                                                                                                                                  MD5:8FF9D357AF3806D997BB8654E95F530C
                                                                                                                                                                                                                                  SHA1:62292163299CC229031BB4EAFBE900323056561A
                                                                                                                                                                                                                                  SHA-256:E36864B33D7C2B47FE26646377BE86FB341BBF2B6DF13E33BD799E87D24FC193
                                                                                                                                                                                                                                  SHA-512:ECDC47E7D1F0F9C0C052ACA2EB2DE10E78B2256E8DB85D7B52F365C1074A4E24CDB1C7A2780B36DFA36F174FF87B6A31C49F61CC0AC3D2412B3915234D911C9C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Ttk widget set: Alternate theme.#..namespace eval ttk::theme::alt {.. variable colors. array set colors {..-frame .."#d9d9d9"..-window.."#ffffff"..-darker ."#c3c3c3"..-border.."#414141"..-activebg ."#ececec"..-disabledfg."#a3a3a3"..-selectbg."#4a6984"..-selectfg."#ffffff"..-altindicator."#aaaaaa". }.. ttk::style theme settings alt {...ttk::style configure "." \.. -background .$colors(-frame) \.. -foreground .black \.. -troughcolor.$colors(-darker) \.. -bordercolor.$colors(-border) \.. -selectbackground .$colors(-selectbg) \.. -selectforeground .$colors(-selectfg) \.. -font ..TkDefaultFont \.. ;...ttk::style map "." -background \.. [list disabled $colors(-frame) active $colors(-activebg)] ;..ttk::style map "." -foreground [list disabled $colors(-disabledfg)] ;. ttk::style map "." -embossed [list disabled 1] ;...ttk::style configure TButton \.. -anchor center -width -11 -padding "1 1" \.. -relief raised -shiftrelief 1 \.. -highl
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2245
                                                                                                                                                                                                                                  Entropy (8bit):4.988082031411997
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:tdlBlblITKleKgNX1gPc+JFzVPb9ZLJY2ZL7X0jX4:p51gRK7F9DzrMo
                                                                                                                                                                                                                                  MD5:6466DBA5F7DDB28F280A24E2397DD875
                                                                                                                                                                                                                                  SHA1:060C504D08B014EB388EFAF48E3720CE5D7F0132
                                                                                                                                                                                                                                  SHA-256:CBC17D1C434CACD0AB42CDCC4D62ED193F926447189AD258C13738D4EC154A80
                                                                                                                                                                                                                                  SHA-512:5FAAC1C5FC868DCE8B7A9431BEAEB8117ADDE5C752306CAD7B6FA8123758F2CF37FB1CF18CAC2934F7D07B14FAFCE01581BAD0CA952BFECFCBD9E1E26FF9A64C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Aqua theme (OSX native look and feel).#..namespace eval ttk::theme::aqua {. ttk::style theme settings aqua {...ttk::style configure . \.. -font TkDefaultFont \.. -background systemWindowBody \.. -foreground systemModelessDialogActiveText \.. -selectbackground systemHighlight \.. -selectforeground systemModelessDialogActiveText \.. -selectborderwidth 0 \.. -insertwidth 1...ttk::style map . \.. -foreground {disabled systemModelessDialogInactiveText... background systemModelessDialogInactiveText} \.. -selectbackground {background systemHighlightSecondary... !focus systemHighlightSecondary} \.. -selectforeground {background systemModelessDialogInactiveText... !focus systemDialogActiveText}...# Workaround for #1100117:..# Actually, on Aqua we probably shouldn't stipple images in..# disabled buttons even if it did work.....ttk::style configure . -stipple {}...ttk::style configure TButton -anchor center -width -6..ttk::style configure Toolbutton -
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2978
                                                                                                                                                                                                                                  Entropy (8bit):4.8919006418640265
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:hpNRZ/rtWkRMC0ScGHsAEfKPi7K1MFNQ6z4Dvh8niT6CUI+SfRHThp:DNRZzse1cGH3UvKmFNQ6z2hT6CUI+4Hb
                                                                                                                                                                                                                                  MD5:EA7CF40852AFD55FFDA9DB29A0E11322
                                                                                                                                                                                                                                  SHA1:B7B42FAC93E250B54EB76D95048AC3132B10E6D8
                                                                                                                                                                                                                                  SHA-256:391B6E333D16497C4B538A7BDB5B16EF11359B6E3B508D470C6E3703488E3B4D
                                                                                                                                                                                                                                  SHA-512:123D78D6AC34AF4833D05814220757DCCF2A9AF4761FE67A8FE5F67A0D258B3C8D86ED346176FFB936AB3717CFD75B4FAB7373F7853D44FA356BE6E3A75E51B9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Bindings for Buttons, Checkbuttons, and Radiobuttons..#.# Notes: <Button1-Leave>, <Button1-Enter> only control the "pressed".# state; widgets remain "active" if the pointer is dragged out..# This doesn't seem to be conventional, but it's a nice way.# to provide extra feedback while the grab is active..# (If the button is released off the widget, the grab deactivates and.# we get a <Leave> event then, which turns off the "active" state).#.# Normally, <ButtonRelease> and <ButtonN-Enter/Leave> events are .# delivered to the widget which received the initial <ButtonPress>.# event. However, Tk [grab]s (#1223103) and menu interactions.# (#1222605) can interfere with this. To guard against spurious.# <Button1-Enter> events, the <Button1-Enter> binding only sets.# the pressed state if the button is currently active..#..namespace eval ttk::button {}..bind TButton <Enter> ..{ %W instate !disabled {%W state active} }.bind TButton <Leave>..{ %W state !active }.bind TButton <Key-space>.{ ttk:
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4742
                                                                                                                                                                                                                                  Entropy (8bit):4.859511673200619
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:9zDTlU3tCKW3PiAu4UZQsk+EBSucCtCqM368CtTU/+xgxaYgxaf/sY2+rF5usxzk:ZuHjO7uCkqM3JCNU/igxNgxor2tpuTM
                                                                                                                                                                                                                                  MD5:AA2987DC061DAA998B73A1AD937EE4BB
                                                                                                                                                                                                                                  SHA1:33FE9DFA76FB08B9D8D5C3554D13482D330C2DB1
                                                                                                                                                                                                                                  SHA-256:4ED0ACDD29FC1FB45C6BDC9EFB2CBADE34B93C45D5DBB269A4A4A3044CF4CB7A
                                                                                                                                                                                                                                  SHA-512:5A83B1FC88E42BB1DAD60D89CD5F2193E6AB59C4902A6C727E0090D1F395C2F122521FDFF250A14109EE5113D5034319199FB260129416EA962559350F217A03
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# "Clam" theme..#.# Inspired by the XFCE family of Gnome themes..#..namespace eval ttk::theme::clam {. variable colors . array set colors {..-disabledfg.."#999999"..-frame .."#dcdad5"..-window .."#ffffff"..-dark..."#cfcdc8"..-darker .."#bab5ab"..-darkest.."#9e9a91"..-lighter.."#eeebe7"..-lightest .."#ffffff"..-selectbg.."#4a6984"..-selectfg.."#ffffff"..-altindicator.."#5895bc"..-disabledaltindicator."#a0a0a0". }.. ttk::style theme settings clam {...ttk::style configure "." \.. -background $colors(-frame) \.. -foreground black \.. -bordercolor $colors(-darkest) \.. -darkcolor $colors(-dark) \.. -lightcolor $colors(-lighter) \.. -troughcolor $colors(-darker) \.. -selectbackground $colors(-selectbg) \.. -selectforeground $colors(-selectfg) \.. -selectborderwidth 0 \.. -font TkDefaultFont \.. ;...ttk::style map "." \.. -background [list disabled $colors(-frame) \.... active $colors(-lighter)] \.. -foreground [list disabled $colors(
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3828
                                                                                                                                                                                                                                  Entropy (8bit):4.892728136244756
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:yAJZjsTMw96Ey6kvzuVuby+x0M+x06uxjFVGQJFVGQuxzUFIGQutK2MRvD7J+iSz:yAJZ8MVJiVR+x/+xefVItuTy7Urt
                                                                                                                                                                                                                                  MD5:7DBF35F3F0F9FB68626019FF94EFBCD3
                                                                                                                                                                                                                                  SHA1:213F18224BF0573744836CD3BEDC83D5E443A406
                                                                                                                                                                                                                                  SHA-256:30E6766E9B8292793395324E412B0F5A8888512B84B080E247F95BF6EFB11A9D
                                                                                                                                                                                                                                  SHA-512:9081E5C89ECDE8337C5A52531DEF24924C0BCB3A1F0596D3B986CC59E635F67A78327ABF26209BF71A9BA370A93174298E6ABD11586382D7D70ADEA7E5CCF854
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# "classic" Tk theme..#.# Implements Tk's traditional Motif-like look and feel..#..namespace eval ttk::theme::classic {.. variable colors; array set colors {..-frame.."#d9d9d9"..-window.."#ffffff"..-activebg."#ececec"..-troughbg."#c3c3c3"..-selectbg."#c3c3c3"..-selectfg."#000000"..-disabledfg."#a3a3a3"..-indicator."#b03060"..-altindicator."#b05e5e". }.. ttk::style theme settings classic {..ttk::style configure "." \.. -font..TkDefaultFont \.. -background..$colors(-frame) \.. -foreground..black \.. -selectbackground.$colors(-selectbg) \.. -selectforeground.$colors(-selectfg) \.. -troughcolor.$colors(-troughbg) \.. -indicatorcolor.$colors(-frame) \.. -highlightcolor.$colors(-frame) \.. -highlightthickness.1 \.. -selectborderwidth.1 \.. -insertwidth.2 \.. ;...# To match pre-Xft X11 appearance, use:..#.ttk::style configure . -font {Helvetica 12 bold}...ttk::style map "." -background \.. [list disabled $colors(-frame) active $colors(-activeb
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):12493
                                                                                                                                                                                                                                  Entropy (8bit):5.024195855137721
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:l/9k9hqpFXQN9uK5Bt3NvnIW+KYNbrulkL90t98VrQETczIT9QeSaQjJI1/P0lcx:BhllSBtVL5MmI0K
                                                                                                                                                                                                                                  MD5:FBCAA6A08D9830114248F91E10D4C918
                                                                                                                                                                                                                                  SHA1:FA63C94824BEBD3531086816650D3F3FA73FE434
                                                                                                                                                                                                                                  SHA-256:9D80AA9701E82862467684D3DFF1A9EC5BBC2BBBA4F4F070518BBDE7E38499BB
                                                                                                                                                                                                                                  SHA-512:B377C31CC9137851679CBA0560EFE4265792D1576BD781DD42C22014A7A8F3D10D9D48A1154BB88A2987197594C8B728B71FA689CE1B32928F8513796A6A0AA3
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Combobox bindings..#.# <<NOTE-WM-TRANSIENT>>:.#.#.Need to set [wm transient] just before mapping the popdown.#.instead of when it's created, in case a containing frame.#.has been reparented [#1818441]..#.#.On Windows: setting [wm transient] prevents the parent.#.toplevel from becoming inactive when the popdown is posted.#.(Tk 8.4.8+).#.#.On X11: WM_TRANSIENT_FOR on override-redirect windows.#.may be used by compositing managers and by EWMH-aware.#.window managers (even though the older ICCCM spec says.#.it's meaningless)..#.#.On OSX: [wm transient] does utterly the wrong thing..#.Instead, we use [MacWindowStyle "help" "noActivates hideOnSuspend"]..#.The "noActivates" attribute prevents the parent toplevel.#.from deactivating when the popdown is posted, and is also.#.necessary for "help" windows to receive mouse events..#."hideOnSuspend" makes the popdown disappear (resp. reappear).#.when the parent toplevel is deactivated (resp. reactivated)..#.(see [#1814778]). Also set [wm resiz
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4007
                                                                                                                                                                                                                                  Entropy (8bit):4.827479665184231
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:xtIni2E1nmuVoLlTxG6qVXvDiPOaCkhxKLbqnJ2RLWumgMJVZlZPDjsfMh8vIviX:sn+myoLBxG3laOqJlZT3rkdSVOJm0
                                                                                                                                                                                                                                  MD5:74596004DFDBF2ECF6AF9C851156415D
                                                                                                                                                                                                                                  SHA1:933318C992B705BF9F8511621B4458ECB8772788
                                                                                                                                                                                                                                  SHA-256:7BDFFA1C2692C5D1CF67B518F9ACB32FA4B4D9936ED076F4DB835943BC1A00D6
                                                                                                                                                                                                                                  SHA-512:0D600B21DB67BF9DADBDD49559573078EFB41E473E94124AC4D2551BC10EC764846DC1F7674DAA79F8D2A8AEB4CA27A5E11C2F30EDE47E3ECEE77D60D7842262
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Map symbolic cursor names to platform-appropriate cursors..#.# The following cursors are defined:.#.#.standard.-- default cursor for most controls.#.""..-- inherit cursor from parent window.#.none..-- no cursor.#.#.text..-- editable widgets (entry, text).#.link..-- hyperlinks within text.#.crosshair.-- graphic selection, fine control.#.busy..-- operation in progress.#.forbidden.-- action not allowed.#.#.hresize..-- horizontal resizing.#.vresize..-- vertical resizing.#.# Also resize cursors for each of the compass points,.# {nw,n,ne,w,e,sw,s,se}resize..#.# Platform notes:.#.# Windows doesn't distinguish resizing at the 8 compass points,.# only horizontal, vertical, and the two diagonals..#.# OSX doesn't have resize cursors for nw, ne, sw, or se corners..# We use the Tk-defined X11 fallbacks for these..#.# X11 doesn't have a "forbidden" cursor (usually a slashed circle);.# "pirate" seems to be the conventional cursor for this purpose..#.# Windows has an IDC_HELP cursor, but it's not
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4490
                                                                                                                                                                                                                                  Entropy (8bit):4.888203318286333
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:AMUoi/higxS4JAigxS4J/1+tDtj/9uTaf30QOdt:AMUoQhigQ42igQ4kFMY3n0t
                                                                                                                                                                                                                                  MD5:0E03292F7678540CB4F3440859863B0C
                                                                                                                                                                                                                                  SHA1:909849894B02F2C213BDE0FBCED8C1378EB9B81E
                                                                                                                                                                                                                                  SHA-256:304FF31FC82F6086C93AAA594D83D8DA25866CE1C2AF1208F9E7585D74CA9A51
                                                                                                                                                                                                                                  SHA-512:87E5D2484E5E7E3C00B319219028B012576B7D73B84A9A13ED15551C9431BF216C0B96376AE5A7070B5A391D9887E55ABF9FA4AFEE971177408B7969363D9302
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Settings for default theme..#..namespace eval ttk::theme::default {. variable colors. array set colors {..-frame..."#d9d9d9"..-foreground.."#000000"..-window..."#ffffff"..-text .."#000000"..-activebg.."#ececec"..-selectbg.."#4a6984"..-selectfg.."#ffffff"..-darker .."#c3c3c3"..-disabledfg.."#a3a3a3"..-indicator.."#4a6984"..-disabledindicator."#a3a3a3"..-altindicator.."#9fbdd8"..-disabledaltindicator."#c0c0c0". }.. ttk::style theme settings default {...ttk::style configure "." \.. -borderwidth .1 \.. -background .$colors(-frame) \.. -foreground .$colors(-foreground) \.. -troughcolor .$colors(-darker) \.. -font ..TkDefaultFont \.. -selectborderwidth.1 \.. -selectbackground.$colors(-selectbg) \.. -selectforeground.$colors(-selectfg) \.. -insertwidth .1 \.. -indicatordiameter.10 \.. ;...ttk::style map "." -background \.. [list disabled $colors(-frame) active $colors(-activebg)]..ttk::style map "." -foreground \.. [list disabled $colo
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):16408
                                                                                                                                                                                                                                  Entropy (8bit):4.974125903666712
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:hRy3ALQksU0oayTUXIQzNiQ2iEL8QmOhQVqknFoTOXyJtcC1JMuZm4FZxO252ExD:GoUXmiEyOFWiTOEtcC1q252Ezp
                                                                                                                                                                                                                                  MD5:F9B29AB14304F18E32821A29233BE816
                                                                                                                                                                                                                                  SHA1:6D0253274D777E081FA36CC38E51C2ABB9259D0E
                                                                                                                                                                                                                                  SHA-256:62D1DF52C510A83103BADAB4F3A77ABB1AA3A0E1E21F68ECE0CECCA2CA2F1341
                                                                                                                                                                                                                                  SHA-512:698DB665E29B29864F9FE65934CCA83A5092D81D5130FFD1EAC68C51327AE9EBC007A60A60E1AF37063017E448CE84A4024D4A412990A1078287B605DF344C70
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# DERIVED FROM: tk/library/entry.tcl r1.22.#.# Copyright (c) 1992-1994 The Regents of the University of California..# Copyright (c) 1994-1997 Sun Microsystems, Inc..# Copyright (c) 2004, Joe English.#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES..#..namespace eval ttk {. namespace eval entry {..variable State...set State(x) 0..set State(selectMode) none..set State(anchor) 0..set State(scanX) 0..set State(scanIndex) 0..set State(scanMoved) 0...# Button-2 scan speed is (scanNum/scanDen) characters..# per pixel of mouse movement...# The standard Tk entry widget uses the equivalent of..# scanNum = 10, scanDen = average character width...# I don't know why that was chosen...#..set State(scanNum) 1..set State(scanDen) 1..set State(deadband) 3.;# #pixels for mouse-moved deadband.. }.}..### Option database settings..#.option add *TEntry.cursor [ttk::cursor text] widgetDefault..### Bindings..#.# Removed
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5576
                                                                                                                                                                                                                                  Entropy (8bit):4.956417003071239
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:Nduphbitcq1Zs/ZrBiZy227IhLkdhetOstWGbRafkeHH+4:3CheHvsbiZyDmJbRa3+4
                                                                                                                                                                                                                                  MD5:7017B5C1D53F341F703322A40C76C925
                                                                                                                                                                                                                                  SHA1:57540C56C92CC86F94B47830A00C29F826DEF28E
                                                                                                                                                                                                                                  SHA-256:0EB518251FBE9CF0C9451CC1FEF6BB6AEE16D62DA00B0050C83566DA053F68D0
                                                                                                                                                                                                                                  SHA-512:FD18976A8FBB7E59B12944C2628DBD66D463B2F7342661C8F67160DF37A393FA3C0CE7FDDA31073674B7A46E0A0A7D0A7B29EBE0D9488AFD9EF8B3A39410B5A8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Font specifications..#.# This file, [source]d at initialization time, sets up the following.# symbolic fonts based on the current platform:.#.# TkDefaultFont.-- default for GUI items not otherwise specified.# TkTextFont.-- font for user text (entry, listbox, others).# TkFixedFont.-- standard fixed width font.# TkHeadingFont.-- headings (column headings, etc).# TkCaptionFont -- dialog captions (primary text in alert dialogs, etc.).# TkTooltipFont.-- font to use for tooltip windows.# TkIconFont.-- font to use for icon captions.# TkMenuFont.-- used to use for menu items.#.# In Tk 8.5, some of these fonts may be provided by the TIP#145 implementation.# (On Windows and Mac OS X as of Oct 2007)..#.# +++ Platform notes:.#.# Windows:.#.The default system font changed from "MS Sans Serif" to "Tahoma".# .in Windows XP/Windows 2000..#.#.MS documentation says to use "Tahoma 8" in Windows 2000/XP,.#.although many MS programs still use "MS Sans Serif 8".#.#.Should use SystemParametersInfo() inst
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4913
                                                                                                                                                                                                                                  Entropy (8bit):4.841521491900473
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:1reigApQy38gaQJy+3nN+PN8JdNhtOPqoK4J+wQCV7EkGxIaqc9ld9qtlWnITOZI:hfbJvnN+PN8JdNHs64J+wQCPGxtqWrqf
                                                                                                                                                                                                                                  MD5:DB24841643CEBD38D5FFD1D42B42E7F4
                                                                                                                                                                                                                                  SHA1:E394AF7FAF83FAD863C7B13D855FCF3705C4F1C7
                                                                                                                                                                                                                                  SHA-256:81B0B7818843E293C55FF541BD95168DB51FE760941D32C7CDE9A521BB42E956
                                                                                                                                                                                                                                  SHA-512:380272D003D5F90C13571952D0C73F5FCE2A22330F98F29707F3D5BFC29C99D9BF11A947CF2CA64CF7B8DF5E4AFE56FFA00F9455BB30D15611FC5C86130346BE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Bindings for Menubuttons..#.# Menubuttons have three interaction modes:.#.# Pulldown: Press menubutton, drag over menu, release to activate menu entry.# Popdown: Click menubutton to post menu.# Keyboard: <Key-space> or accelerator key to post menu.#.# (In addition, when menu system is active, "dropdown" -- menu posts.# on mouse-over. Ttk menubuttons don't implement this)..#.# For keyboard and popdown mode, we hand off to tk_popup and let .# the built-in Tk bindings handle the rest of the interaction..#.# ON X11:.#.# Standard Tk menubuttons use a global grab on the menubutton..# This won't work for Ttk menubuttons in pulldown mode,.# since we need to process the final <ButtonRelease> event,.# and this might be delivered to the menu. So instead we.# rely on the passive grab that occurs on <ButtonPress> events,.# and transition to popdown mode when the mouse is released.# or dragged outside the menubutton..# .# ON WINDOWS:.#.# I'm not sure what the hell is going on here. [$menu pos
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):5619
                                                                                                                                                                                                                                  Entropy (8bit):4.937953914483602
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:d4tDJf49tzG809fhQAKWCgQOK/6PF+hEi8YYFSL+3FJVCj0QlK2kfJcQIni:d4tktzwfWngQOK/6PF+hDDYFNJVCj0Q2
                                                                                                                                                                                                                                  MD5:82C9DFC512E143DDA78F91436937D4DD
                                                                                                                                                                                                                                  SHA1:26ABC23C1E0C201A217E3CEA7A164171418973B0
                                                                                                                                                                                                                                  SHA-256:D1E5267CDE3D7BE408B4C94220F7E1833C9D452BB9BA3E194E12A5EB2F9ADB80
                                                                                                                                                                                                                                  SHA-512:A9D3C04AD67E0DC3F1C12F9E21EF28A61FA84DBF710313D4CA656BDF35DFBBFBA9C268C018004C1F5614DB3A1128025D795BC14B4FFFAA5603A5313199798D04
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Bindings for TNotebook widget.#..namespace eval ttk::notebook {. variable TLNotebooks ;# See enableTraversal.}..bind TNotebook <ButtonPress-1>..{ ttk::notebook::Press %W %x %y }.bind TNotebook <Key-Right>..{ ttk::notebook::CycleTab %W 1; break }.bind TNotebook <Key-Left>..{ ttk::notebook::CycleTab %W -1; break }.bind TNotebook <Control-Key-Tab>.{ ttk::notebook::CycleTab %W 1; break }.bind TNotebook <Control-Shift-Key-Tab>.{ ttk::notebook::CycleTab %W -1; break }.catch {.bind TNotebook <Control-ISO_Left_Tab>.{ ttk::notebook::CycleTab %W -1; break }.}.bind TNotebook <Destroy>..{ ttk::notebook::Cleanup %W }..# ActivateTab $nb $tab --.#.Select the specified tab and set focus..#.# Desired behavior:.#.+ take focus when reselecting the currently-selected tab;.#.+ keep focus if the notebook already has it;.#.+ otherwise set focus to the first traversable widget.#. in the newly-selected tab;.#.+ do not leave the focus in a deselected tab..#.proc ttk::notebook::ActivateTab {w tab} {.
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1920
                                                                                                                                                                                                                                  Entropy (8bit):4.916119835701688
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:kfkVpfktNZz51kfkB6fkO/cfkyk2fkI4fkI1fkxUufkYfkEtNMiyHvyPHfk9tNZ5:0ZPhMiyHvyPQZNtiisZvUriZPaa+fdl
                                                                                                                                                                                                                                  MD5:A12915FA5CAF93E23518E9011200F5A4
                                                                                                                                                                                                                                  SHA1:A61F665A408C10419FB81001578D99B43D048720
                                                                                                                                                                                                                                  SHA-256:CE0053D637B580170938CF552B29AE890559B98EB28038C2F0A23A265DDEB273
                                                                                                                                                                                                                                  SHA-512:669E1D66F1223CCA6CEB120914D5D876BD3CF401EE4A46F35825361076F19C7341695596A7DBB00D6CFF4624666FB4E7A2D8E7108C3C56A12BDA7B04E99E6F9A
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Bindings for ttk::panedwindow widget..#..namespace eval ttk::panedwindow {. variable State. array set State {..pressed 0. .pressX.-..pressY.-..sash .-..sashPos -. }.}..## Bindings:.#.bind TPanedwindow <ButtonPress-1> .{ ttk::panedwindow::Press %W %x %y }.bind TPanedwindow <B1-Motion>..{ ttk::panedwindow::Drag %W %x %y }.bind TPanedwindow <ButtonRelease-1> .{ ttk::panedwindow::Release %W %x %y }..bind TPanedwindow <Motion> ..{ ttk::panedwindow::SetCursor %W %x %y }.bind TPanedwindow <Enter> ..{ ttk::panedwindow::SetCursor %W %x %y }.bind TPanedwindow <Leave> ..{ ttk::panedwindow::ResetCursor %W }.# See <<NOTE-PW-LEAVE-NOTIFYINFERIOR>>.bind TPanedwindow <<EnteredChild>>.{ ttk::panedwindow::ResetCursor %W }..## Sash movement:.#.proc ttk::panedwindow::Press {w x y} {. variable State.. set sash [$w identify $x $y]. if {$sash eq ""} {. .set State(pressed) 0..return. }. set State(pressed) .1. set State(pressX) .$x. set State(pressY) .$y. set State(sa
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1089
                                                                                                                                                                                                                                  Entropy (8bit):4.7101709883442755
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:o83oOUyNSiBj0oNA7h5EwIa2s0ImxamrNlUImyJDirNPpwWgJ:oMtS6j0eyEw0s02mhlU4khPp4J
                                                                                                                                                                                                                                  MD5:B0074341A4BDA36BCDFF3EBCAE39EB73
                                                                                                                                                                                                                                  SHA1:D070A01CC5A787249BC6DAD184B249C4DD37396A
                                                                                                                                                                                                                                  SHA-256:A9C34F595E547CE94EE65E27C415195D2B210653A9FFCFB39559C5E0FA9C06F8
                                                                                                                                                                                                                                  SHA-512:AF23563602886A648A42B03CC5485D84FCC094AB90B08DF5261434631B6C31CE38D83A3A60CC7820890C797F6C778D5B5EFF47671CE3EE4710AB14C6110DCC35
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Ttk widget set: progress bar utilities..#..namespace eval ttk::progressbar {. variable Timers.;# Map: widget name -> after ID.}..# Autoincrement --.#.Periodic callback procedure for autoincrement mode.#.proc ttk::progressbar::Autoincrement {pb steptime stepsize} {. variable Timers.. if {![winfo exists $pb]} {. .# widget has been destroyed -- cancel timer..unset -nocomplain Timers($pb)..return. }.. set Timers($pb) [after $steptime \. .[list ttk::progressbar::Autoincrement $pb $steptime $stepsize] ].. $pb step $stepsize.}..# ttk::progressbar::start --.#.Start autoincrement mode. Invoked by [$pb start] widget code..#.proc ttk::progressbar::start {pb {steptime 50} {stepsize 1}} {. variable Timers. if {![info exists Timers($pb)]} {..Autoincrement $pb $steptime $stepsize. }.}..# ttk::progressbar::stop --.#.Cancel autoincrement mode. Invoked by [$pb stop] widget code..#.proc ttk::progressbar::stop {pb} {. variable Timers. if {[info exists Timers($pb
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2698
                                                                                                                                                                                                                                  Entropy (8bit):4.7624002445430955
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:6Zsdayx/HZtYRqucO6wEKyRtZt0TcKVqZ4TFZkPDMiNf:Wde/5tYRquMwEKyFt0TcKVG4TrkLMwf
                                                                                                                                                                                                                                  MD5:B41A9DF31924DEA36D69CB62891E8472
                                                                                                                                                                                                                                  SHA1:4C2877FBB210FDBBDE52EA8B5617F68AD2DF7B93
                                                                                                                                                                                                                                  SHA-256:25D0FE2B415292872EF7ACDB2DFA12D04C080B7F9B1C61F28C81AA2236180479
                                                                                                                                                                                                                                  SHA-512:A50DB6DA3D40D07610629DE45F06A438C6F2846324C3891C54C99074CFB7BEED329F27918C8A85BADB22C6B64740A2053B891F8E5D129D9B0A1FF103E7137D83
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# scale.tcl - Copyright (C) 2004 Pat Thoyts <patthoyts@users.sourceforge.net>.#.# Bindings for the TScale widget..namespace eval ttk::scale {. variable State. array set State {..dragging 0. }.}..bind TScale <ButtonPress-1> { ttk::scale::Press %W %x %y }.bind TScale <B1-Motion> { ttk::scale::Drag %W %x %y }.bind TScale <ButtonRelease-1> { ttk::scale::Release %W %x %y }..bind TScale <ButtonPress-2> { ttk::scale::Jump %W %x %y }.bind TScale <B2-Motion> { ttk::scale::Drag %W %x %y }.bind TScale <ButtonRelease-2> { ttk::scale::Release %W %x %y }..bind TScale <ButtonPress-3> { ttk::scale::Jump %W %x %y }.bind TScale <B3-Motion> { ttk::scale::Drag %W %x %y }.bind TScale <ButtonRelease-3> { ttk::scale::Release %W %x %y }..## Keyboard navigation bindings:.#.bind TScale <<LineStart>> { %W set [%W cget -from] }.bind TScale <<LineEnd>> { %W set [%W cget -to] }..bind TScale <<PrevChar>> { ttk::scale::Increment %W -1 }.bind TScale <<PrevLine>> {
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):3097
                                                                                                                                                                                                                                  Entropy (8bit):4.913511104649656
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:OsSofRsvfH3Noo2kvrjnWG3Lcyst0Rhrdy:plcHdoorDjWEFeuTy
                                                                                                                                                                                                                                  MD5:93181DBE76EF9C39849A09242D6DF8C0
                                                                                                                                                                                                                                  SHA1:DE3B47AFC3E5371BF1CD0541790A9B78A97570AB
                                                                                                                                                                                                                                  SHA-256:5932043286A30A3CFFB2B6CE68CCDB9172A718F32926E25D3A962AE63CAD515C
                                                                                                                                                                                                                                  SHA-512:5C85284E063A5DE17F6CE432B3EF899D046A78725BD1F930229576BED1116C03A3EE0611B988E9903F47DA8F694483E5A76464450C48EB14622F6784004B8F7E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Bindings for TScrollbar widget.#..# Still don't have a working ttk::scrollbar under OSX -.# Swap in a [tk::scrollbar] on that platform,.# unless user specifies -class or -style..#.if {[tk windowingsystem] eq "aqua"} {. rename ::ttk::scrollbar ::ttk::_scrollbar. proc ttk::scrollbar {w args} {..set constructor ::tk::scrollbar..foreach {option _} $args {.. if {$option eq "-class" || $option eq "-style"} {...set constructor ::ttk::_scrollbar...break.. }..}..return [$constructor $w {*}$args]. }.}..namespace eval ttk::scrollbar {. variable State. # State(xPress).--. # State(yPress).-- initial position of mouse at start of drag.. # State(first).-- value of -first at start of drag..}..bind TScrollbar <ButtonPress-1> .{ ttk::scrollbar::Press %W %x %y }.bind TScrollbar <B1-Motion>..{ ttk::scrollbar::Drag %W %x %y }.bind TScrollbar <ButtonRelease-1>.{ ttk::scrollbar::Release %W %x %y }..bind TScrollbar <ButtonPress-2> .{ ttk::scrollbar::Jump %W %x %y }.bind TScrollb
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2406
                                                                                                                                                                                                                                  Entropy (8bit):4.78080326075935
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:KqL4LUBItZ3EZEhHR4vuRbMMie8GMW/H7vZZNQdqrYfy2nL+ZZvBb:KDYBIjHHRmiM1qvbnNQdqriyQIvB
                                                                                                                                                                                                                                  MD5:3C8916A58C6EE1D61836E500A54C9321
                                                                                                                                                                                                                                  SHA1:54F3F709698FAD020A048668749CB5A09EDE35AB
                                                                                                                                                                                                                                  SHA-256:717D2EDD71076EA059903C7144588F8BBD8B0AFE69A55CBF23953149D6694D33
                                                                                                                                                                                                                                  SHA-512:2B71569A5A96CAC1B708E894A2466B1054C3FAE5405E10799B182012141634BD2A7E9E9F516658E1A6D6E9E776E397608B581501A6CFE2EB4EC54459E9ECB267
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Sizegrip widget bindings..#.# Dragging a sizegrip widget resizes the containing toplevel..#.# NOTE: the sizegrip widget must be in the lower right hand corner..#..switch -- [tk windowingsystem] {. x11 -. win32 {..option add *TSizegrip.cursor [ttk::cursor seresize] widgetDefault. }. aqua {. .# Aqua sizegrips use default Arrow cursor.. }.}..namespace eval ttk::sizegrip {. variable State. array set State {..pressed .0..pressX ..0..pressY ..0..width ..0..height ..0..widthInc.1..heightInc.1. resizeX 1. resizeY 1..toplevel .{}. }.}..bind TSizegrip <ButtonPress-1> ..{ ttk::sizegrip::Press.%W %X %Y }.bind TSizegrip <B1-Motion> ..{ ttk::sizegrip::Drag .%W %X %Y }.bind TSizegrip <ButtonRelease-1> .{ ttk::sizegrip::Release %W %X %Y }..proc ttk::sizegrip::Press {W X Y} {. variable State.. if {[$W instate disabled]} { return }.. set top [winfo toplevel $W].. # If the toplevel is not resizable then bail. foreach {State(resiz
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4255
                                                                                                                                                                                                                                  Entropy (8bit):4.9576194953603006
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:17n+wMf6/ocy2nO6lz+Ni2QQ0Q3LqSFLfhrxJSS3hQb:ln+wMOxVlaNi2QQ0QbdFLfhrxJzhQb
                                                                                                                                                                                                                                  MD5:86BCA3AB915C2774425B70420E499140
                                                                                                                                                                                                                                  SHA1:FD4798D79EEBA9CFFABCB2548068591DB531A716
                                                                                                                                                                                                                                  SHA-256:51F8A6C772648541684B48622FFE41B77871A185A8ACD11E9DEC9EC41D65D9CD
                                                                                                                                                                                                                                  SHA-512:659FB7E1631ED898E3C11670A04B953EB05CECB42A3C5EFBDD1BD97A7F99061920FD5DB3915476F224BB2C72358623E1B474B0FC3FBB7FD3734487B87A388FD7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# ttk::spinbox bindings.#..namespace eval ttk::spinbox { }..### Spinbox bindings..#.# Duplicate the Entry bindings, override if needed:.#..ttk::copyBindings TEntry TSpinbox..bind TSpinbox <Motion>...{ ttk::spinbox::Motion %W %x %y }.bind TSpinbox <ButtonPress-1> ..{ ttk::spinbox::Press %W %x %y }.bind TSpinbox <ButtonRelease-1> .{ ttk::spinbox::Release %W }.bind TSpinbox <Double-Button-1> .{ ttk::spinbox::DoubleClick %W %x %y }.bind TSpinbox <Triple-Button-1> .{} ;# disable TEntry triple-click..bind TSpinbox <KeyPress-Up>..{ event generate %W <<Increment>> }.bind TSpinbox <KeyPress-Down> ..{ event generate %W <<Decrement>> }..bind TSpinbox <<Increment>>..{ ttk::spinbox::Spin %W +1 }.bind TSpinbox <<Decrement>> ..{ ttk::spinbox::Spin %W -1 }..ttk::bindMouseWheel TSpinbox ..[list ttk::spinbox::MouseWheel %W]..## Motion --.#.Sets cursor..#.proc ttk::spinbox::Motion {w x y} {. if { [$w identify $x $y] eq "textarea". && [$w instate {!readonly !disabled}]. } {..ttk::setCurso
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8898
                                                                                                                                                                                                                                  Entropy (8bit):4.860766938410698
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:2Ou002WQZ4sNNxjKomA3xj9L/37NbbF3r3G4eeMxCSbk3TPMrngEibSB1GjwPBKf:ZWeZ5BDFK+DsXibSQUMHLCGLdE2bZ
                                                                                                                                                                                                                                  MD5:46B1D0EADBCF11AC51DD14B1A215AE04
                                                                                                                                                                                                                                  SHA1:339026AE9533F4C331ADF8C71799B222DDD89D4F
                                                                                                                                                                                                                                  SHA-256:DB6FAA8540C322F3E314968256D8AFFF39A1E4700EC17C7EFE364241F355D80F
                                                                                                                                                                                                                                  SHA-512:0FC81426857949D5AC9FE7FF3C85A1270BD35BF6E6EAF3FE7AE0DE22A0C0E5CD96D6C9471216DC1DA673FAD949CA96A3751C3D3222474D2206AA9D8A455BA12E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# ttk::treeview widget bindings and utilities..#..namespace eval ttk::treeview {. variable State.. # Enter/Leave/Motion. #. set State(activeWidget) .{}. set State(activeHeading) .{}.. # Press/drag/release:. #. set State(pressMode) .none. set State(pressX)..0.. # For pressMode == "resize". set State(resizeColumn).#0.. # For pressmode == "heading". set State(heading) .{}.}..### Widget bindings..#..bind Treeview.<Motion> ..{ ttk::treeview::Motion %W %x %y }.bind Treeview.<B1-Leave>..{ #nothing }.bind Treeview.<Leave>...{ ttk::treeview::ActivateHeading {} {}}.bind Treeview.<ButtonPress-1> .{ ttk::treeview::Press %W %x %y }.bind Treeview.<Double-ButtonPress-1> .{ ttk::treeview::DoubleClick %W %x %y }.bind Treeview.<ButtonRelease-1> .{ ttk::treeview::Release %W %x %y }.bind Treeview.<B1-Motion> ..{ ttk::treeview::Drag %W %x %y }.bind Treeview .<KeyPress-Up> .{ ttk::treeview::Keynav %W up }.bind Treeview .<KeyPress-Down> .{ ttk::treeview::Keynav %
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4546
                                                                                                                                                                                                                                  Entropy (8bit):4.888987944406022
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:96:53a25129CKELfMonw+PzpaVnNqovaq2126262R2D2q2k2j+/2FhbtpGt0vcWOQRg:53j5MoKE7JEnN7CTMDDA6Tlj+uFhbttK
                                                                                                                                                                                                                                  MD5:E38B399865C45E49419C01FF2ADDCE75
                                                                                                                                                                                                                                  SHA1:F8A79CBC97A32622922D4A3A5694BCCB3F19DECB
                                                                                                                                                                                                                                  SHA-256:61BAA0268770F127394A006340D99CE831A1C7AD773181C0C13122F7D2C5B7F6
                                                                                                                                                                                                                                  SHA-512:285F520B648F5EC70DD79190C3B456F4D6DA2053210985F9E2C84139D8D51908296E4962B336894EE30536F09FAE84B912BC2ABF44A7011620F66CC5D9F71A8C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Ttk widget set initialization script..#..### Source library scripts..#..namespace eval ::ttk {. variable library. if {![info exists library]} {..set library [file dirname [info script]]. }.}..source [file join $::ttk::library fonts.tcl].source [file join $::ttk::library cursors.tcl].source [file join $::ttk::library utils.tcl]..## ttk::deprecated $old $new --.#.Define $old command as a deprecated alias for $new command.#.$old and $new must be fully namespace-qualified..#.proc ttk::deprecated {old new} {. interp alias {} $old {} ttk::do'deprecate $old $new.}.## do'deprecate --.#.Implementation procedure for deprecated commands --.#.issue a warning (once), then re-alias old to new..#.proc ttk::do'deprecate {old new args} {. deprecated'warning $old $new. interp alias {} $old {} $new. uplevel 1 [linsert $args 0 $new].}..## deprecated'warning --.#.Gripe about use of deprecated commands..#.proc ttk::deprecated'warning {old new} {. puts stderr "$old deprecated -- u
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):8562
                                                                                                                                                                                                                                  Entropy (8bit):4.958950985117383
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:MpEpXI4jqmW/y3gp9F+QE9PBRc+vWHJOfqW8j3ki3LDRdielRu+MXw+:6yXuwg1oPnc+epOEj31/s/5
                                                                                                                                                                                                                                  MD5:65193FE52D77B8726B75FBF909EE860A
                                                                                                                                                                                                                                  SHA1:991DEDD4666462DD9776FDF6C21F24D6CF794C85
                                                                                                                                                                                                                                  SHA-256:C7CC9A15CFA999CF3763772729CC59F629E7E060AF67B7D783C50530B9B756E1
                                                                                                                                                                                                                                  SHA-512:E43989F5F368D2E19C9A3521FB82C6C1DD9EEB91DF936A980FFC7674C8B236CB84E113908B8C9899B85430E8FC30315BDEC891071822D701C91C5978096341B7
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Utilities for widget implementations..#..### Focus management..#.# See also: #1516479.#..## ttk::takefocus --.#.This is the default value of the "-takefocus" option.#.for ttk::* widgets that participate in keyboard navigation..#.# NOTES:.#.tk::FocusOK (called by tk_focusNext) tests [winfo viewable].#.if -takefocus is 1, empty, or missing; but not if it's a.#.script prefix, so we have to check that here as well..#.#.proc ttk::takefocus {w} {. expr {[$w instate !disabled] && [winfo viewable $w]}.}..## ttk::GuessTakeFocus --.#.This routine is called as a fallback for widgets.#.with a missing or empty -takefocus option..#.#.It implements the same heuristics as tk::FocusOK..#.proc ttk::GuessTakeFocus {w} {. # Don't traverse to widgets with '-state disabled':. #. if {![catch {$w cget -state} state] && $state eq "disabled"} {..return 0. }.. # Allow traversal to widgets with explicit key or focus bindings:. #. if {[regexp {Key|Focus} [concat [bind $w] [bind [winfo c
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):9670
                                                                                                                                                                                                                                  Entropy (8bit):4.6132627565634055
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:kSsdZ6XzgE2kiSCyNPNVVSCIA5l/r5l/rW+i/CE38S7r/2JeJnpna+yfdyMq53Id:QZ6XzD2kFVeArPKJ3z7cQ0383cdd
                                                                                                                                                                                                                                  MD5:ED071B9CEA98B7594A7E74593211BD38
                                                                                                                                                                                                                                  SHA1:90998A1A51BCBAA3B4D72B08F5CBF19E330148D2
                                                                                                                                                                                                                                  SHA-256:98180630FC1E8D7D7C1B20A5FF3352C8BD8CF259DD4EB3B829B8BD4CB8AE76A4
                                                                                                                                                                                                                                  SHA-512:60C1EA45481AF5CFA3C5E579514DD3F4AC6C8D168553F374D0A3B3E1342E76CB71FA825C306233E185BED057E2B99877BAF9A5E88EBD48CF6DE171A8E7F6A230
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Settings for Microsoft Windows Vista and Server 2008.#..# The Vista theme can only be defined on Windows Vista and above. The theme.# is created in C due to the need to assign a theme-enabled function for .# detecting when themeing is disabled. On systems that cannot support the.# Vista theme, there will be no such theme created and we must not.# evaluate this script...if {"vista" ni [ttk::style theme names]} {. return.}..namespace eval ttk::theme::vista {.. ttk::style theme settings vista {.. .ttk::style configure . \.. -background SystemButtonFace \.. -foreground SystemWindowText \.. -selectforeground SystemHighlightText \.. -selectbackground SystemHighlight \.. -insertcolor SystemWindowText \.. -font TkDefaultFont \.. ;...ttk::style map "." \.. -foreground [list disabled SystemGrayText] \.. ;...ttk::style configure TButton -anchor center -padding {1 1} -width -11..ttk::style configure TRadiobutton -padding 2..ttk::style configure TCheckbutton -pa
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2867
                                                                                                                                                                                                                                  Entropy (8bit):4.876730704118724
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:679ahSh6FPGh0Ds0IXF6yjAfSAfqFRaBgLtei42kt+5Ql/n+iOaVhttZLgtKZLtO:6UJM0uTk5tm4RX0
                                                                                                                                                                                                                                  MD5:0AE8205DFBA3C9B8EEAD01AC11C965D6
                                                                                                                                                                                                                                  SHA1:61E8D2E909CF46886F6EA8571D4234DD336FEFB3
                                                                                                                                                                                                                                  SHA-256:93E4011CAA9F01802D6DD5E02C3104E619084799E949974DFEE5E0C94D1E3952
                                                                                                                                                                                                                                  SHA-512:E4448B922CA0FB425F879988537B9DB8F8C8A5A773805607574499506FDD9DEEB9CD41660E497002F78727AFBE3BEC17D9674E99CEF4A9D66FFD9C4536AFE153
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Settings for 'winnative' theme..#..namespace eval ttk::theme::winnative {. ttk::style theme settings winnative {...ttk::style configure "." \.. -background SystemButtonFace \.. -foreground SystemWindowText \.. -selectforeground SystemHighlightText \.. -selectbackground SystemHighlight \.. -fieldbackground SystemWindow \.. -insertcolor SystemWindowText \.. -troughcolor SystemScrollbar \.. -font TkDefaultFont \.. ;...ttk::style map "." -foreground [list disabled SystemGrayText] ;. ttk::style map "." -embossed [list disabled 1] ;...ttk::style configure TButton \.. -anchor center -width -11 -relief raised -shiftrelief 1..ttk::style configure TCheckbutton -padding "2 4"..ttk::style configure TRadiobutton -padding "2 4"..ttk::style configure TMenubutton \.. -padding "8 4" -arrowsize 3 -relief raised...ttk::style map TButton -relief {{!disabled pressed} sunken}...ttk::style configure TEntry \.. -padding 2 -selectborderwidth 0 -insertwidth 1..t
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):2375
                                                                                                                                                                                                                                  Entropy (8bit):4.931678702435916
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:48:NaxYun9ahShCd/T5QNt+7aVzEmAf8Afb9AfMMB+iOaVhttZLgtKZLti:k41eTXM
                                                                                                                                                                                                                                  MD5:BD892A940333C1B804DF5C4594B0A5E6
                                                                                                                                                                                                                                  SHA1:4E187F09F45898749CFE7860EDEF0D5EB83D764E
                                                                                                                                                                                                                                  SHA-256:196C6FEF40FB6296D7762F30058AA73273083906F72F490E69FC77F1D5589B88
                                                                                                                                                                                                                                  SHA-512:8273A8F789D695601A7BC74DFA2A6BD7FE280EC528869F502A578E90B6DD1613C4BCC5B6CD0D93A5CA0E6538BE740CD370F634DA84064213E1F50B919EBF35B8
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:#.# Settings for 'xpnative' theme.#..namespace eval ttk::theme::xpnative {.. ttk::style theme settings xpnative {...ttk::style configure . \.. -background SystemButtonFace \.. -foreground SystemWindowText \.. -selectforeground SystemHighlightText \.. -selectbackground SystemHighlight \.. -insertcolor SystemWindowText \.. -font TkDefaultFont \.. ;...ttk::style map "." \.. -foreground [list disabled SystemGrayText] \.. ;...ttk::style configure TButton -anchor center -padding {1 1} -width -11..ttk::style configure TRadiobutton -padding 2..ttk::style configure TCheckbutton -padding 2..ttk::style configure TMenubutton -padding {8 4}...ttk::style configure TNotebook -tabmargins {2 2 2 0}..ttk::style map TNotebook.Tab \.. -expand [list selected {2 2 2 2}]...# Treeview:..ttk::style configure Heading -font TkHeadingFont..ttk::style configure Treeview -background SystemWindow..ttk::style map Treeview \.. -background [list selected SystemHighlight] \.. -fore
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10252
                                                                                                                                                                                                                                  Entropy (8bit):5.02143730499245
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:1kMv11IDCB7PFPHGosvS6UMn8O9MGM/OTMjcrrwrt:xuMYMj+sZ
                                                                                                                                                                                                                                  MD5:C832FDF24CA1F5C5E9B33FA5ECD11CAC
                                                                                                                                                                                                                                  SHA1:8082FDE50C428D2511B05F529FCCF02651D5AC93
                                                                                                                                                                                                                                  SHA-256:E34D828E740F151B96022934AAEC7BB8343E23D040FB54C04641888F51767EB8
                                                                                                                                                                                                                                  SHA-512:58BEB05778271D4C91527B1CB23491962789D95ACCBC6C28E25D05BD3D6172AAC9A90E7741CD606C69FB8CECC29EE515DA7C7D4E6098BF67F08F18DFB7983323
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# unsupported.tcl --.#.# Commands provided by Tk without official support. Use them at your.# own risk. They may change or go away without notice..#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES...# ----------------------------------------------------------------------.# Unsupported compatibility interface for folks accessing Tk's private.# commands and variable against recommended usage..# ----------------------------------------------------------------------..namespace eval ::tk::unsupported {.. # Map from the old global names of Tk private commands to their. # new namespace-encapsulated names... variable PrivateCommands. array set PrivateCommands {..tkButtonAutoInvoke..::tk::ButtonAutoInvoke..tkButtonDown...::tk::ButtonDown..tkButtonEnter...::tk::ButtonEnter..tkButtonInvoke...::tk::ButtonInvoke..tkButtonLeave...::tk::ButtonLeave..tkButtonUp...::tk::ButtonUp..tkCancelRepeat...::tk::Cance
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):26075
                                                                                                                                                                                                                                  Entropy (8bit):4.9212533677507535
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:obPA7Xi6V2+Bec3ipnFH6HZ1KDZvRcbQ3sd1GkjDo413lK/RIV5MXrSomsjiETwM:orA3TVJc3sd1GkF3cIVf591w
                                                                                                                                                                                                                                  MD5:F863B7C5680017EE9F744900CC6C3834
                                                                                                                                                                                                                                  SHA1:155E6E8752F6D48EF8D32CE2228E17EE58C2768E
                                                                                                                                                                                                                                  SHA-256:9C78A976BBC933863FB0E4C23EE62B26F8EB3D7F101D7D32E6768579499E43B1
                                                                                                                                                                                                                                  SHA-512:34F5B51EA1A2EFCD53B51A74E7E9B69FB154E017527BBD1CB3961F1619E74BE9D49D0583D193DBA7E8A3904F6C7446F278BC7977011DCCDAEBBE42D71FA5630C
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# xmfbox.tcl --.#.#.Implements the "Motif" style file selection dialog for the.#.Unix platform. This implementation is used only if the.#."::tk_strictMotif" flag is set..#.# Copyright (c) 1996 Sun Microsystems, Inc..# Copyright (c) 1998-2000 Scriptics Corporation.#.# See the file "license.terms" for information on usage and redistribution.# of this file, and for a DISCLAIMER OF ALL WARRANTIES...namespace eval ::tk::dialog {}.namespace eval ::tk::dialog::file {}...# ::tk::MotifFDialog --.#.#.Implements a file dialog similar to the standard Motif file.#.selection box..#.# Arguments:.#.type.."open" or "save".#.args..Options parsed by the procedure..#.# Results:.#.When -multiple is set to 0, this returns the absolute pathname.#.of the selected file. (NOTE: This is not the same as a single.#.element list.).#.#.When -multiple is set to > 0, this returns a Tcl list of absolute.# pathnames. The argument for -multiple is ignored, but for consistency.# with Windows it defines the max
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1119760
                                                                                                                                                                                                                                  Entropy (8bit):5.371858754181543
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12288:teTMmuZ63NHQCb5Pfhnzr0ql8L8kUM7IRG5eeme6VZyrIBHdQLhfFE+uRbenwr:teTuoZV0m8MMMREtV6Vo4uYR9r
                                                                                                                                                                                                                                  MD5:8320C54418D77EBA5D4553A5D6EC27F9
                                                                                                                                                                                                                                  SHA1:E5123CF166229AEBB076B469459856A56FB16D7F
                                                                                                                                                                                                                                  SHA-256:7E719BA47919B668ACC62008079C586133966ED8B39FEC18E312A773CB89EDAE
                                                                                                                                                                                                                                  SHA-512:B9E6CDCB37D26FF9C573381BDA30FA4CF1730361025CD502B67288C55744962BDD0A99790CEDD4A48FEEF3139E3903265AB112EC545CB1154EAA2A91201F6B34
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............,..,..,..l,..,...-..,...-..,...-..,...-..,Y..-..,...-..,..,...,Y..-..,Y..-..,Y..,..,Y..-..,Rich..,........PE..d....={_.........." .....J...........).......................................@............`.............................................X...X........ .......................0......`L..T............................L..0............`...............................text....H.......J.................. ..`.rdata.......`.......N..............@..@.data...............................@....pdata..............................@..@.rsrc........ ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):14848
                                                                                                                                                                                                                                  Entropy (8bit):5.114869094150954
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:192:zrCm72PEO1jIUs0YqEcPbF55UgCWV4rofnbPztEZoqDLWn7ycLmrD/:zrardA0Bzx14r6nb/0WE/
                                                                                                                                                                                                                                  MD5:BB187E1456794B37F3426B41D6936B55
                                                                                                                                                                                                                                  SHA1:4284D971B02916F11DC4F0FEE475A8ECF4B45078
                                                                                                                                                                                                                                  SHA-256:AF26AF0958BD9A0FEA51F0FD9630C187A29B6F4AAEA3C09C625B93ABA2CC22BF
                                                                                                                                                                                                                                  SHA-512:013193A445C5DE347CDBE2A7ECBAD836ECB8CF8A487176591F4A1A905A30582BC4314D74218195B1FCB82B69EC23CE6F2E8CEA23DB3FDFE17B0EAE74064990BF
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Pf..1...1...1...I...1..D...1...Z...1..D...1..D...1..D...1..BX...1...1...1...D...1...D...1...D...1..Rich.1..................PE..d......d.........." ......................................................................`..........................................;..`...`;..d....p..l....`..................@...|2..T............................2..8............0..p............................text............................... ..`.rdata..$....0......................@..@.data........P......................@....pdata.......`.......0..............@..@.rsrc...l....p.......4..............@..@.reloc..@............8..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):133632
                                                                                                                                                                                                                                  Entropy (8bit):5.851469350935171
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:pI+kHubb2wCc8Rd0BvDAQolRVFhLaNKPNyymA4FZ5dorG0e:ShObbac8Rd0BUlRVlPNynFZ57
                                                                                                                                                                                                                                  MD5:05E4B3B876E5FA6A2B8951F764559623
                                                                                                                                                                                                                                  SHA1:4AD50F70EEF4FEAA9D051C2F161FBAC8A862A4BC
                                                                                                                                                                                                                                  SHA-256:A52F8BD28B5B9558CDE10333CE452A7D6F338CE1005A2B8451755005868E4A98
                                                                                                                                                                                                                                  SHA-512:5648306AF7C056C9250731B7D5A508664294BBB8BA865F9DC06FD7216ADF7B8CC31B1CFBC0175C7F2752680744F6546A1959E7F7D1EC7A8A845F75642CE034D9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......t.uV0...0...0...9...8...b...4...b...8...b...4.......2.......2...b...'...$...;...0...g.......2.......1.......1...Rich0...................PE..d......d.........." .........................................................P............`..........................................................0..T....................@..$....v..T............................<..8............0..........@....................text............................... ..`.rdata......0......................@..@.data...x(......."..................@....pdata..............................@..@.rsrc...T....0......................@..@.reloc..$....@......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):124416
                                                                                                                                                                                                                                  Entropy (8bit):5.961248400051204
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:qMTeHaAQiijmswWBLpbFf9AbWKPpH9UlcU23a:qMTeHaziijmsw+UxH6l8
                                                                                                                                                                                                                                  MD5:A67B8DB9D41F93CB0A22C08738EC265C
                                                                                                                                                                                                                                  SHA1:FBF1C672B68CE67F2E3EBF780F234C26AE1D86CB
                                                                                                                                                                                                                                  SHA-256:D351F3B7CF5A6440A245353985EBE2336080D5D7A62AF6E04339D3E8EFF028BF
                                                                                                                                                                                                                                  SHA-512:6B4905942F7686D6639F01B00E02ABB5BFB678CCF55B7686D462E10BF837C12D74CFAA0B0F20A218A11489A8745A0BBDC2F73A85900C9748F3E3A7B0E6CBC695
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.....................J............................Z......................C...Z......Z......Z......Rich............................PE..d......d.........." ................X........................................ ............`.........................................0o.................\.......................H....G..T............................H..8............... ............................text............................... ..`.rdata..*...........................@..@.data....-.......(..................@....pdata..............................@..@.rsrc...\...........................@..@.reloc..H...........................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):34816
                                                                                                                                                                                                                                  Entropy (8bit):5.6127326100217365
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:7M47+YedBm0W70IuuGig44ttAYSRgEKtha:71pwQ0ouuxRd+a
                                                                                                                                                                                                                                  MD5:ABE99FC1DC3D9BF69F723387E85603D5
                                                                                                                                                                                                                                  SHA1:1B256C920A06B051645FCF1CD7094CADC573F2F2
                                                                                                                                                                                                                                  SHA-256:86D6F955C1564247B6637E4827AF574EBAF47DA69A3E0553D2D5E1F6BD831247
                                                                                                                                                                                                                                  SHA-512:4578E845823B1A3BA1B0F44C1E11885ACE8E1648659E6DD5480F10F7D0CCD1327E41447A94B034FB04FFFAA81321D6596165EB571EDFDA42EFEB08CEA440A9D0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Z4d.;Z7.;Z7.;Z7.C.7.;Z7.N[6.;Z7.P[6.;Z7.N_6.;Z7.N^6.;Z7.NY6.;Z7#N[6.;Z7zR[6.;Z7.;[7.;Z7#NS6.;Z7#NZ6.;Z7#NX6.;Z7Rich.;Z7................PE..d......d.........." .....D...@.......@....................................................`.........................................0...P...............T............................p..T............................p..8............`...............................text....C.......D.................. ..`.rdata..H,...`.......H..............@..@.data...x............v..............@....pdata...............z..............@..@.rsrc...T...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):23552
                                                                                                                                                                                                                                  Entropy (8bit):5.276917458697061
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:RhhYugi3RZNuX9jXG23R+0I1FERUgg0T8DmNRWqjWPgHKpC9SUayj1Bg:3+hGwX9jjrWEWITzxB
                                                                                                                                                                                                                                  MD5:62ED323CD0A1F81251826A0DD2F2CD94
                                                                                                                                                                                                                                  SHA1:4E7A61EABC958FA645527978F3DE4537FA20103F
                                                                                                                                                                                                                                  SHA-256:94738D17F1015127B01E1E4375FC81602CE20ACAC4DFFEC8CFCF29C679591212
                                                                                                                                                                                                                                  SHA-512:98CFC367B14B15978B931C8D46ECEBA91C1360440DCE0F59069F8DA0E2B85964F475EB8DE0B45FE81FD5CA7DDD64FC2158E0A00119D776E00D4C59B3DABEA89E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......P.*U.qD..qD..qD......qD.F.E..qD.F.A..qD.F.@..qD.F.G..qD...E..qD...E..qD...E..qD..qE.YqD...M..qD...D..qD...F..qD.Rich.qD.........................PE..d......d.........." .....,...,.......'....................................................`..........................................Q..T...dQ..........\....p.......................G..T...........................0H..8............@...............................text....*.......,.................. ..`.rdata.......@.......0..............@..@.data...(....`.......L..............@....pdata.......p.......R..............@..@.rsrc...\............V..............@..@.reloc...............Z..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):528896
                                                                                                                                                                                                                                  Entropy (8bit):6.169158824265627
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6144:OB+Kwmy5L0kOMTe8leskN/LgUs0wK7l4a5KsKnphSV3Mah/jh1jhbC0:OMFmOHOMTenRRea5KsKnph6hthbC0
                                                                                                                                                                                                                                  MD5:A6130B5B59DD0AD4251608639F7FBE6E
                                                                                                                                                                                                                                  SHA1:125A4DFD1EABF36347212973A49576A529DE3058
                                                                                                                                                                                                                                  SHA-256:E51C3E1260A093108309DD1E9BFC9E0F212D19BB386B9324671D615C32FB2F84
                                                                                                                                                                                                                                  SHA-512:E9D1E88BC0A0D31B1432F45220E660AE274C9019FDF919AA890A08FD5DD82C674B81C079F8D36DED4BD0D446C3EEB61C889E905C7ECB0A24D71C68C0B44A45E5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........]...]...]...T.).[......Y......N......U......Y...I..T......_.....Y...I..\...I..T...].............\.....\...Rich]...................PE..d...T..d.........." .....&................................................................`.........................................0...L...|...........D.......Py...............!......T..............................8............@.. ............................text....$.......&.................. ..`.rdata..@....@.......*..............@..@.data...@....0...^..................@....pdata..Py.......z...r..............@..@.rsrc...D...........................@..@.reloc...!......."..................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (393)
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):16525
                                                                                                                                                                                                                                  Entropy (8bit):5.345946398610936
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW
                                                                                                                                                                                                                                  MD5:8947C10F5AB6CFFFAE64BCA79B5A0BE3
                                                                                                                                                                                                                                  SHA1:70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778
                                                                                                                                                                                                                                  SHA-256:4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485
                                                                                                                                                                                                                                  SHA-512:B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:SessionID=f94b8f43-fcd8-49f4-8c6e-bbf5cd863db9.1696420882088 Timestamp=2023-10-04T13:01:22:088+0100 ThreadID=3400 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------".SessionID=f94b8f43-fcd8-49f4-8c6e-bbf5cd863db9.1696420882088 Timestamp=2023-10-04T13:01:22:089+0100 ThreadID=3400 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found".SessionID=f94b8f43-fcd8-49f4-8c6e-bbf5cd863db9.1696420882088 Timestamp=2023-10-04T13:01:22:089+0100 ThreadID=3400 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!".SessionID=f94b8f43-fcd8-49f4-8c6e-bbf5cd863db9.1696420882088 Timestamp=2023-10-04T13:01:22:089+0100 ThreadID=3400 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1".SessionID=f94b8f43-fcd8-49f4-8c6e-bbf5cd863db9.1696420882088 Timestamp=2023-10-04T13:01:22:089+0100 ThreadID=3400 Component=ngl-lib_NglAppLib Description="SetConfig:
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with very long lines (393), with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):15114
                                                                                                                                                                                                                                  Entropy (8bit):5.390665111986284
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:384:0unZtZWZ1Z3ZgGnGoGdGfG4GKGXYeYCYgY8FxFFF+FbFlz9s69H9XOXOzOV7x7Sx:0UrQTByYdKiPFUhHxnvjQNPK69NsUy16
                                                                                                                                                                                                                                  MD5:80AC29AA6C13333EB45FEFA6C1D7BD0F
                                                                                                                                                                                                                                  SHA1:82E80A2D2D7A2D78AC451990FCBFCA30FB114586
                                                                                                                                                                                                                                  SHA-256:A197177AB57340812E2CD4D3BC64B18375B3FAC9DE75A40F10BE5AE1F9818005
                                                                                                                                                                                                                                  SHA-512:CCC3A45CDFD812C52E6A1FE1B51F9AD425B59A88693B55EBDF965E9516CCF8717F1AC6FA512C248EA0FC9D8798AB82DB3B0F1CE15D284B8B023AF40D54451718
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:SessionID=1f589ac7-ffb8-43cb-a8c4-ba4e325d9ad8.1715330297814 Timestamp=2024-05-10T10:38:17:814+0200 ThreadID=7568 Component=ngl-lib_NglAppLib Description="-------- Initializing session logs --------"..SessionID=1f589ac7-ffb8-43cb-a8c4-ba4e325d9ad8.1715330297814 Timestamp=2024-05-10T10:38:17:835+0200 ThreadID=7568 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: No operating configs found"..SessionID=1f589ac7-ffb8-43cb-a8c4-ba4e325d9ad8.1715330297814 Timestamp=2024-05-10T10:38:17:835+0200 ThreadID=7568 Component=ngl-lib_kOperatingConfig Description="GetRuntimeDetails: Fallback to NAMED_USER_ONLINE!!"..SessionID=1f589ac7-ffb8-43cb-a8c4-ba4e325d9ad8.1715330297814 Timestamp=2024-05-10T10:38:17:835+0200 ThreadID=7568 Component=ngl-lib_NglAppLib Description="SetConfig: OS Name=WINDOWS_64, OS Version=10.0.19045.1"..SessionID=1f589ac7-ffb8-43cb-a8c4-ba4e325d9ad8.1715330297814 Timestamp=2024-05-10T10:38:17:835+0200 ThreadID=7568 Component=ngl-lib_NglAppLib Description="SetConf
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):29752
                                                                                                                                                                                                                                  Entropy (8bit):5.389708793373817
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rn:EMasQQIZDaP
                                                                                                                                                                                                                                  MD5:0CE5CC0BA09B5E57AEABE1F3F7C95BD9
                                                                                                                                                                                                                                  SHA1:C17E79FDBAE03A383C12AC0BDD8D25F946EE0703
                                                                                                                                                                                                                                  SHA-256:FF095792BAFEEDA3E0BB6BC4663A462D556F01CF0B4A7FE271DD92CE1AF6B202
                                                                                                                                                                                                                                  SHA-512:D8FBF4579DFDC83914E42DFFAC0DA290B02B532E9E728EB45412A600C4B7BEE9E93705328F58A64A6F680BB67CDE68A1008751925D4D0F0BE1E14075C43D9BAE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:03-10-2023 12:50:40:.---2---..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : ***************************************..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : ***************************************..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : ******** Starting new session ********..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : Starting NGL..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : Setting synchronous launch...03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 ::::: Configuring as AcrobatReader1..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : NGLAppVersion 23.6.20320.6..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : NGLAppMode NGL_INIT..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : AcroCEFPath, NGLCEFWorkflowModulePath - C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1 C:\Program Files\Adobe\Acrobat DC\Acrobat\NGL\cefWorkflow..03-10-2023 12:50:40:.AcroNGL Integ ADC-4240758 : isNGLExternalBrowserDisabled - No..03-10-2023 12:50:40:.Closing File..03-10-
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 33081
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1407294
                                                                                                                                                                                                                                  Entropy (8bit):7.97605879016224
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo
                                                                                                                                                                                                                                  MD5:A0CFC77914D9BFBDD8BC1B1154A7B364
                                                                                                                                                                                                                                  SHA1:54962BFDF3797C95DC2A4C8B29E873743811AD30
                                                                                                                                                                                                                                  SHA-256:81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685
                                                                                                                                                                                                                                  SHA-512:74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 299538
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):758601
                                                                                                                                                                                                                                  Entropy (8bit):7.98639316555857
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg
                                                                                                                                                                                                                                  MD5:3A49135134665364308390AC398006F1
                                                                                                                                                                                                                                  SHA1:28EF4CE5690BF8A9E048AF7D30688120DAC6F126
                                                                                                                                                                                                                                  SHA-256:D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B
                                                                                                                                                                                                                                  SHA-512:BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:...........kWT..0...W`.........b..@..nn........5.._..I.R3I..9g.x....s.\+.J......F...P......V]u......t....jK...C.fD..]..K....;......y._.U..}......S.........7...Q.............W.D..S.....y......%..=.....e..^.RG......L..].T.9.y.zqm.Q]..y..(......Q]..~~..}..q...@.T..xI.B.L.a.6...{..W..}.mK?u...5.#.{...n...........z....m^.6!.`.....u...eFa........N....o..hA-..s.N..B.q..{..z.{=..va4_`5Z........3.uG.n...+...t...z.M."2..x.-...DF..VtK.....o]b.Fp.>........c....,..t..an[............5.1.(}..q.q......K3.....[>..;e..f.Y.........mV.cL...]eF..7.e.<.._.o\.S..Z...`..}......>@......|.......ox.........h.......o....-Yj=.s.g.Cc\.i..\..A.B>.X..8`...P......[..O...-.g...r..u\...k..7..#E....N}...8.....(..0....w....j.......>.L....H.....y.x3...[>..t......0..z.qw..]X..i8..w.b..?0.wp..XH.A.[.....S..g.g..I.A.15.0?._n.Q.]..r8.....l..18...(.].m...!|G.1...... .3.`./....`~......G.............|..pS.e.C....:o.u_..oi.:..|....joi...eM.m.K...2%...Z..j...VUh..9.}.....
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 5111142
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1419751
                                                                                                                                                                                                                                  Entropy (8bit):7.976496077007677
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24576:/xTwYIGNPgeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JTwZG/WLxYGZN3mlind9i4ufFXpAXkru
                                                                                                                                                                                                                                  MD5:DAB0D55487947A8C00DEFEB1863E5D52
                                                                                                                                                                                                                                  SHA1:CA21AE7C3A6C3B75C5FEE6CC45E57F4F8E9AAD6A
                                                                                                                                                                                                                                  SHA-256:915AF8947C717264BA12E43919E2AED3846C3C312EE46DFEE18A7F40BE119623
                                                                                                                                                                                                                                  SHA-512:A6C1268A6C488495C2D07A90F498014192501A27D4A597C20644F5C95D3E4A7777D8E884F13DA9933B8D5C399499C98BDE94988467F79BF11B4391869ACFAF17
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:...........[.s.8..}.....!#..gw.n.`uNl.f6.3....d%EK.D["...#.......!)...r.$.G.......Z..u.._>.~....^e..<..u..........._D.r.Z..M.:...$.I..N.....\`.B.wj...:...E|.P..$ni.{.....T.^~<m-..J....RQk..*..f.....q.......V.rC.M.b.DiL\.....wq.*...$&j....O.........~.U.+..So.]..n..#OJ..p./..-......<...5..WB.O....i....<./T.P.L.;.....h.ik..D*T...<...j..o..fz~..~."...w&.fB...4..@[.g.......Y.>/M.".....-..N.{.2.....\....h..ER..._..(.-..o97..[.t:..>..W*..0.....u...?.%...1u..fg..`.Z.....m ~.GKG.q{.vU.nr..W.%.W..#z..l.T......1.....}.6......D.O...:....PX.......*..R.....j.WD).M..9.Fw...W.-a..z.l\..u*.^....*L..^.`.T...l.^.B.DMc.d....i...o.|M.uF|.nQ.L.E,.b!..NG.....<...J......g.o....;&5..'a.M...l..1.V.iB2.T._I....".+.W.yA ._.......<.O......O$."C....n!H.L`..q.....5..~./.._t.......A....S..3........Q[..+..e..P;...O...x~<B........'.)...n.$e.m.:...m.....&..Y.".H.s....5.9..A5)....s&.k0,.g4.V.K.,*.e....5...X.}6.P....y\.s|..Si..BB..y...~.....D^g...*7'T-.5*.!K.$\...2.
                                                                                                                                                                                                                                  Process:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  File Type:gzip compressed data, from FAT filesystem (MS-DOS, OS/2, NT), original size modulo 2^32 1311022
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):386528
                                                                                                                                                                                                                                  Entropy (8bit):7.9736851559892425
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m
                                                                                                                                                                                                                                  MD5:5C48B0AD2FEF800949466AE872E1F1E2
                                                                                                                                                                                                                                  SHA1:337D617AE142815EDDACB48484628C1F16692A2F
                                                                                                                                                                                                                                  SHA-256:F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE
                                                                                                                                                                                                                                  SHA-512:44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:...........]s[G. Z...{....;...J$%K&..%.[..k...S....$,.`. )Z..m........a.......o..7.VfV...S..HY}Ba.<.NUVVV~W.].;qG4..b,N..#1.=1.#1..o.Fb.........IC.....Z...g_~.OO.l..g.uO...bY.,[..o.s.D<..W....w....?$4..+..%.[.?..h.w<.T.9.vM.!..h0......}..H..$[...lq,....>..K.)=..s.{.g.O...S9".....Q...#...+..)>=.....|6......<4W.'.U.j$....+..=9...l.....S..<.\.k.'....{.1<.?..<..uk.v;.7n.!...g....."P..4.U........c.KC..w._G..u..g./.g....{'^.-|..h#.g.\.PO.|...]x..Kf4..s..............+.Y.....@.K....zI..X......6e?[..u.g"{..h.vKbM<.?i6{%.q)i...v..<P8P3.......CW.fwd...{:@h...;........5..@.C.j.....a.. U.5...].$.L..wW....z...v.......".M.?c.......o..}.a.9..A..%V..o.d....'..|m.WC.....|.....e.[W.p.8...rm....^..x'......5!...|......z..#......X_..Gl..c..R..`...*.s-1f..]x......f...g...k........g....... ).3.B..{"4...!r....v+As...Zn.]K{.8[..M.r.Y..........+%...]...J}f]~}_..K....;.Z.[..V.&..g...>...{F..{I..@~.^.|P..G.R>....U..../HY...(.z.<.~.9OW.Sxo.Y
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):4
                                                                                                                                                                                                                                  Entropy (8bit):2.0
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:qn:qn
                                                                                                                                                                                                                                  MD5:3F1D1D8D87177D3D8D897D7E421F84D6
                                                                                                                                                                                                                                  SHA1:DD082D742A5CB751290F1DB2BD519C286AA86D95
                                                                                                                                                                                                                                  SHA-256:F02285FB90ED8C81531FE78CF4E2ABB68A62BE73EE7D317623E2C3E3AEFDFFF2
                                                                                                                                                                                                                                  SHA-512:2AE2B3936F31756332CA7A4B877D18F3FCC50E41E9472B5CD45A70BEA82E29A0FA956EE6A9EE0E02F23D9DB56B41D19CB51D88AAC06E9C923A820A21023752A9
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:blat
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):176
                                                                                                                                                                                                                                  Entropy (8bit):4.713840781302666
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:S3yE25MOWrYXtHVE/DRFrgm5/gvJgXDLAUDA+ERo6+aEYqVS1f6gq1WGgVSBn:S3mSOWWHVUDjrgmxgRgzLXDA6Va8VeuR
                                                                                                                                                                                                                                  MD5:8C7CA775CF482C6027B4A2D3DB0F6A31
                                                                                                                                                                                                                                  SHA1:E3596A87DD6E81BA7CF43B0E8E80DA5BC823EA1A
                                                                                                                                                                                                                                  SHA-256:52C72CF96B12AE74D84F6C049775DA045FAE47C007DC834CA4DAC607B6F518EA
                                                                                                                                                                                                                                  SHA-512:19C7D229723249885B125121B3CC86E8C571360C1FB7F2AF92B251E6354A297B4C2B9A28E708F2394CA58C35B20987F8B65D9BD6543370F063BBD59DB4A186AC
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:# Generated file - this directory may be deleted to reset the COM cache.....import win32com..if __path__[:-1] != win32com.__gen_path__: __path__.append(win32com.__gen_path__)..
                                                                                                                                                                                                                                  Process:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  File Type:data
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):10
                                                                                                                                                                                                                                  Entropy (8bit):2.7219280948873625
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3:qW6:qW6
                                                                                                                                                                                                                                  MD5:2C7344F3031A5107275CE84AED227411
                                                                                                                                                                                                                                  SHA1:68ACAD72A154CBE8B2D597655FF84FD31D57C43B
                                                                                                                                                                                                                                  SHA-256:83CDA9FECC9C008B22C0C8E58CBCBFA577A3EF8EE9B2F983ED4A8659596D5C11
                                                                                                                                                                                                                                  SHA-512:F58362C70A2017875D231831AE5868DF22D0017B00098A28AACB5753432E8C4267AA7CBF6C5680FEB2DC9B7ABADE5654C3651685167CC26AA208A9EB71528BB6
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:..K....}..
                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\00#U2800.exe
                                                                                                                                                                                                                                  File Type:PDF document, version 1.7, 2 pages
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):94040
                                                                                                                                                                                                                                  Entropy (8bit):7.829853986558587
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:uSpxgm+MDkAJio28HX+sqJ4ckTgBFbwf1oOghuAIfqUU3brj9vgcNeEy/WHlb3Ae:FUm+Ms8HOsq1QoOPAIiUUHxVEmlDAzsH
                                                                                                                                                                                                                                  MD5:57ED39B1D6B4FD5CF636C5ED6E6497DD
                                                                                                                                                                                                                                  SHA1:BEA969673635D127B92A7BAED870B0C1FDD50C9B
                                                                                                                                                                                                                                  SHA-256:8AF0587C0BC27E797F6617543898D3B35DB186467561D50A7ED25F609315549D
                                                                                                                                                                                                                                  SHA-512:21B9313AB11694B8F769D6B200BAA05409AA4EBF03C04E211A494C454FA77211F9D71A5B12778D0C9EC041E2C5CBA6B3487ECC286B4CF5C86B5ED260A9BF78AB
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:%PDF-1.7..%......1 0 obj..<</Type/Catalog/Pages 2 0 R/Lang(en) /StructTreeRoot 30 0 R/MarkInfo<</Marked true>>/Metadata 76 0 R/ViewerPreferences 77 0 R>>..endobj..2 0 obj..<</Type/Pages/Count 2/Kids[ 3 0 R 24 0 R] >>..endobj..3 0 obj..<</Type/Page/Parent 2 0 R/Resources<</ExtGState<</GS5 5 0 R/GS8 8 0 R>>/Font<</F1 6 0 R/F2 9 0 R/F3 12 0 R>>/XObject<</Image20 20 0 R/Image22 22 0 R>>/ProcSet[/PDF/Text/ImageB/ImageC/ImageI] >>/Annots[ 11 0 R 17 0 R 18 0 R 19 0 R] /MediaBox[ 0 0 595.32 842.04] /Contents 4 0 R/Group<</Type/Group/S/Transparency/CS/DeviceRGB>>/Tabs/S/StructParents 0>>..endobj..4 0 obj..<</Filter/FlateDecode/Length 3813>>..stream..x..]mO.I.............!%!.r..MN.iu.....l....U.3cCf...{.U..<SU]..O..T/.W/_........W.O.T/~..............Q.5.......j5;<....A...7U....d.=...m.8.F...>..'.......s..U..Z..)Q7...K.8<x.....)...>}EF...+.k..[.K...q.........zx.......z5]...h.e...............r".....c.z"...xn5#..ku..Q.'.!s*C........].@.r4.....Yu;6...X.V....j.....e5.-...N.+.]md...R.
                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\00#U2800.exe
                                                                                                                                                                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Mon Mar 18 01:44:10 2024, mtime=Mon Mar 18 01:49:14 2024, atime=Mon Mar 18 01:44:10 2024, length=301056, window=hide
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):1098
                                                                                                                                                                                                                                  Entropy (8bit):4.436391784824064
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:24:8mqGvd2ofoacrtwJA+stFyDPf1Myzv/MRht1d/5zmWwM:8mqGVxfvy+sXyD31mfoM
                                                                                                                                                                                                                                  MD5:6B154F17E34516337B5B3EEA7E91B2C5
                                                                                                                                                                                                                                  SHA1:7326F2DB01133B9208340F6C2F8C38FF3C2C124D
                                                                                                                                                                                                                                  SHA-256:1403563827E7CA7AB6A17CF8B75A0A6C4F5480941FCF2A8FDCEE6FD6D7CCF27B
                                                                                                                                                                                                                                  SHA-512:EFEC5AE674450C388399B6B98737FCFB71979D60786D86ABE536679235E6DDDE79B96412B6DA747D0BA832BD5C88EB46444A9BF0A467C56AE2B8312B8548AAF1
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:L..................F.... ......'.x...k0..x..P..'.x...............................P.O. .:i.....+00.../C:\...................`.1.....rX....EXPLOR~1..H......rXS.rX...........................?.v.e.x.p.l.o.r.e.r.w.i.n.....V.2.....rX.. .pdf.exe.@......rX..rX.............................e..p.d.f...e.x.e.......E...............-.......D............./L.....C:\explorerwin\pdf.exe......\.p.d.f...e.x.e...C.:.\.e.x.p.l.o.r.e.r.w.i.n.\.............x.)#x...................6.......C.o.n.s.o.l.a.s...T.T.F.o.n.t._._....k..........9.a......G......d...................2................7......:...................vvv.;x......a....HV............n.......A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.............1SPS..W....C.a.!..P&................................................................................................................................................................................................................9...1SPS..mD..pH.H@..=x.....h....H.......U..B.....f.........`.
                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\00#U2800.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):102769152
                                                                                                                                                                                                                                  Entropy (8bit):7.998707787561555
                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                  SSDEEP:3145728:8Zp8rQ7qC7hLCZ8FETSUTN8nwap+Ubvq+A1ETjav:UxmCFCZANUTWprmnES
                                                                                                                                                                                                                                  MD5:B6D61F0D3C8AF06E8EDB4364E01451BC
                                                                                                                                                                                                                                  SHA1:24964DDAEF57D35DDE4D575CD25A889AA8A89421
                                                                                                                                                                                                                                  SHA-256:66F51838243F73004B8F4E082224A217323245BD8AF74E7983BC14BE0B9DD6A2
                                                                                                                                                                                                                                  SHA-512:4D4135429B064B5B190F58AC4C94A79ADC4F487AA1E5CFFAFD0AED1F9DAEC03FD9A7BD861B3709067CBB638680575B2B17A27E4BEE8814307942A41BF1A7624E
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......IF'..'I..'I..'I.._..'I..H..'I..L..'I..M..'I..J..'I..^H..'I.F_H..'I..'H.\'I...M..'I..'I..'I...I..'I...K..'I.Rich.'I.........................PE..d...#.<f.........." ...'.............u.......................................P ...........`.............................................d...T................. .x'...........@ .........T.......................(...@...@............................................text............................... ..`.rdata...O.......P..................@..@.data...............................@....pdata..x'.... ..(..................@..@.reloc.......@ ....... .............@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\00#U2800.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):112640
                                                                                                                                                                                                                                  Entropy (8bit):6.2314402483336195
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:3072:o0QerCBW1DtZ4JhAkZ9Vbc0oraewKpJTdR:JrCsBtZYhPvb6raapJxR
                                                                                                                                                                                                                                  MD5:64BBFFE8014097F4782E523A7C522D19
                                                                                                                                                                                                                                  SHA1:C9F3FCDCE0F02247DB59A5326BCF61127D2C9C88
                                                                                                                                                                                                                                  SHA-256:2B27A6693ACBFD12E02A48E91B1BDE5EB6720591F0AE6890CC7D9A6BBAA1DC51
                                                                                                                                                                                                                                  SHA-512:B552DB207CF3DF2B11AB8099CB9D57FAE9F6F07828C9036B3F0F084096A5BBD127D6F14E25CF54228A32B9EF17F58A20EA98C6717004EB45C307149F1B261E6F
                                                                                                                                                                                                                                  Malicious:false
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......?.iZ{...{...{...r.......'..y....'..t....'..|....'..x.......y...0...~...{...:...{...y....$..z....$..z...Rich{...................PE..d....<f.........." ...'.F...p......XA....................................................`.............................................d......................................x...0...T.......................(......@............`...............................text...xD.......F.................. ..`.rdata..`Z...`...\...J..............@..@.data...h...........................@....pdata..............................@..@.reloc..x...........................@..B........................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\00#U2800.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):102917049
                                                                                                                                                                                                                                  Entropy (8bit):7.995853111857083
                                                                                                                                                                                                                                  Encrypted:true
                                                                                                                                                                                                                                  SSDEEP:3145728:lcogYRPSC++6y9J2sTdet/VG6RmtCRlGPr/2qHO5icEP9:bxaC4y9vd65mERluhHCiPP
                                                                                                                                                                                                                                  MD5:490B24AAABFD71DC7561947289B252A5
                                                                                                                                                                                                                                  SHA1:AC2D9EC2CD024FFF564E4E397EC8FBC9E65594D2
                                                                                                                                                                                                                                  SHA-256:2EBD029B1D588DDA7D230B3776C3FA99C399F90449CD2DBDD79B071331EFE4C6
                                                                                                                                                                                                                                  SHA-512:FA80AA32A66211D4D33FA7E51D502E8418D8928C9F0D810C3D40FFB1F35A968FF6AFD1C1FAFE5259488E2612EFF198481E5A89288752119110662595A92E65C6
                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1_..P1..P1..P1..(2..P1..(4.|P1..(5..P1../..P1../4..P1../5..P1../2..P1..(0..P1..P0..P1...5..P1...3..P1.Rich.P1.........................PE..d...s.<f.........."....%.....T................@.............................`........"...`.....................................................P....`....... ..."...........P..\...P...................................@...............x............................text............................... ..`.rdata...).......*..................@..@.data...83..........................@....pdata..."... ...$..................@..@_RDATA..\....P......................@..@.rsrc........`......................@..@.reloc..\....P......................@..B................................................................................................................................................................................................
                                                                                                                                                                                                                                  Process:C:\Users\user\Desktop\00#U2800.exe
                                                                                                                                                                                                                                  File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Category:dropped
                                                                                                                                                                                                                                  Size (bytes):239616
                                                                                                                                                                                                                                  Entropy (8bit):6.089596930924194
                                                                                                                                                                                                                                  Encrypted:false
                                                                                                                                                                                                                                  SSDEEP:1536:PsAsLVid74fycayKjEhNkOS3paR4bMAXvgX+ILEY218cPT3LybGJB2EfxidD7pEQ:0AsLV4JyoEhF60+VHbhxi66QzWquHDB
                                                                                                                                                                                                                                  MD5:86EDB9CBB19D37360BB868ACE85691C5
                                                                                                                                                                                                                                  SHA1:13DB6F80843E5E005B6A09B94F1C8147C8AE39C3
                                                                                                                                                                                                                                  SHA-256:908E71698C64039AE4F565A7062A3DDE52394A74402A9D41C78C3B35ADF95767
                                                                                                                                                                                                                                  SHA-512:79A23C9EF5E462B0D0D1827593D4EBB39C0DEEA1DEDA8793F9DE7BD1C7AD7ED271C1A0A535E475DC9A20485E9F5BAC85CB6AB164078B74BB8DC835B92FCC07DA
                                                                                                                                                                                                                                  Malicious:true
                                                                                                                                                                                                                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......u.L.1v".1v".1v".8...=v"...#.3v"...'.&v"...&.8v"...!.2v"..#.9v".z.#.4v".1v#..v".1v"..v".....0v"... .0v".Rich1v".................PE..d...F.<f.........."....'.......................@..........................................`.................................................L...................8....................}..T....................~..(...p|..@...............(............................text...z........................... ..`.rdata..^...........................@..@.data...............................@....pdata..8...........................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                  File type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                                  Entropy (8bit):7.998595995126542
                                                                                                                                                                                                                                  TrID:
                                                                                                                                                                                                                                  • Win64 Executable Console (202006/5) 92.65%
                                                                                                                                                                                                                                  • Win64 Executable (generic) (12005/4) 5.51%
                                                                                                                                                                                                                                  • Generic Win/DOS Executable (2004/3) 0.92%
                                                                                                                                                                                                                                  • DOS Executable Generic (2002/1) 0.92%
                                                                                                                                                                                                                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                                                                                                                                                  File name:00#U2800.exe
                                                                                                                                                                                                                                  File size:103'126'528 bytes
                                                                                                                                                                                                                                  MD5:ff6ddcc3a1804e75999a12f983ec76a8
                                                                                                                                                                                                                                  SHA1:9bc7369c82203c261e398cb44944662517870e7a
                                                                                                                                                                                                                                  SHA256:05525c085fe8d08ca8a6a52a27ef1594b87276187738a55e8751eb8ab8fa8975
                                                                                                                                                                                                                                  SHA512:be772ffe437da5f0dd6211a3d75a432c2be3eee4fac847aa5252b8251ae02b7425d59d4f0f0f3fd4b794ac52cfff927252937c31aa70935c12a440402cb2e23c
                                                                                                                                                                                                                                  SSDEEP:3145728:MZp8rQ7qC7hLCZ8FETSUTN8nwap+Ubvq+A1ETjav:kxmCFCZANUTWprmnES
                                                                                                                                                                                                                                  TLSH:28383399F26525F8D163F0B164980F06E871F08A1F30ADFBB3684A254B71AF257F8B54
                                                                                                                                                                                                                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........AnQ./=Q./=Q./=X..=]./=...<S./=..*<F./=..+<X./=..,<R./=...<Y./=...<V./=Q..=../=Q./=x./=...=P./=..-<P./=RichQ./=........PE..d..
                                                                                                                                                                                                                                  Icon Hash:357561d6dad24d55
                                                                                                                                                                                                                                  Entrypoint:0x140022904
                                                                                                                                                                                                                                  Entrypoint Section:.text
                                                                                                                                                                                                                                  Digitally signed:false
                                                                                                                                                                                                                                  Imagebase:0x140000000
                                                                                                                                                                                                                                  Subsystem:windows cui
                                                                                                                                                                                                                                  Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                                                                                                                                                                                  DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                                                  Time Stamp:0x663CAC27 [Thu May 9 10:57:43 2024 UTC]
                                                                                                                                                                                                                                  TLS Callbacks:0x40014480, 0x1
                                                                                                                                                                                                                                  CLR (.Net) Version:
                                                                                                                                                                                                                                  OS Version Major:6
                                                                                                                                                                                                                                  OS Version Minor:0
                                                                                                                                                                                                                                  File Version Major:6
                                                                                                                                                                                                                                  File Version Minor:0
                                                                                                                                                                                                                                  Subsystem Version Major:6
                                                                                                                                                                                                                                  Subsystem Version Minor:0
                                                                                                                                                                                                                                  Import Hash:b0bd2c89068305385973af46fd58f914
                                                                                                                                                                                                                                  Instruction
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  sub esp, 28h
                                                                                                                                                                                                                                  call 00007FF184BDCFB8h
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  add esp, 28h
                                                                                                                                                                                                                                  jmp 00007FF184BDCB47h
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  inc eax
                                                                                                                                                                                                                                  push ebx
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  sub esp, 20h
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  lea eax, dword ptr [06224033h]
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  mov ebx, ecx
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  mov dword ptr [ecx], eax
                                                                                                                                                                                                                                  test dl, 00000001h
                                                                                                                                                                                                                                  je 00007FF184BDCCDCh
                                                                                                                                                                                                                                  mov edx, 00000018h
                                                                                                                                                                                                                                  call 00007FF184BDD337h
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  mov eax, ebx
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  add esp, 20h
                                                                                                                                                                                                                                  pop ebx
                                                                                                                                                                                                                                  ret
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  int3
                                                                                                                                                                                                                                  nop word ptr [eax+eax+00000000h]
                                                                                                                                                                                                                                  dec eax
                                                                                                                                                                                                                                  sub esp, 10h
                                                                                                                                                                                                                                  dec esp
                                                                                                                                                                                                                                  mov dword ptr [esp], edx
                                                                                                                                                                                                                                  dec esp
                                                                                                                                                                                                                                  mov dword ptr [esp+08h], ebx
                                                                                                                                                                                                                                  dec ebp
                                                                                                                                                                                                                                  xor ebx, ebx
                                                                                                                                                                                                                                  dec esp
                                                                                                                                                                                                                                  lea edx, dword ptr [esp+18h]
                                                                                                                                                                                                                                  dec esp
                                                                                                                                                                                                                                  sub edx, eax
                                                                                                                                                                                                                                  dec ebp
                                                                                                                                                                                                                                  cmovb edx, ebx
                                                                                                                                                                                                                                  dec esp
                                                                                                                                                                                                                                  mov ebx, dword ptr [00000010h]
                                                                                                                                                                                                                                  dec ebp
                                                                                                                                                                                                                                  cmp edx, ebx
                                                                                                                                                                                                                                  jnc 00007FF184BDCCE8h
                                                                                                                                                                                                                                  inc cx
                                                                                                                                                                                                                                  and edx, 8D4DF000h
                                                                                                                                                                                                                                  wait
                                                                                                                                                                                                                                  add al, dh
                                                                                                                                                                                                                                  Programming Language:
                                                                                                                                                                                                                                  • [IMP] VS2008 SP1 build 30729
                                                                                                                                                                                                                                  NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x624b5040xc8.rdata
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x62500000xc4b8.rsrc
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x624e0000x1bcc.pdata
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x625d0000x56c.reloc
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x6246ab00x54.rdata
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_TLS0x6246b800x28.rdata
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x62469700x140.rdata
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_IAT0x260000x370.rdata
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                  .text0x10000x2425a0x2440090d3b49ec8db77c251ab261803f6ccdcFalse0.5118265086206897data6.384896315807181IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                  .rdata0x260000x62262340x62264007993ef2fffe715a7551e53b712a0a757unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                  .data0x624d0000x3a80x20064e50db78131645fa86dc68b043102b4False0.267578125DOS executable (block device driver)2.0234641283730554IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                                                  .pdata0x624e0000x1bcc0x1c004929f3b28bf58b33fe525e72e3584cf6False0.5015345982142857data5.575629408249248IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                  .rsrc0x62500000xc4b80xc600ad56000c051700c0ccc04ce79d3374bdFalse0.2331518308080808data4.487620031722322IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                  .reloc0x625d0000x56c0x600e12a943fc3260c83d0737a61191b7211False0.6165364583333334data5.2436074881274415IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                                                  RT_ICON0x62503d80x18dePNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9696826892868363
                                                                                                                                                                                                                                  RT_ICON0x6251cb80x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.08974964572508266
                                                                                                                                                                                                                                  RT_ICON0x6255ee00x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.12935684647302906
                                                                                                                                                                                                                                  RT_ICON0x62584880x1a68Device independent bitmap graphic, 40 x 80 x 32, image size 6720EnglishUnited States0.16553254437869822
                                                                                                                                                                                                                                  RT_ICON0x6259ef00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.21106941838649157
                                                                                                                                                                                                                                  RT_ICON0x625af980x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400EnglishUnited States0.29508196721311475
                                                                                                                                                                                                                                  RT_ICON0x625b9200x6b8Device independent bitmap graphic, 20 x 40 x 32, image size 1680EnglishUnited States0.33313953488372094
                                                                                                                                                                                                                                  RT_ICON0x625bfd80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.4592198581560284
                                                                                                                                                                                                                                  RT_GROUP_ICON0x625c4400x76dataEnglishUnited States0.7457627118644068
                                                                                                                                                                                                                                  RT_VERSION0x62502400x198OpenPGP Public KeyEnglishUnited States0.5147058823529411
                                                                                                                                                                                                                                  DLLImport
                                                                                                                                                                                                                                  KERNEL32.dllLoadLibraryW, GetProcAddress, FreeLibrary, SetConsoleTitleW, SetConsoleCursorPosition, Sleep, GetModuleHandleA, CloseHandle, GetStdHandle, SetConsoleMode, GetConsoleMode, CreateFileW, GetConsoleScreenBufferInfo, SetConsoleScreenBufferSize, SetConsoleTextAttribute, SetConsoleWindowInfo, FillConsoleOutputCharacterA, FillConsoleOutputAttribute, GetLargestConsoleWindowSize, WriteConsoleW, ReleaseSRWLockExclusive, GetLastError, AddVectoredExceptionHandler, SetThreadStackGuarantee, WaitForSingleObject, QueryPerformanceCounter, AcquireSRWLockExclusive, RtlCaptureContext, RtlVirtualUnwind, RtlLookupFunctionEntry, SetLastError, GetCurrentDirectoryW, GetEnvironmentVariableW, GetCurrentProcess, SetFileInformationByHandle, GetCurrentProcessId, TryAcquireSRWLockExclusive, QueryPerformanceFrequency, HeapAlloc, GetProcessHeap, HeapFree, HeapReAlloc, AcquireSRWLockShared, ReleaseSRWLockShared, ReleaseMutex, FindClose, GetFileInformationByHandle, GetFileInformationByHandleEx, CreateDirectoryW, FindFirstFileW, GetModuleHandleW, FormatMessageW, GetFullPathNameW, MultiByteToWideChar, GetCurrentThread, GetSystemTimeAsFileTime, WaitForSingleObjectEx, LoadLibraryA, CreateMutexA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, IsDebuggerPresent, InitializeSListHead, GetCurrentThreadId, IsProcessorFeaturePresent
                                                                                                                                                                                                                                  SHELL32.dllShellExecuteW
                                                                                                                                                                                                                                  ntdll.dllNtWriteFile, RtlNtStatusToDosError
                                                                                                                                                                                                                                  VCRUNTIME140.dllmemcpy, __current_exception_context, __current_exception, __C_specific_handler, _CxxThrowException, memset, memmove, memcmp, __CxxFrameHandler3
                                                                                                                                                                                                                                  api-ms-win-crt-runtime-l1-1-0.dll_register_onexit_function, _initialize_onexit_table, terminate, _crt_atexit, _register_thread_local_exe_atexit_callback, _c_exit, _cexit, __p___argv, __p___argc, _exit, exit, _initterm_e, _initterm, _initialize_narrow_environment, _configure_narrow_argv, _get_initial_narrow_environment, _set_app_type, _seh_filter_exe
                                                                                                                                                                                                                                  api-ms-win-crt-math-l1-1-0.dll__setusermatherr
                                                                                                                                                                                                                                  api-ms-win-crt-stdio-l1-1-0.dll__p__commode, _set_fmode
                                                                                                                                                                                                                                  api-ms-win-crt-locale-l1-1-0.dll_configthreadlocale
                                                                                                                                                                                                                                  api-ms-win-crt-heap-l1-1-0.dllfree, _set_new_mode
                                                                                                                                                                                                                                  Language of compilation systemCountry where language is spokenMap
                                                                                                                                                                                                                                  EnglishUnited States
                                                                                                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.285761118 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.285789013 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.285845995 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.286259890 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.286278963 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.613449097 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.619827986 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.619848013 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.620935917 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.620995998 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.694346905 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.694511890 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.694854975 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.694873095 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.781169891 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.804621935 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.804701090 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.804752111 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.837521076 CEST49747443192.168.2.423.78.8.145
                                                                                                                                                                                                                                  May 10, 2024 10:38:29.837548971 CEST4434974723.78.8.145192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.181840897 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.181883097 CEST44349749142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.181989908 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.196671963 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.196690083 CEST44349749142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.431308985 CEST44349749142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.439822912 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.439846992 CEST44349749142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.440968990 CEST44349749142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.441047907 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.441905022 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.442073107 CEST44349749142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.442110062 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.442130089 CEST49749443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.446618080 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.446646929 CEST44349750142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.446866989 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.457636118 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.457648993 CEST44349750142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.686244011 CEST44349750142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.686996937 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.687016010 CEST44349750142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.688023090 CEST44349750142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.688111067 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.688689947 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.688821077 CEST44349750142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.688841105 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.688868999 CEST49750443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.693305016 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.693341017 CEST44349751142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.693439960 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.704054117 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.704066992 CEST44349751142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.934451103 CEST44349751142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.935026884 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.935041904 CEST44349751142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.936124086 CEST44349751142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.936278105 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.936886072 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.937016010 CEST44349751142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.937027931 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.937208891 CEST49751443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.941668987 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.941706896 CEST44349752142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.943172932 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.953341961 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.953358889 CEST44349752142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.181710958 CEST44349752142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.185544014 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.185564041 CEST44349752142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.186589003 CEST44349752142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.186646938 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.187469959 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.187602997 CEST44349752142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.187654972 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.187676907 CEST49752443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.193793058 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.193833113 CEST44349753142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.193902969 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.205569983 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.205595970 CEST44349753142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.433814049 CEST44349753142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.434329987 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.434361935 CEST44349753142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.435384989 CEST44349753142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.435475111 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.435910940 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.436043978 CEST44349753142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.436079025 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.436096907 CEST49753443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.440922022 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.440958023 CEST44349754142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.441073895 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.451621056 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.451642990 CEST44349754142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.679781914 CEST44349754142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.680246115 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.680270910 CEST44349754142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.681263924 CEST44349754142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.681355953 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.681799889 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.681916952 CEST44349754142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.681945086 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.681993008 CEST49754443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.686522961 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.686558008 CEST44349755142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.686759949 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.697046041 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.697068930 CEST44349755142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.925822973 CEST44349755142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.926289082 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.926307917 CEST44349755142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.927330017 CEST44349755142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.927395105 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.928061962 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.928201914 CEST44349755142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.928256035 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.928404093 CEST49755443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.934113979 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.934144974 CEST44349756142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.934268951 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.946167946 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:54.946182966 CEST44349756142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.174909115 CEST44349756142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.177500963 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.177519083 CEST44349756142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.178519964 CEST44349756142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.178582907 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.179071903 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.179193974 CEST44349756142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.179205894 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.179239035 CEST49756443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.183518887 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.183542967 CEST44349757142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.183643103 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.194077969 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.194091082 CEST44349757142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.422595978 CEST44349757142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.425489902 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.425501108 CEST44349757142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.426510096 CEST44349757142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.426599026 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.427103996 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.427212000 CEST44349757142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.427236080 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.427263021 CEST49757443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.431386948 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.431410074 CEST44349758142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.431528091 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.442413092 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.442424059 CEST44349758142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.671551943 CEST44349758142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.672215939 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.672235966 CEST44349758142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.673245907 CEST44349758142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.673337936 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.673779964 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.673902035 CEST44349758142.250.191.129192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.673927069 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  May 10, 2024 10:38:55.673957109 CEST49758443192.168.2.4142.250.191.129
                                                                                                                                                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.068442106 CEST6238553192.168.2.41.1.1.1
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.177906036 CEST53623851.1.1.1192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:39:08.813102007 CEST6481753192.168.2.41.1.1.1
                                                                                                                                                                                                                                  May 10, 2024 10:39:08.935530901 CEST53648171.1.1.1192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:39:32.921962023 CEST5896353192.168.2.41.1.1.1
                                                                                                                                                                                                                                  May 10, 2024 10:39:33.031613111 CEST53589631.1.1.1192.168.2.4
                                                                                                                                                                                                                                  May 10, 2024 10:39:57.423106909 CEST5299853192.168.2.41.1.1.1
                                                                                                                                                                                                                                  May 10, 2024 10:39:57.542722940 CEST53529981.1.1.1192.168.2.4
                                                                                                                                                                                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.068442106 CEST192.168.2.41.1.1.10x20e0Standard query (0)drive.usercontent.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  May 10, 2024 10:39:08.813102007 CEST192.168.2.41.1.1.10xd06cStandard query (0)drive.usercontent.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  May 10, 2024 10:39:32.921962023 CEST192.168.2.41.1.1.10xb96eStandard query (0)drive.usercontent.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  May 10, 2024 10:39:57.423106909 CEST192.168.2.41.1.1.10xec30Standard query (0)drive.usercontent.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                  May 10, 2024 10:38:53.177906036 CEST1.1.1.1192.168.2.40x20e0No error (0)drive.usercontent.google.com142.250.191.129A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  May 10, 2024 10:39:08.935530901 CEST1.1.1.1192.168.2.40xd06cNo error (0)drive.usercontent.google.com142.250.190.65A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  May 10, 2024 10:39:33.031613111 CEST1.1.1.1192.168.2.40xb96eNo error (0)drive.usercontent.google.com142.250.190.97A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  May 10, 2024 10:39:57.542722940 CEST1.1.1.1192.168.2.40xec30No error (0)drive.usercontent.google.com142.250.191.129A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                  • armmf.adobe.com
                                                                                                                                                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                  0192.168.2.44974723.78.8.1454437796C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                  2024-05-10 08:38:29 UTC475OUTGET /onboarding/smskillreader.txt HTTP/1.1
                                                                                                                                                                                                                                  Host: armmf.adobe.com
                                                                                                                                                                                                                                  Connection: keep-alive
                                                                                                                                                                                                                                  Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                  User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) ReaderServices/23.6.20320 Chrome/105.0.0.0 Safari/537.36
                                                                                                                                                                                                                                  Sec-Fetch-Site: same-origin
                                                                                                                                                                                                                                  Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                  Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                  Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                  If-None-Match: "78-5faa31cce96da"
                                                                                                                                                                                                                                  If-Modified-Since: Mon, 01 May 2023 15:02:33 GMT
                                                                                                                                                                                                                                  2024-05-10 08:38:29 UTC198INHTTP/1.1 304 Not Modified
                                                                                                                                                                                                                                  Content-Type: text/plain; charset=UTF-8
                                                                                                                                                                                                                                  Last-Modified: Mon, 01 May 2023 15:02:33 GMT
                                                                                                                                                                                                                                  ETag: "78-5faa31cce96da"
                                                                                                                                                                                                                                  Date: Fri, 10 May 2024 08:38:29 GMT
                                                                                                                                                                                                                                  Connection: close


                                                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                                                  Click to dive into process behavior distribution

                                                                                                                                                                                                                                  Click to jump to process

                                                                                                                                                                                                                                  Target ID:0
                                                                                                                                                                                                                                  Start time:10:38:12
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\Users\user\Desktop\00#U2800.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:"C:\Users\user\Desktop\00#U2800.exe"
                                                                                                                                                                                                                                  Imagebase:0x7ff62dd50000
                                                                                                                                                                                                                                  File size:103'126'528 bytes
                                                                                                                                                                                                                                  MD5 hash:FF6DDCC3A1804E75999A12F983EC76A8
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                  Target ID:1
                                                                                                                                                                                                                                  Start time:10:38:12
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                  Imagebase:0x7ff7699e0000
                                                                                                                                                                                                                                  File size:862'208 bytes
                                                                                                                                                                                                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                  Target ID:2
                                                                                                                                                                                                                                  Start time:10:38:13
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\user\None.pdf"
                                                                                                                                                                                                                                  Imagebase:0x7ff6bc1b0000
                                                                                                                                                                                                                                  File size:5'641'176 bytes
                                                                                                                                                                                                                                  MD5 hash:24EAD1C46A47022347DC0F05F6EFBB8C
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:moderate
                                                                                                                                                                                                                                  Has exited:false

                                                                                                                                                                                                                                  Target ID:3
                                                                                                                                                                                                                                  Start time:10:38:15
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --backgroundcolor=16777215
                                                                                                                                                                                                                                  Imagebase:0x7ff74bb60000
                                                                                                                                                                                                                                  File size:3'581'912 bytes
                                                                                                                                                                                                                                  MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:moderate
                                                                                                                                                                                                                                  Has exited:false

                                                                                                                                                                                                                                  Target ID:5
                                                                                                                                                                                                                                  Start time:10:38:15
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --log-severity=disable --user-agent-product="ReaderServices/23.6.20320 Chrome/105.0.0.0" --lang=en-US --user-data-dir="C:\Users\user\AppData\Local\CEF\User Data" --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1896 --field-trial-handle=1640,i,18113123113952577735,16265978303955578204,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:8
                                                                                                                                                                                                                                  Imagebase:0x7ff74bb60000
                                                                                                                                                                                                                                  File size:3'581'912 bytes
                                                                                                                                                                                                                                  MD5 hash:9B38E8E8B6DD9622D24B53E095C5D9BE
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:moderate
                                                                                                                                                                                                                                  Has exited:false

                                                                                                                                                                                                                                  Target ID:9
                                                                                                                                                                                                                                  Start time:10:38:26
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\explorerwin\pdf.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:"C:\explorerwin\pdf.exe"
                                                                                                                                                                                                                                  Imagebase:0x7ff70a1f0000
                                                                                                                                                                                                                                  File size:239'616 bytes
                                                                                                                                                                                                                                  MD5 hash:86EDB9CBB19D37360BB868ACE85691C5
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                  Target ID:10
                                                                                                                                                                                                                                  Start time:10:38:26
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                  Imagebase:0x7ff7699e0000
                                                                                                                                                                                                                                  File size:862'208 bytes
                                                                                                                                                                                                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                  Target ID:11
                                                                                                                                                                                                                                  Start time:10:38:30
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:"C:\explorerwin\explorer.exe"
                                                                                                                                                                                                                                  Imagebase:0x7ff71dbd0000
                                                                                                                                                                                                                                  File size:102'917'049 bytes
                                                                                                                                                                                                                                  MD5 hash:490B24AAABFD71DC7561947289B252A5
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                  Target ID:12
                                                                                                                                                                                                                                  Start time:10:38:30
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                  Imagebase:0x7ff7699e0000
                                                                                                                                                                                                                                  File size:862'208 bytes
                                                                                                                                                                                                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:high
                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                  Target ID:15
                                                                                                                                                                                                                                  Start time:10:38:50
                                                                                                                                                                                                                                  Start date:10/05/2024
                                                                                                                                                                                                                                  Path:C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                  Wow64 process (32bit):false
                                                                                                                                                                                                                                  Commandline:"C:\explorerwin\explorer.exe"
                                                                                                                                                                                                                                  Imagebase:0x7ff71dbd0000
                                                                                                                                                                                                                                  File size:102'917'049 bytes
                                                                                                                                                                                                                                  MD5 hash:490B24AAABFD71DC7561947289B252A5
                                                                                                                                                                                                                                  Has elevated privileges:true
                                                                                                                                                                                                                                  Has administrator privileges:true
                                                                                                                                                                                                                                  Programmed in:C, C++ or other language
                                                                                                                                                                                                                                  Reputation:low
                                                                                                                                                                                                                                  Has exited:true

                                                                                                                                                                                                                                  Reset < >

                                                                                                                                                                                                                                    Execution Graph

                                                                                                                                                                                                                                    Execution Coverage:3.2%
                                                                                                                                                                                                                                    Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                    Signature Coverage:10.5%
                                                                                                                                                                                                                                    Total number of Nodes:897
                                                                                                                                                                                                                                    Total number of Limit Nodes:29
                                                                                                                                                                                                                                    execution_graph 13204 7ff70a1f9029 13205 7ff70a1f912a 13204->13205 13206 7ff70a1f9039 13204->13206 13217 7ff70a1f90ba 13205->13217 13218 7ff70a1f911d 13205->13218 13212 7ff70a1ff850 16 API calls 13206->13212 13206->13217 13206->13218 13207 7ff70a1f9180 13210 7ff70a1f918a memmove 13207->13210 13213 7ff70a1f915b 13207->13213 13208 7ff70a1f91b9 13209 7ff70a210cf0 6 API calls 13208->13209 13211 7ff70a1f91c9 13209->13211 13210->13213 13214 7ff70a1f6be0 6 API calls 13211->13214 13212->13206 13216 7ff70a1f91f6 13214->13216 13215 7ff70a210cf0 6 API calls 13215->13213 13217->13207 13217->13208 13217->13213 13218->13213 13218->13215 12268 7ff70a1f3090 12269 7ff70a1f30b9 12268->12269 12270 7ff70a1f32ac 12269->12270 12271 7ff70a1f33b2 12269->12271 12272 7ff70a1f3118 12269->12272 12273 7ff70a1f33ef 12271->12273 12275 7ff70a1f2820 7 API calls 12271->12275 12308 7ff70a1f5b20 12272->12308 12275->12273 12277 7ff70a1f3142 12277->12270 12288 7ff70a1f2820 7 API calls 12277->12288 12278 7ff70a1f317a 12281 7ff70a1f318b 12278->12281 12282 7ff70a1f326f 12278->12282 12289 7ff70a1f31c1 12278->12289 12279 7ff70a1f2820 7 API calls 12279->12277 12280 7ff70a1f31d1 12316 7ff70a1f3650 12280->12316 12312 7ff70a1f5b90 12281->12312 12285 7ff70a1f3650 7 API calls 12282->12285 12286 7ff70a1f3134 12285->12286 12286->12277 12286->12279 12288->12270 12289->12286 12329 7ff70a1f5c00 12289->12329 12290 7ff70a1f3230 12290->12286 12291 7ff70a1f3250 12290->12291 12293 7ff70a1f5b90 GetLastError 12290->12293 12291->12286 12333 7ff70a1f5d40 12291->12333 12293->12291 12295 7ff70a1f3324 12298 7ff70a1f3385 12295->12298 12299 7ff70a1f332a 12295->12299 12296 7ff70a1f32c9 12337 7ff70a1f2c80 12296->12337 12302 7ff70a1f3398 12298->12302 12305 7ff70a1f2820 7 API calls 12298->12305 12301 7ff70a1f2c80 12 API calls 12299->12301 12300 7ff70a1f3314 12368 7ff70a1f35a0 12300->12368 12304 7ff70a1f3375 12301->12304 12302->12270 12307 7ff70a1f2820 7 API calls 12302->12307 12306 7ff70a1f35a0 6 API calls 12304->12306 12305->12302 12306->12286 12307->12270 12309 7ff70a1f5b4a 12308->12309 12310 7ff70a1f5b64 GetLastError 12309->12310 12311 7ff70a1f3129 12309->12311 12310->12311 12311->12278 12311->12280 12311->12286 12313 7ff70a1f5baa 12312->12313 12314 7ff70a1f5bb5 GetLastError 12313->12314 12315 7ff70a1f5bae 12313->12315 12314->12289 12315->12289 12317 7ff70a1f36a3 12316->12317 12323 7ff70a1f3674 12316->12323 12319 7ff70a1f36a9 memmove 12317->12319 12318 7ff70a1f370f 12321 7ff70a208cc0 6 API calls 12318->12321 12320 7ff70a1f36cd 12319->12320 12322 7ff70a1f36d2 12320->12322 12324 7ff70a2106e0 6 API calls 12320->12324 12321->12322 12322->12286 12326 7ff70a1f9258 12322->12326 12327 7ff70a2106e0 6 API calls 12322->12327 12323->12318 12323->12319 12325 7ff70a2106e0 6 API calls 12323->12325 12324->12318 12325->12317 12326->12286 12328 7ff70a1f9285 12327->12328 12328->12286 12330 7ff70a1f5c41 12329->12330 12331 7ff70a1f5c45 12330->12331 12332 7ff70a1f5c4c GetLastError 12330->12332 12331->12290 12332->12290 12334 7ff70a1f5d54 12333->12334 12335 7ff70a1f5d6f GetLastError 12334->12335 12336 7ff70a1f3262 12334->12336 12335->12336 12336->12286 12336->12295 12336->12296 12338 7ff70a1f2cb3 12337->12338 12339 7ff70a1f2c9a 12337->12339 12340 7ff70a1f2cc9 12338->12340 12360 7ff70a1f2cb8 12338->12360 12346 7ff70a1f2ca4 memmove 12339->12346 12339->12360 12341 7ff70a1f2d23 12340->12341 12342 7ff70a1f2cda 12340->12342 12340->12346 12344 7ff70a208cc0 6 API calls 12341->12344 12345 7ff70a1f2d28 12342->12345 12342->12346 12344->12345 12348 7ff70a2106e0 6 API calls 12345->12348 12346->12300 12347 7ff70a2092d0 12349 7ff70a2092fe 12347->12349 12351 7ff70a210bd0 6 API calls 12347->12351 12350 7ff70a1f2d35 12348->12350 12349->12300 12377 7ff70a1f5970 12350->12377 12354 7ff70a209341 12351->12354 12353 7ff70a1f2d58 12355 7ff70a1f2da7 12353->12355 12357 7ff70a1f5680 GetLastError 12353->12357 12356 7ff70a208cc0 6 API calls 12354->12356 12355->12300 12358 7ff70a209348 12356->12358 12359 7ff70a1f2d71 12357->12359 12358->12300 12361 7ff70a1f2d77 12359->12361 12363 7ff70a1f5650 2 API calls 12359->12363 12360->12347 12360->12354 12362 7ff70a2106e0 6 API calls 12360->12362 12361->12355 12366 7ff70a1f2820 7 API calls 12361->12366 12362->12347 12364 7ff70a1f2d8c 12363->12364 12364->12361 12365 7ff70a1f2da9 12364->12365 12365->12355 12367 7ff70a1f2820 7 API calls 12365->12367 12366->12355 12367->12355 12369 7ff70a1f35cf 12368->12369 12370 7ff70a1f35fa 12369->12370 12373 7ff70a1f35d4 12369->12373 12371 7ff70a2106e0 6 API calls 12370->12371 12372 7ff70a1f360d 12371->12372 12372->12286 12374 7ff70a1f9258 12373->12374 12375 7ff70a2106e0 6 API calls 12373->12375 12374->12286 12376 7ff70a1f9285 12375->12376 12376->12286 12378 7ff70a1f5d90 6 API calls 12377->12378 12379 7ff70a1f59b3 12378->12379 12380 7ff70a1f5a44 GetLastError 12379->12380 12381 7ff70a1f59f0 12379->12381 12382 7ff70a1f5a0b 12380->12382 12381->12382 12383 7ff70a2106e0 6 API calls 12381->12383 12382->12353 12384 7ff70a1f5a94 12383->12384 12384->12353 11362 7ff70a20e458 11363 7ff70a20e471 11362->11363 11364 7ff70a20e479 __scrt_acquire_startup_lock 11363->11364 11365 7ff70a20e5af 11363->11365 11367 7ff70a20e5b9 11364->11367 11372 7ff70a20e497 __scrt_release_startup_lock 11364->11372 11387 7ff70a20e9e4 IsProcessorFeaturePresent 11365->11387 11368 7ff70a20e9e4 9 API calls 11367->11368 11369 7ff70a20e5c4 11368->11369 11371 7ff70a20e5cc _exit 11369->11371 11370 7ff70a20e4bc 11372->11370 11373 7ff70a20e542 _get_initial_narrow_environment __p___argv __p___argc 11372->11373 11376 7ff70a20e53a _register_thread_local_exe_atexit_callback 11372->11376 11382 7ff70a1f27a0 11373->11382 11376->11373 11379 7ff70a20e56f 11380 7ff70a20e579 11379->11380 11381 7ff70a20e574 _cexit 11379->11381 11380->11370 11381->11380 11393 7ff70a1f7f30 RtlAddVectoredExceptionHandler 11382->11393 11384 7ff70a1f27cc 11385 7ff70a20eb34 GetModuleHandleW 11384->11385 11386 7ff70a20e56b 11385->11386 11386->11369 11386->11379 11388 7ff70a20ea0a 11387->11388 11389 7ff70a20ea18 memset RtlCaptureContext RtlLookupFunctionEntry 11388->11389 11390 7ff70a20ea8e memset IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 11389->11390 11391 7ff70a20ea52 RtlVirtualUnwind 11389->11391 11392 7ff70a20eb0e 11390->11392 11391->11390 11392->11367 11394 7ff70a1f8044 11393->11394 11395 7ff70a1f7f69 SetThreadStackGuarantee 11393->11395 11471 7ff70a2107d0 11394->11471 11397 7ff70a1f7f8d 11395->11397 11398 7ff70a1f7f7e GetLastError 11395->11398 11413 7ff70a1ffe10 11397->11413 11398->11397 11399 7ff70a1f8107 11398->11399 11402 7ff70a2107d0 6 API calls 11399->11402 11401 7ff70a1f7f9e 11419 7ff70a208e30 11401->11419 11409 7ff70a1f8036 11402->11409 11404 7ff70a1f7fb7 11404->11409 11433 7ff70a1f8740 11404->11433 11406 7ff70a1f7fdf 11442 7ff70a1fcc60 11406->11442 11408 7ff70a1f7fe7 11449 7ff70a1f1c60 11408->11449 11409->11384 11410 7ff70a1f7ff2 11410->11409 11454 7ff70a210240 11410->11454 11414 7ff70a1ffe26 11413->11414 11417 7ff70a1ffe56 11414->11417 11474 7ff70a200490 11414->11474 11416 7ff70a1ffe42 11416->11417 11418 7ff70a1ffe62 GetCurrentThread SetThreadDescription 11416->11418 11417->11401 11418->11417 11420 7ff70a208f5a 11419->11420 11421 7ff70a208e55 11419->11421 11529 7ff70a2108a0 11420->11529 11423 7ff70a208e5b 11421->11423 11424 7ff70a208f72 11421->11424 11426 7ff70a208f77 11423->11426 11427 7ff70a208e81 memmove 11423->11427 11425 7ff70a208cc0 6 API calls 11424->11425 11425->11426 11428 7ff70a2106e0 6 API calls 11426->11428 11431 7ff70a208e98 11427->11431 11429 7ff70a208f84 11428->11429 11429->11404 11430 7ff70a208ef9 11430->11404 11431->11430 11516 7ff70a208fd0 11431->11516 11540 7ff70a2096a0 11433->11540 11435 7ff70a1f8794 11439 7ff70a1f87d3 11435->11439 11545 7ff70a210000 11435->11545 11436 7ff70a1f87ee 11438 7ff70a2106e0 6 API calls 11436->11438 11437 7ff70a1f876f 11437->11435 11437->11436 11441 7ff70a1f87fd 11438->11441 11439->11406 11441->11406 11443 7ff70a1fcc9f 11442->11443 11446 7ff70a1fccd1 11442->11446 11444 7ff70a1fcd9c 11443->11444 11445 7ff70a1fcca7 11443->11445 11448 7ff70a210bd0 6 API calls 11444->11448 11551 7ff70a1ffea0 11445->11551 11446->11408 11448->11446 11564 7ff70a1f1c50 11449->11564 11453 7ff70a1f1cda 11453->11410 11465 7ff70a21028b 11454->11465 11455 7ff70a2104f8 11458 7ff70a2107d0 6 API calls 11455->11458 11456 7ff70a210434 12147 7ff70a200b10 11456->12147 11457 7ff70a210470 11457->11409 11459 7ff70a2102ce 11458->11459 11460 7ff70a2108a0 6 API calls 11459->11460 11464 7ff70a210547 11460->11464 11462 7ff70a210485 11466 7ff70a210760 6 API calls 11462->11466 11463 7ff70a1f8740 6 API calls 11463->11465 11464->11409 11465->11455 11465->11456 11465->11457 11465->11459 11465->11462 11465->11463 11467 7ff70a1ffea0 6 API calls 11465->11467 11468 7ff70a21049d 11465->11468 12132 7ff70a1f8550 11465->12132 11466->11468 11467->11465 11469 7ff70a2107d0 6 API calls 11468->11469 11469->11455 12177 7ff70a1fdc70 11471->12177 11475 7ff70a2004bf 11474->11475 11476 7ff70a2004ed 11474->11476 11477 7ff70a20060e 11475->11477 11478 7ff70a2004cc 11475->11478 11487 7ff70a1f7da0 11476->11487 11499 7ff70a208cc0 11477->11499 11478->11476 11481 7ff70a200613 11478->11481 11502 7ff70a2106e0 11481->11502 11486 7ff70a2005a1 11486->11416 11490 7ff70a1f7dcb 11487->11490 11488 7ff70a1f7f0b 11488->11486 11491 7ff70a1f7bf0 11488->11491 11490->11488 11508 7ff70a20fe90 11490->11508 11492 7ff70a1f7c87 11491->11492 11495 7ff70a1f7bff 11491->11495 11493 7ff70a208cc0 6 API calls 11492->11493 11494 7ff70a1f7c8c 11493->11494 11494->11486 11495->11492 11495->11494 11496 7ff70a1f7c9a 11495->11496 11497 7ff70a2106e0 6 API calls 11496->11497 11498 7ff70a1f7ca4 11497->11498 11498->11486 11500 7ff70a2107d0 6 API calls 11499->11500 11501 7ff70a208cfe 11500->11501 11501->11481 11503 7ff70a2106f2 11502->11503 11504 7ff70a2107d0 6 API calls 11503->11504 11505 7ff70a210758 11504->11505 11506 7ff70a2107d0 6 API calls 11505->11506 11507 7ff70a2107c2 11506->11507 11509 7ff70a20ff27 11508->11509 11512 7ff70a20fe9f 11508->11512 11510 7ff70a208cc0 6 API calls 11509->11510 11511 7ff70a20ff2c 11510->11511 11511->11488 11512->11509 11512->11511 11513 7ff70a20ff3a 11512->11513 11514 7ff70a2106e0 6 API calls 11513->11514 11515 7ff70a20ff44 11514->11515 11523 7ff70a208ff8 11516->11523 11524 7ff70a209063 11516->11524 11517 7ff70a209122 11520 7ff70a208cc0 6 API calls 11517->11520 11518 7ff70a2090d7 11518->11430 11522 7ff70a2090d5 11520->11522 11521 7ff70a20907b 11521->11518 11525 7ff70a2106e0 6 API calls 11521->11525 11522->11430 11523->11517 11523->11524 11526 7ff70a20911d 11523->11526 11524->11521 11532 7ff70a208b80 11524->11532 11525->11522 11526->11517 11527 7ff70a209131 11526->11527 11528 7ff70a2106e0 6 API calls 11527->11528 11528->11522 11530 7ff70a2107d0 6 API calls 11529->11530 11531 7ff70a2108e2 11530->11531 11533 7ff70a208c11 11532->11533 11536 7ff70a208b8f 11532->11536 11534 7ff70a208cc0 6 API calls 11533->11534 11535 7ff70a208c16 11534->11535 11535->11521 11536->11533 11536->11535 11537 7ff70a208c24 11536->11537 11538 7ff70a2106e0 6 API calls 11537->11538 11539 7ff70a208c2e 11538->11539 11541 7ff70a2096c5 11540->11541 11543 7ff70a2096dc 11541->11543 11548 7ff70a210bd0 11541->11548 11543->11437 11546 7ff70a2107d0 6 API calls 11545->11546 11547 7ff70a21003e 11546->11547 11549 7ff70a2107d0 6 API calls 11548->11549 11550 7ff70a210c63 11549->11550 11552 7ff70a1ffed8 11551->11552 11555 7ff70a1fff8c 11551->11555 11553 7ff70a1fff28 11552->11553 11556 7ff70a1f7a80 11552->11556 11553->11446 11555->11446 11557 7ff70a1f7b1f 11556->11557 11560 7ff70a1f7a8f 11556->11560 11558 7ff70a208cc0 6 API calls 11557->11558 11559 7ff70a1f7b24 11558->11559 11559->11553 11560->11557 11560->11559 11561 7ff70a1f7b32 11560->11561 11562 7ff70a2106e0 6 API calls 11561->11562 11563 7ff70a1f7b3c 11562->11563 11572 7ff70a1f20c0 11564->11572 11565 7ff70a1f1c56 11565->11453 11567 7ff70a1fa0c0 11565->11567 12111 7ff70a1f9ea0 11567->12111 11569 7ff70a1fa0cd 11571 7ff70a1fa0f4 11569->11571 12119 7ff70a1f9d10 11569->12119 11571->11453 11573 7ff70a1f20df 11572->11573 11574 7ff70a1f24ce 11573->11574 11575 7ff70a1f20e8 11573->11575 11576 7ff70a210bd0 6 API calls 11574->11576 11639 7ff70a1f9800 11575->11639 11583 7ff70a1f24c9 11576->11583 11578 7ff70a1f20ed 11644 7ff70a1f3e20 11578->11644 11581 7ff70a1f2105 11662 7ff70a1f19c0 11581->11662 11582 7ff70a1f2111 11585 7ff70a1f9830 19 API calls 11582->11585 11583->11565 11586 7ff70a1f210f 11585->11586 11587 7ff70a1f21b0 11586->11587 11588 7ff70a1f3e20 44 API calls 11586->11588 11589 7ff70a210bd0 6 API calls 11587->11589 11590 7ff70a1f213d 11588->11590 11589->11583 11591 7ff70a1f2155 11590->11591 11592 7ff70a1f2145 11590->11592 11594 7ff70a1f9830 19 API calls 11591->11594 11666 7ff70a1f1870 11592->11666 11595 7ff70a1f2153 11594->11595 11595->11587 11596 7ff70a1f3e20 44 API calls 11595->11596 11597 7ff70a1f218d 11596->11597 11598 7ff70a1f21b5 11597->11598 11599 7ff70a1f2191 11597->11599 11601 7ff70a1f9830 19 API calls 11598->11601 11670 7ff70a1f1b00 11599->11670 11604 7ff70a1f21be 11601->11604 11602 7ff70a1f3e20 44 API calls 11603 7ff70a1f22ba 11602->11603 11605 7ff70a1f22e1 11603->11605 11606 7ff70a1f22be 11603->11606 11604->11587 11607 7ff70a1f2245 11604->11607 11608 7ff70a1f2567 11604->11608 11611 7ff70a1f9830 19 API calls 11605->11611 11684 7ff70a1f9850 11606->11684 11612 7ff70a1f2260 SetConsoleTitleW 11607->11612 11674 7ff70a1f1330 11607->11674 11610 7ff70a210bd0 6 API calls 11608->11610 11610->11583 11616 7ff70a1f22d4 11611->11616 11613 7ff70a1f21a7 11612->11613 11614 7ff70a1f2479 GetLastError 11612->11614 11613->11587 11613->11602 11614->11613 11616->11587 11618 7ff70a1f9800 9 API calls 11616->11618 11617 7ff70a1f225c 11617->11612 11619 7ff70a1f230a 11618->11619 11648 7ff70a1f9830 11619->11648 11622 7ff70a1f2320 11623 7ff70a1f24ff 11622->11623 11624 7ff70a1f232e 11622->11624 11625 7ff70a210bd0 6 API calls 11623->11625 11651 7ff70a1f1470 11624->11651 11625->11583 11627 7ff70a1f235e 11628 7ff70a1f2402 11627->11628 11629 7ff70a1f2377 11627->11629 11687 7ff70a208d30 11628->11687 11631 7ff70a208e30 7 API calls 11629->11631 11632 7ff70a1f238d 11631->11632 11633 7ff70a1f23a1 GetProcAddress 11632->11633 11634 7ff70a1f252d 11632->11634 11635 7ff70a1f241b 11633->11635 11638 7ff70a1f23be 11633->11638 11636 7ff70a210bd0 6 API calls 11634->11636 11637 7ff70a208d30 7 API calls 11635->11637 11636->11583 11637->11638 11638->11565 11640 7ff70a1f9811 11639->11640 11641 7ff70a1f981d 11639->11641 11640->11578 11698 7ff70a210160 11641->11698 11643 7ff70a1f9822 11643->11578 11645 7ff70a1f20fd 11644->11645 11646 7ff70a1f3e40 11644->11646 11645->11581 11645->11582 11703 7ff70a20f0c0 11646->11703 11961 7ff70a1f9870 11648->11961 11650 7ff70a1f2317 11650->11587 11650->11622 11653 7ff70a1f149c 11651->11653 11652 7ff70a1f1564 11652->11627 11653->11652 11654 7ff70a1f1621 11653->11654 11655 7ff70a1f180d 11653->11655 11657 7ff70a1f1812 11654->11657 11660 7ff70a1f164a 11654->11660 11656 7ff70a208cc0 6 API calls 11655->11656 11656->11657 11658 7ff70a2106e0 6 API calls 11657->11658 11659 7ff70a1f181f 11658->11659 11659->11627 11660->11652 12041 7ff70a20ef40 11660->12041 11664 7ff70a1f1a43 11662->11664 11663 7ff70a1f1aaf 11663->11586 11664->11663 11665 7ff70a2107d0 6 API calls 11664->11665 11665->11663 11667 7ff70a1f1900 11666->11667 11668 7ff70a2107d0 6 API calls 11667->11668 11669 7ff70a1f1970 11667->11669 11668->11669 11669->11595 11671 7ff70a1f1b8b 11670->11671 11672 7ff70a1f1bf7 11671->11672 11673 7ff70a2107d0 6 API calls 11671->11673 11672->11613 11673->11672 11675 7ff70a1f13c7 11674->11675 11678 7ff70a1f133f 11674->11678 11676 7ff70a208cc0 6 API calls 11675->11676 11677 7ff70a1f13cc 11676->11677 11677->11617 11678->11675 11678->11677 11679 7ff70a1f13da 11678->11679 11680 7ff70a2106e0 6 API calls 11679->11680 11681 7ff70a1f13e4 11680->11681 11682 7ff70a1f9850 22 API calls 11681->11682 11683 7ff70a1f140e 11682->11683 11683->11617 12049 7ff70a1f99c0 11684->12049 11686 7ff70a1f9863 11686->11616 11688 7ff70a208d7f 11687->11688 11689 7ff70a208d50 11687->11689 11690 7ff70a208d84 memmove 11688->11690 11689->11690 11695 7ff70a2106e0 6 API calls 11689->11695 11697 7ff70a208ddf 11689->11697 11693 7ff70a208da8 11690->11693 11691 7ff70a208cc0 6 API calls 11692 7ff70a208de6 11691->11692 11692->11638 11694 7ff70a208dad 11693->11694 11696 7ff70a2106e0 6 API calls 11693->11696 11694->11638 11695->11688 11696->11697 11697->11691 11699 7ff70a210171 11698->11699 11700 7ff70a210176 11698->11700 11699->11643 11701 7ff70a210240 9 API calls 11700->11701 11702 7ff70a2101bc 11701->11702 11702->11643 11704 7ff70a20f117 11703->11704 11717 7ff70a20f43a 11703->11717 11707 7ff70a20f44e 11704->11707 11709 7ff70a20f368 Sleep 11704->11709 11714 7ff70a20f489 11704->11714 11704->11717 11719 7ff70a20f498 11704->11719 11736 7ff70a1f45d0 11704->11736 11742 7ff70a1f50f0 11704->11742 11754 7ff70a20f7c0 11704->11754 11757 7ff70a20f820 11704->11757 11722 7ff70a1f37d0 11707->11722 11709->11704 11711 7ff70a20f473 11711->11717 11761 7ff70a1f4060 11711->11761 11773 7ff70a210940 11714->11773 11717->11645 11784 7ff70a20f7a0 11719->11784 11787 7ff70a1f8b10 11722->11787 11725 7ff70a1f37ff 11732 7ff70a1f387f 11725->11732 11790 7ff70a1f57d0 11725->11790 11726 7ff70a1f3877 11726->11732 11798 7ff70a1f5680 11726->11798 11729 7ff70a1f3900 11729->11732 11805 7ff70a1f2820 11729->11805 11730 7ff70a1f393c 11730->11732 11735 7ff70a1f2820 7 API calls 11730->11735 11732->11711 11734 7ff70a1f3934 11734->11729 11734->11730 11735->11732 11737 7ff70a1f45f4 11736->11737 11740 7ff70a1f45e8 11736->11740 11738 7ff70a1ffea0 6 API calls 11737->11738 11738->11740 11739 7ff70a1f45ed 11739->11704 11740->11739 11741 7ff70a1f50f0 28 API calls 11740->11741 11741->11739 11750 7ff70a1f5130 11742->11750 11743 7ff70a20f7c0 10 API calls 11743->11750 11744 7ff70a1f5204 11744->11704 11745 7ff70a1f522a 11843 7ff70a1f4dd0 11745->11843 11748 7ff70a1f533c 11748->11704 11749 7ff70a20f820 24 API calls 11749->11750 11750->11743 11750->11745 11750->11749 11751 7ff70a1f51f4 11750->11751 11751->11744 11858 7ff70a20fb10 GetModuleHandleA 11751->11858 11752 7ff70a210940 6 API calls 11752->11751 11753 7ff70a1f5235 11753->11751 11753->11752 11755 7ff70a1f4dd0 10 API calls 11754->11755 11756 7ff70a20f7d2 11755->11756 11756->11704 11760 7ff70a20f841 11757->11760 11758 7ff70a20f86a 11758->11704 11759 7ff70a20fb10 24 API calls 11759->11760 11760->11758 11760->11759 11765 7ff70a1f40b0 11761->11765 11762 7ff70a20f7c0 10 API calls 11762->11765 11763 7ff70a1f440f 11764 7ff70a210940 6 API calls 11763->11764 11766 7ff70a1f441e 11764->11766 11765->11762 11765->11763 11767 7ff70a20f820 24 API calls 11765->11767 11768 7ff70a1f412c 11765->11768 11766->11717 11767->11765 11769 7ff70a1f4171 11768->11769 11914 7ff70a20f550 11768->11914 11770 7ff70a1f42f0 memmove 11769->11770 11772 7ff70a1f4352 11770->11772 11772->11717 11774 7ff70a2107d0 6 API calls 11773->11774 11775 7ff70a2109b4 11774->11775 11937 7ff70a2108f0 11775->11937 11955 7ff70a1f4a10 11784->11955 11808 7ff70a1f8c40 11787->11808 11789 7ff70a1f8b23 11789->11725 11825 7ff70a1f5d90 11790->11825 11792 7ff70a1f5813 CreateFileW 11793 7ff70a1f58a4 GetLastError 11792->11793 11794 7ff70a1f5850 11792->11794 11795 7ff70a1f586b 11793->11795 11794->11795 11796 7ff70a2106e0 6 API calls 11794->11796 11795->11726 11797 7ff70a1f58f4 11796->11797 11797->11726 11799 7ff70a1f56a1 11798->11799 11800 7ff70a1f38fa 11799->11800 11801 7ff70a1f56b0 GetLastError 11799->11801 11800->11729 11800->11730 11802 7ff70a1f5650 SetConsoleMode 11800->11802 11801->11800 11803 7ff70a1f5664 11802->11803 11804 7ff70a1f566b GetLastError 11802->11804 11803->11734 11804->11734 11837 7ff70a1f56e0 11805->11837 11809 7ff70a200490 6 API calls 11808->11809 11815 7ff70a1f8c72 11809->11815 11810 7ff70a1f8d78 SetLastError GetEnvironmentVariableW 11812 7ff70a1f8d99 GetLastError 11810->11812 11810->11815 11811 7ff70a20fe90 6 API calls 11811->11815 11813 7ff70a1f8ebb GetLastError 11812->11813 11812->11815 11817 7ff70a1f8c85 11813->11817 11814 7ff70a1f8db3 GetLastError 11814->11815 11816 7ff70a1f8ef6 11814->11816 11815->11810 11815->11811 11815->11814 11815->11817 11818 7ff70a1f8de6 11815->11818 11821 7ff70a2108a0 6 API calls 11816->11821 11817->11789 11819 7ff70a1f8f10 11818->11819 11820 7ff70a1f8def 11818->11820 11822 7ff70a210cf0 6 API calls 11819->11822 11823 7ff70a1fabd0 7 API calls 11820->11823 11824 7ff70a1f8f0e 11821->11824 11822->11824 11823->11817 11824->11789 11830 7ff70a1f5dba 11825->11830 11826 7ff70a1f5fa7 11826->11792 11827 7ff70a1f5e0d 11831 7ff70a1f60c1 11827->11831 11834 7ff70a1f5e35 11827->11834 11828 7ff70a1f60bc 11829 7ff70a208cc0 6 API calls 11828->11829 11829->11831 11830->11826 11830->11827 11830->11828 11832 7ff70a2106e0 6 API calls 11831->11832 11833 7ff70a1f60ce 11832->11833 11833->11792 11834->11826 11835 7ff70a20f000 6 API calls 11834->11835 11836 7ff70a1f5f9e 11835->11836 11836->11792 11838 7ff70a1f2831 11837->11838 11839 7ff70a1f56ea CloseHandle 11837->11839 11838->11732 11839->11838 11840 7ff70a1f56fb 11839->11840 11841 7ff70a20fcf0 6 API calls 11840->11841 11842 7ff70a1f5700 11841->11842 11877 7ff70a1fbf40 QueryPerformanceCounter 11843->11877 11845 7ff70a1f4f42 11846 7ff70a208cc0 6 API calls 11845->11846 11848 7ff70a1f4fda 11846->11848 11847 7ff70a1f4e25 11847->11845 11849 7ff70a1f4e69 11847->11849 11850 7ff70a2106e0 6 API calls 11847->11850 11848->11753 11852 7ff70a1f4ef3 11849->11852 11884 7ff70a1f54c0 11849->11884 11850->11849 11853 7ff70a1f4f47 11852->11853 11855 7ff70a1f4f2d 11852->11855 11854 7ff70a1f4f7a 11853->11854 11857 7ff70a2106e0 6 API calls 11853->11857 11854->11753 11856 7ff70a2106e0 6 API calls 11855->11856 11856->11845 11857->11845 11859 7ff70a20fb6e GetModuleHandleA 11858->11859 11860 7ff70a20fb36 GetProcAddress 11858->11860 11862 7ff70a20fc63 11859->11862 11863 7ff70a20fb83 GetProcAddress 11859->11863 11860->11859 11861 7ff70a20fb4d GetProcAddress 11860->11861 11861->11859 11871 7ff70a20fb64 11861->11871 11892 7ff70a20fae0 11862->11892 11863->11862 11864 7ff70a20fb9e GetProcAddress 11863->11864 11864->11862 11867 7ff70a20fbb9 GetProcAddress 11864->11867 11866 7ff70a20fc68 11869 7ff70a2106e0 6 API calls 11866->11869 11867->11862 11868 7ff70a20fbd4 11867->11868 11868->11862 11868->11871 11870 7ff70a20fc7f 11869->11870 11872 7ff70a20fca8 CloseHandle 11870->11872 11873 7ff70a20fcb1 11870->11873 11871->11866 11874 7ff70a20fc0b 11871->11874 11872->11873 11873->11748 11875 7ff70a20fc40 11874->11875 11876 7ff70a20fc33 CloseHandle 11874->11876 11875->11748 11876->11875 11878 7ff70a1fbf78 GetLastError 11877->11878 11879 7ff70a1fbf68 11877->11879 11880 7ff70a210bd0 6 API calls 11878->11880 11881 7ff70a200190 8 API calls 11879->11881 11883 7ff70a1fbfb2 11880->11883 11882 7ff70a1fbf71 11881->11882 11882->11847 11883->11847 11885 7ff70a1f555f 11884->11885 11888 7ff70a1f54cf 11884->11888 11886 7ff70a208cc0 6 API calls 11885->11886 11887 7ff70a1f5564 11886->11887 11887->11849 11888->11885 11888->11887 11889 7ff70a1f5572 11888->11889 11890 7ff70a2106e0 6 API calls 11889->11890 11891 7ff70a1f557c 11890->11891 11893 7ff70a1f53f0 6 API calls 11892->11893 11894 7ff70a20fb0f GetModuleHandleA 11893->11894 11896 7ff70a20fb6e GetModuleHandleA 11894->11896 11897 7ff70a20fb36 GetProcAddress 11894->11897 11899 7ff70a20fc63 11896->11899 11900 7ff70a20fb83 GetProcAddress 11896->11900 11897->11896 11898 7ff70a20fb4d GetProcAddress 11897->11898 11898->11896 11908 7ff70a20fb64 11898->11908 11902 7ff70a20fae0 6 API calls 11899->11902 11900->11899 11901 7ff70a20fb9e GetProcAddress 11900->11901 11901->11899 11904 7ff70a20fbb9 GetProcAddress 11901->11904 11903 7ff70a20fc68 11902->11903 11906 7ff70a2106e0 6 API calls 11903->11906 11904->11899 11905 7ff70a20fbd4 11904->11905 11905->11899 11905->11908 11907 7ff70a20fc7f 11906->11907 11909 7ff70a20fca8 CloseHandle 11907->11909 11910 7ff70a20fcb1 11907->11910 11908->11903 11911 7ff70a20fc0b 11908->11911 11909->11910 11910->11866 11912 7ff70a20fc40 11911->11912 11913 7ff70a20fc33 CloseHandle 11911->11913 11912->11866 11913->11912 11915 7ff70a20f570 11914->11915 11916 7ff70a20f70a 11915->11916 11918 7ff70a20f5a4 11915->11918 11934 7ff70a210760 11916->11934 11919 7ff70a20f722 11918->11919 11921 7ff70a20f5cd 11918->11921 11920 7ff70a2108a0 6 API calls 11919->11920 11930 7ff70a20f6b4 11920->11930 11923 7ff70a20f5dd memmove 11921->11923 11926 7ff70a20f614 11921->11926 11933 7ff70a20f6e6 11921->11933 11922 7ff70a2108a0 6 API calls 11924 7ff70a20f752 11922->11924 11923->11924 11923->11926 11925 7ff70a210bd0 6 API calls 11924->11925 11927 7ff70a20f6c6 11925->11927 11926->11924 11929 7ff70a20f67b 11926->11929 11926->11930 11926->11933 11928 7ff70a2106e0 6 API calls 11927->11928 11927->11933 11931 7ff70a20f796 11928->11931 11929->11927 11932 7ff70a20f698 memmove 11929->11932 11930->11922 11930->11927 11932->11933 11933->11768 11935 7ff70a2107d0 6 API calls 11934->11935 11936 7ff70a2107c2 11935->11936 11950 7ff70a210810 11937->11950 11951 7ff70a1fdc70 6 API calls 11950->11951 11952 7ff70a210871 11951->11952 11953 7ff70a2109c0 6 API calls 11952->11953 11954 7ff70a210896 11953->11954 11958 7ff70a1f4ba0 11955->11958 11957 7ff70a1f4a19 11959 7ff70a1fe030 6 API calls 11958->11959 11960 7ff70a1f4bce 11959->11960 11960->11957 11962 7ff70a1f98bc AcquireSRWLockExclusive 11961->11962 11963 7ff70a1f98ac 11961->11963 11962->11963 11964 7ff70a1f993a 11963->11964 11966 7ff70a1f98f5 11963->11966 11967 7ff70a1f992e 11963->11967 11965 7ff70a210760 6 API calls 11964->11965 11970 7ff70a1f9954 11965->11970 11974 7ff70a1f8fe0 11966->11974 11988 7ff70a210700 11967->11988 11970->11650 11971 7ff70a1f9906 11972 7ff70a1f9916 ReleaseSRWLockExclusive 11971->11972 11973 7ff70a1f9924 11971->11973 11972->11973 11973->11650 11977 7ff70a1f911d 11974->11977 11980 7ff70a1f900e 11974->11980 11976 7ff70a1f915b 11976->11971 11977->11976 12004 7ff70a210cf0 11977->12004 11979 7ff70a1f90ba 11979->11976 11981 7ff70a1f9180 11979->11981 11982 7ff70a1f91b9 11979->11982 11980->11977 11980->11979 11993 7ff70a1ff850 11980->11993 11981->11976 11984 7ff70a1f918a memmove 11981->11984 11983 7ff70a210cf0 6 API calls 11982->11983 11985 7ff70a1f91c9 11983->11985 11984->11976 12007 7ff70a1f6be0 11985->12007 11987 7ff70a1f91f6 11987->11971 11989 7ff70a2107d0 6 API calls 11988->11989 11990 7ff70a210758 11989->11990 11991 7ff70a2107d0 6 API calls 11990->11991 11992 7ff70a2107c2 11991->11992 11994 7ff70a1ff8a6 11993->11994 11995 7ff70a1ff877 GetStdHandle 11993->11995 11994->11980 11995->11994 11996 7ff70a1ff88a 11995->11996 11996->11994 11997 7ff70a1ff8c0 GetConsoleMode 11996->11997 11998 7ff70a1ff941 11997->11998 11999 7ff70a1ff8d8 11997->11999 12033 7ff70a1fee10 11998->12033 11999->11998 12002 7ff70a1ff96c 11999->12002 12002->11994 12012 7ff70a1ffb90 12002->12012 12005 7ff70a2107d0 6 API calls 12004->12005 12006 7ff70a210d64 12005->12006 12008 7ff70a1f6bfa 12007->12008 12009 7ff70a1f6beb 12007->12009 12008->11987 12009->12008 12010 7ff70a210cf0 6 API calls 12009->12010 12011 7ff70a1f6c30 12010->12011 12014 7ff70a1ffba1 12012->12014 12013 7ff70a1ffbe9 MultiByteToWideChar 12015 7ff70a1ffc16 12013->12015 12016 7ff70a1ffd87 12013->12016 12014->12013 12017 7ff70a1ffc24 WriteConsoleW 12015->12017 12018 7ff70a1ffdc1 12015->12018 12019 7ff70a2107d0 6 API calls 12016->12019 12020 7ff70a1ffc53 12017->12020 12021 7ff70a1ffd3e GetLastError 12017->12021 12022 7ff70a210cf0 6 API calls 12018->12022 12019->12018 12024 7ff70a1ffc66 12020->12024 12025 7ff70a1ffd75 12020->12025 12032 7ff70a1ffcdd 12020->12032 12021->12032 12023 7ff70a1ffcd4 12022->12023 12026 7ff70a210cf0 6 API calls 12023->12026 12023->12032 12024->12023 12028 7ff70a1ffc7a WriteConsoleW 12024->12028 12027 7ff70a210940 6 API calls 12025->12027 12029 7ff70a1ffde7 12026->12029 12027->12016 12028->12023 12030 7ff70a1ffcae GetLastError 12028->12030 12031 7ff70a1f6a20 12030->12031 12031->12023 12034 7ff70a1fee54 NtWriteFile 12033->12034 12035 7ff70a1fee44 12033->12035 12036 7ff70a1feea1 WaitForSingleObject 12034->12036 12037 7ff70a1feeba 12034->12037 12035->12034 12036->12037 12040 7ff70a1feef1 12036->12040 12038 7ff70a1feebe 12037->12038 12039 7ff70a1feecb RtlNtStatusToDosError 12037->12039 12038->11994 12039->12038 12042 7ff70a20efd7 12041->12042 12045 7ff70a20ef4f 12041->12045 12043 7ff70a208cc0 6 API calls 12042->12043 12044 7ff70a20efdc 12043->12044 12044->11660 12045->12042 12045->12044 12046 7ff70a20efea 12045->12046 12047 7ff70a2106e0 6 API calls 12046->12047 12048 7ff70a20eff4 12047->12048 12050 7ff70a1f9a04 12049->12050 12051 7ff70a1f9a10 AcquireSRWLockExclusive 12049->12051 12052 7ff70a1f9a7b 12050->12052 12053 7ff70a1f9a0b 12050->12053 12051->12053 12055 7ff70a210760 6 API calls 12052->12055 12062 7ff70a1f9ae0 12053->12062 12057 7ff70a1f9a93 12055->12057 12056 7ff70a1f9a55 12058 7ff70a1f9a61 ReleaseSRWLockExclusive 12056->12058 12059 7ff70a1f9a6f 12056->12059 12060 7ff70a1f9acc 12057->12060 12061 7ff70a1f9aba ReleaseSRWLockExclusive 12057->12061 12058->12059 12059->11686 12060->11686 12061->12060 12063 7ff70a1f9cb1 12062->12063 12064 7ff70a1f9b09 12062->12064 12065 7ff70a210700 6 API calls 12063->12065 12091 7ff70a20bc60 12064->12091 12067 7ff70a1f9cbd 12065->12067 12069 7ff70a2108a0 6 API calls 12067->12069 12071 7ff70a1f9cd5 12069->12071 12070 7ff70a1f9b30 12070->12067 12072 7ff70a1f9b3f 12070->12072 12071->12056 12073 7ff70a1f9bc1 12072->12073 12074 7ff70a1f9b49 12072->12074 12098 7ff70a1fa170 12073->12098 12080 7ff70a1f9c11 12074->12080 12081 7ff70a1f9b58 memmove 12074->12081 12075 7ff70a1f9b78 12076 7ff70a1f9b9b 12075->12076 12082 7ff70a1f8fe0 17 API calls 12075->12082 12077 7ff70a1f9c6c memmove 12076->12077 12078 7ff70a1f9bbc 12076->12078 12084 7ff70a1f9c5c 12076->12084 12077->12084 12079 7ff70a210040 16 API calls 12078->12079 12079->12084 12105 7ff70a210040 12080->12105 12085 7ff70a1f9c1f 12081->12085 12082->12076 12084->12056 12085->12084 12087 7ff70a1f8fe0 17 API calls 12085->12087 12088 7ff70a1f9bd1 12087->12088 12088->12077 12088->12084 12089 7ff70a1f9c4e 12088->12089 12090 7ff70a210040 16 API calls 12089->12090 12090->12084 12092 7ff70a20bc97 12091->12092 12093 7ff70a20bc81 12091->12093 12095 7ff70a210cf0 6 API calls 12092->12095 12097 7ff70a1f9b22 12092->12097 12093->12092 12108 7ff70a210c70 12093->12108 12096 7ff70a20bd83 12095->12096 12097->12070 12097->12075 12099 7ff70a1fa22d 12098->12099 12101 7ff70a1fa188 12098->12101 12099->12088 12100 7ff70a1ff850 16 API calls 12100->12101 12101->12099 12101->12100 12102 7ff70a1fa24f 12101->12102 12103 7ff70a210c70 6 API calls 12102->12103 12104 7ff70a1fa25e 12103->12104 12106 7ff70a210071 12105->12106 12107 7ff70a1fa170 16 API calls 12106->12107 12109 7ff70a2107d0 6 API calls 12108->12109 12110 7ff70a210ce4 12109->12110 12112 7ff70a1f9ec4 12111->12112 12118 7ff70a1f9f9b 12111->12118 12113 7ff70a1f9ee4 12112->12113 12128 7ff70a1fec70 12112->12128 12115 7ff70a1f9f15 AcquireSRWLockExclusive 12113->12115 12113->12118 12116 7ff70a1f9f3a 12115->12116 12117 7ff70a1f9fce ReleaseSRWLockExclusive 12116->12117 12117->12118 12118->11569 12120 7ff70a1f9d60 AcquireSRWLockExclusive 12119->12120 12121 7ff70a1f9d50 12119->12121 12123 7ff70a1f9d5b 12120->12123 12122 7ff70a1f9e0d 12121->12122 12121->12123 12124 7ff70a210760 6 API calls 12122->12124 12126 7ff70a1f9dd5 ReleaseSRWLockExclusive 12123->12126 12127 7ff70a1f9de7 12123->12127 12125 7ff70a1f9e25 12124->12125 12125->11571 12126->12127 12127->11571 12129 7ff70a1feca4 12128->12129 12131 7ff70a1fec98 12128->12131 12130 7ff70a1ffea0 6 API calls 12129->12130 12130->12131 12131->12113 12158 7ff70a1fcaf0 12132->12158 12135 7ff70a1f857e 12138 7ff70a1f85ef 12135->12138 12139 7ff70a1f8598 12135->12139 12144 7ff70a1f85cd 12135->12144 12136 7ff70a1f866c 12137 7ff70a210760 6 API calls 12136->12137 12140 7ff70a1f8684 12137->12140 12142 7ff70a1f8686 12138->12142 12143 7ff70a1f8620 12138->12143 12138->12144 12141 7ff70a1f85b0 WaitOnAddress 12139->12141 12140->11465 12141->12141 12141->12144 12145 7ff70a2107d0 6 API calls 12142->12145 12143->12144 12146 7ff70a1f8636 CloseHandle 12143->12146 12144->11465 12145->12140 12146->12144 12148 7ff70a200cb9 12147->12148 12156 7ff70a200b4e 12147->12156 12166 7ff70a20fe50 12148->12166 12150 7ff70a200c3e 12150->11457 12152 7ff70a200c50 12153 7ff70a2108a0 6 API calls 12152->12153 12154 7ff70a200c68 12153->12154 12155 7ff70a2107d0 6 API calls 12154->12155 12155->12148 12156->12150 12156->12152 12156->12154 12157 7ff70a200c13 CloseHandle 12156->12157 12157->12156 12159 7ff70a1fcb22 12158->12159 12160 7ff70a1fcb50 12158->12160 12161 7ff70a1ffea0 6 API calls 12159->12161 12164 7ff70a1f8572 12159->12164 12162 7ff70a1f8740 6 API calls 12160->12162 12160->12164 12161->12160 12163 7ff70a1fcb7d 12162->12163 12163->12164 12165 7ff70a2107d0 6 API calls 12163->12165 12164->12135 12164->12136 12165->12164 12169 7ff70a2109e0 12166->12169 12170 7ff70a210a0f 12169->12170 12171 7ff70a210afc 12170->12171 12173 7ff70a2107d0 6 API calls 12170->12173 12172 7ff70a2107d0 6 API calls 12171->12172 12174 7ff70a210bc6 12172->12174 12173->12170 12175 7ff70a2107d0 6 API calls 12174->12175 12176 7ff70a210c63 12175->12176 12178 7ff70a1fdc95 12177->12178 12179 7ff70a1fdc7d 12177->12179 12186 7ff70a1fc8f0 12178->12186 12180 7ff70a2108a0 6 API calls 12179->12180 12180->12178 12189 7ff70a1fdf30 12186->12189 12188 7ff70a1fc8f9 12191 7ff70a1fdf53 12189->12191 12190 7ff70a1fdfab 12192 7ff70a1fe030 6 API calls 12190->12192 12191->12190 12195 7ff70a1fe030 12191->12195 12194 7ff70a1fdfe9 12192->12194 12194->12188 12196 7ff70a1fe069 12195->12196 12198 7ff70a1fe17d 12195->12198 12197 7ff70a1fe08f AcquireSRWLockShared 12196->12197 12196->12198 12199 7ff70a1fe0f6 12197->12199 12200 7ff70a1fe114 ReleaseSRWLockShared 12197->12200 12198->12190 12205 7ff70a1fd640 12199->12205 12200->12198 12203 7ff70a1fe16e 12200->12203 12229 7ff70a1fe380 12203->12229 12206 7ff70a1fd66a 12205->12206 12208 7ff70a1fd664 12205->12208 12206->12208 12232 7ff70a1fadb0 12206->12232 12209 7ff70a1fcaf0 4 API calls 12208->12209 12212 7ff70a1fd723 12209->12212 12210 7ff70a1fd7ae 12214 7ff70a1fdb20 2 API calls 12210->12214 12211 7ff70a1fd7a5 12211->12210 12216 7ff70a1fd7ea AcquireSRWLockExclusive 12211->12216 12212->12210 12212->12211 12213 7ff70a1fec70 4 API calls 12212->12213 12215 7ff70a1fd7c6 12213->12215 12224 7ff70a1fd879 12214->12224 12215->12211 12217 7ff70a1fd951 12215->12217 12218 7ff70a1fd80f 12216->12218 12219 7ff70a1fd82e 12216->12219 12221 7ff70a210bd0 4 API calls 12217->12221 12236 7ff70a1fdb20 12218->12236 12222 7ff70a1fd847 ReleaseSRWLockExclusive 12219->12222 12226 7ff70a1fd979 12221->12226 12223 7ff70a1fd8ae 12222->12223 12222->12224 12225 7ff70a1fec70 4 API calls 12223->12225 12224->12200 12228 7ff70a1fd8b9 12225->12228 12226->12200 12227 7ff70a210bd0 4 API calls 12227->12226 12228->12224 12228->12227 12246 7ff70a201e60 12229->12246 12231 7ff70a1fe389 12233 7ff70a1fadc6 12232->12233 12234 7ff70a2108a0 6 API calls 12233->12234 12235 7ff70a1fae99 12234->12235 12238 7ff70a1fdbac 12236->12238 12237 7ff70a1fdbe9 12237->12219 12238->12237 12239 7ff70a1fdc46 12238->12239 12240 7ff70a1fdbe1 12238->12240 12242 7ff70a1fbfe0 2 API calls 12239->12242 12243 7ff70a1fbfe0 AcquireSRWLockExclusive 12240->12243 12242->12237 12245 7ff70a1fc01e 12243->12245 12244 7ff70a1fc092 ReleaseSRWLockExclusive 12244->12237 12245->12244 12247 7ff70a201e67 12246->12247 12248 7ff70a201efe 12247->12248 12255 7ff70a1fd440 12247->12255 12248->12231 12250 7ff70a201f12 12259 7ff70a2109c0 12250->12259 12256 7ff70a1fd4a9 12255->12256 12257 7ff70a2109c0 6 API calls 12256->12257 12258 7ff70a1fd506 12257->12258 12258->12250 12260 7ff70a2108f0 6 API calls 12259->12260 12261 7ff70a2109d5 12260->12261 12262 7ff70a210afc 12261->12262 12264 7ff70a2107d0 6 API calls 12261->12264 12263 7ff70a2107d0 6 API calls 12262->12263 12265 7ff70a210bc6 12263->12265 12264->12261 12266 7ff70a2107d0 6 API calls 12265->12266 12267 7ff70a210c63 12266->12267 13684 7ff70a1f81a7 13685 7ff70a1f7ff2 13684->13685 13688 7ff70a1f7fe7 13684->13688 13686 7ff70a1f8036 13685->13686 13687 7ff70a210240 9 API calls 13685->13687 13687->13686 13689 7ff70a1f81c6 13688->13689 13690 7ff70a1f1c60 74 API calls 13688->13690 13690->13685 12385 7ff70a1f2e00 12386 7ff70a1f5970 7 API calls 12385->12386 12387 7ff70a1f2e18 12386->12387 12388 7ff70a1f2e67 12387->12388 12389 7ff70a1f5680 GetLastError 12387->12389 12390 7ff70a1f2e31 12389->12390 12391 7ff70a1f2e37 12390->12391 12392 7ff70a1f5650 2 API calls 12390->12392 12391->12388 12395 7ff70a1f2820 7 API calls 12391->12395 12393 7ff70a1f2e4c 12392->12393 12393->12391 12394 7ff70a1f2e69 12393->12394 12394->12388 12396 7ff70a1f2820 7 API calls 12394->12396 12395->12388 12396->12388

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 0 7ff70a1f20c0-7ff70a1f20e2 call 7ff70a1f3790 3 7ff70a1f24ce-7ff70a1f24fa call 7ff70a210bd0 0->3 4 7ff70a1f20e8-7ff70a1f2103 call 7ff70a1f9800 call 7ff70a1f3e20 0->4 9 7ff70a1f2593-7ff70a1f25b8 3->9 14 7ff70a1f2105-7ff70a1f210f call 7ff70a1f19c0 4->14 15 7ff70a1f2111-7ff70a1f2119 call 7ff70a1f9830 4->15 12 7ff70a1f25d0-7ff70a1f25db 9->12 13 7ff70a1f25ba-7ff70a1f25cb call 7ff70a1f27f0 9->13 13->12 23 7ff70a1f2128-7ff70a1f212b 14->23 21 7ff70a1f211f-7ff70a1f2123 call 7ff70a1f3e70 15->21 22 7ff70a1f249a 15->22 21->23 26 7ff70a1f249d-7ff70a1f24c9 call 7ff70a210bd0 22->26 23->22 25 7ff70a1f2131-7ff70a1f2143 call 7ff70a1f3e20 23->25 31 7ff70a1f2155-7ff70a1f215d call 7ff70a1f9830 25->31 32 7ff70a1f2145-7ff70a1f2153 call 7ff70a1f1870 25->32 26->9 31->22 38 7ff70a1f2163-7ff70a1f2167 call 7ff70a1f37c0 31->38 37 7ff70a1f216c-7ff70a1f216f 32->37 37->22 39 7ff70a1f2175-7ff70a1f218f call 7ff70a1f3e20 37->39 38->37 43 7ff70a1f21b5-7ff70a1f21c1 call 7ff70a1f9830 39->43 44 7ff70a1f2191-7ff70a1f21aa call 7ff70a1f1b00 39->44 43->22 51 7ff70a1f21c7-7ff70a1f223f call 7ff70a20a760 43->51 49 7ff70a1f22b1-7ff70a1f22bc call 7ff70a1f3e20 44->49 50 7ff70a1f21b0 44->50 56 7ff70a1f22e1-7ff70a1f22ed call 7ff70a1f9830 49->56 57 7ff70a1f22be-7ff70a1f22da call 7ff70a1f9850 49->57 50->22 58 7ff70a1f2245-7ff70a1f224d 51->58 59 7ff70a1f2567-7ff70a1f258e call 7ff70a210bd0 51->59 56->22 70 7ff70a1f22f3-7ff70a1f22ff call 7ff70a1f37b0 56->70 75 7ff70a1f2305-7ff70a1f231a call 7ff70a1f9800 call 7ff70a1f9830 57->75 76 7ff70a1f22dc 57->76 63 7ff70a1f224f-7ff70a1f225c call 7ff70a1f1330 58->63 64 7ff70a1f2260-7ff70a1f2285 SetConsoleTitleW 58->64 59->9 63->64 65 7ff70a1f228b-7ff70a1f2294 64->65 66 7ff70a1f2479-7ff70a1f248f GetLastError 64->66 72 7ff70a1f2296-7ff70a1f22a3 call 7ff70a1f27f0 65->72 73 7ff70a1f22a8-7ff70a1f22ab 65->73 66->72 74 7ff70a1f2495 66->74 70->22 70->75 72->73 73->26 73->49 74->73 75->22 84 7ff70a1f2320-7ff70a1f2328 call 7ff70a1f37a0 75->84 76->26 87 7ff70a1f24ff-7ff70a1f252b call 7ff70a210bd0 84->87 88 7ff70a1f232e-7ff70a1f2371 call 7ff70a1f1470 call 7ff70a20e306 84->88 87->9 95 7ff70a1f2402-7ff70a1f2419 call 7ff70a208d30 88->95 96 7ff70a1f2377-7ff70a1f239b call 7ff70a208e30 88->96 101 7ff70a1f244d-7ff70a1f2454 95->101 102 7ff70a1f23a1-7ff70a1f23bc GetProcAddress 96->102 103 7ff70a1f252d-7ff70a1f2565 call 7ff70a210bd0 96->103 106 7ff70a1f2456-7ff70a1f2463 call 7ff70a1f27f0 101->106 107 7ff70a1f2468-7ff70a1f2478 101->107 104 7ff70a1f23be-7ff70a1f23c3 call 7ff70a20e312 102->104 105 7ff70a1f241b-7ff70a1f2440 call 7ff70a208d30 102->105 103->9 117 7ff70a1f23c8-7ff70a1f23d6 104->117 105->101 114 7ff70a1f2442-7ff70a1f2448 call 7ff70a1f27f0 105->114 106->107 114->101 118 7ff70a1f23e3-7ff70a1f23ea 117->118 119 7ff70a1f23d8-7ff70a1f23de call 7ff70a1f27f0 117->119 121 7ff70a1f23fe-7ff70a1f2400 118->121 122 7ff70a1f23ec-7ff70a1f23f9 call 7ff70a1f27f0 118->122 119->118 121->107 122->121
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressConsoleErrorLastProcTitlememmove
                                                                                                                                                                                                                                    • String ID: C:/explorerwin/dlll.dllFailed to load the DLLmsg_frm_vxsrc\main.rs$Eror$Failed to disable raw mode$Failed to get the functionFailed to enable raw mode$called `Result::unwrap()` on an `Err` value$formatting failedC:\Users\tvry2\.cargo\registry\src\index.crates.io-6f17d22bba15001f\crossterm-0.22.1\src\terminal\sys\windows.rs
                                                                                                                                                                                                                                    • API String ID: 3754616096-3989702896
                                                                                                                                                                                                                                    • Opcode ID: 3b149c93e04b5b4be62672bdf7b3ae807d77bbb44dadbe74c16a43ecdcbe4d5d
                                                                                                                                                                                                                                    • Instruction ID: c6a8b2dbb0f323ca4d07136f6d095d56930ccf4b4aa8c12644adac3c0422077b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3b149c93e04b5b4be62672bdf7b3ae807d77bbb44dadbe74c16a43ecdcbe4d5d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4FE12D63A09A9398FB10AB60EC403E8A7B1EF54388F844575DB4D46B9AEF7CE545C360

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorExceptionGuaranteeHandlerLastStackThreadVectored
                                                                                                                                                                                                                                    • String ID: main
                                                                                                                                                                                                                                    • API String ID: 1207050972-3207122276
                                                                                                                                                                                                                                    • Opcode ID: 405942905872f9236965eab61c32a70971dcf7895ad1a6592bf40fbb413f1437
                                                                                                                                                                                                                                    • Instruction ID: 56d0c1efcc1157f3e320ed312d89709c32e464905bf9fe9505a0e9f01bb5c1c4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 405942905872f9236965eab61c32a70971dcf7895ad1a6592bf40fbb413f1437
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B271F723A05B8299FB10EF60EC403E867B4FF54358F904676EA4D52B98DF38D599D390
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: 9b403a85afd2c4226912a7cf3641345153e784ebcde8f337292e3f0f8d412922
                                                                                                                                                                                                                                    • Instruction ID: 6677fefe291cd8dd7823fc6c4b43c176b95e0d9bbdbb487ef3017d5a2bb4db37
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9b403a85afd2c4226912a7cf3641345153e784ebcde8f337292e3f0f8d412922
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A2D15593D0C6D744FA21AB64ED406B9EAA19F01764FD493B0CBAD132E1CFAD59839320

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: __p___argc__p___argv__scrt_acquire_startup_lock__scrt_release_startup_lock_cexit_exit_get_initial_narrow_environment_register_thread_local_exe_atexit_callback
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1133592946-0
                                                                                                                                                                                                                                    • Opcode ID: 4bfcd4f826f1d5b30b6f579f5633f353bdbbee8d395b9d76a283013a168d495e
                                                                                                                                                                                                                                    • Instruction ID: fb7ac8c92ee10eb2d7b85c961bc80693c9eb100503389329d82715519b945dd3
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4bfcd4f826f1d5b30b6f579f5633f353bdbbee8d395b9d76a283013a168d495e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2312A23E0810782FA50BB20DD11BB9D692AFD4784FC64CB9E65D877D7DF2CA484A231

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ConsoleErrorLastWrite$ByteCharMultiWide
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1956605914-0
                                                                                                                                                                                                                                    • Opcode ID: 09127046161c550510f6cb87b2ef26c9cda4432b1be89e080cae4719e8f3a3e1
                                                                                                                                                                                                                                    • Instruction ID: 2abe7822b2c09c305faf9759aefcab2ed84609915126b01afbda101180ee957e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 09127046161c550510f6cb87b2ef26c9cda4432b1be89e080cae4719e8f3a3e1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 13518F63A0969342F720AB21FC443BAE261FF94780FA44175DA8D46BE4DFBCD586D720

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CreateErrorFileLast
                                                                                                                                                                                                                                    • String ID: CONIN$$CONOUT$
                                                                                                                                                                                                                                    • API String ID: 1214770103-123850019
                                                                                                                                                                                                                                    • Opcode ID: 1f63f8c906e9d56153ab9f5a36c46af045d4bec27cc01f25c88d486c3e23e1be
                                                                                                                                                                                                                                    • Instruction ID: 93be25a6a059684b59a2f4c67eee820f00f87f86e4604c2ac8230942cb557aab
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1f63f8c906e9d56153ab9f5a36c46af045d4bec27cc01f25c88d486c3e23e1be
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C631AFA3B04A5285F710AB61EC443A9AA71BF907E8F548274DEAD177C9DF3DD4418350

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • AcquireSRWLockExclusive.KERNEL32(?,?,?,?,?,?,00007FF70A1F9843,?,?,?,?,00007FF70A1F2116), ref: 00007FF70A1F98BF
                                                                                                                                                                                                                                    • ReleaseSRWLockExclusive.KERNEL32(?,?,?,?,?,?,00007FF70A1F9843,?,?,?,?,00007FF70A1F2116), ref: 00007FF70A1F991E
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs, xrefs: 00007FF70A1F993C
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExclusiveLock$AcquireRelease
                                                                                                                                                                                                                                    • String ID: lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs
                                                                                                                                                                                                                                    • API String ID: 17069307-2303981482
                                                                                                                                                                                                                                    • Opcode ID: 62e0db353255cd8033a184ea59d69d73c3e41d5912c7c8ea873316efdfa9a18f
                                                                                                                                                                                                                                    • Instruction ID: 5381d4a82c385318deeade62850ed855566c6c914a9ac8ebcc218f269c35fb91
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 62e0db353255cd8033a184ea59d69d73c3e41d5912c7c8ea873316efdfa9a18f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 24316F37A04A8696EA50EB15EC843A8B370FF94B64F904671CB6E437E4DF38E196C310

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 291 7ff70a20f0c0-7ff70a20f111 292 7ff70a20f117-7ff70a20f119 291->292 293 7ff70a20f43a-7ff70a20f44d 291->293 294 7ff70a20f11b 292->294 295 7ff70a20f194-7ff70a20f198 292->295 298 7ff70a20f144-7ff70a20f148 294->298 296 7ff70a20f49a-7ff70a20f4e0 call 7ff70a20f7a0 295->296 297 7ff70a20f19e-7ff70a20f1a2 295->297 314 7ff70a20f4f7-7ff70a20f508 296->314 315 7ff70a20f4e2-7ff70a20f4ec 296->315 302 7ff70a20f170-7ff70a20f183 297->302 303 7ff70a20f1a4-7ff70a20f1a8 297->303 299 7ff70a20f14a-7ff70a20f14e 298->299 300 7ff70a20f120-7ff70a20f133 298->300 304 7ff70a20f150-7ff70a20f153 299->304 305 7ff70a20f1c4-7ff70a20f1db call 7ff70a1f53d0 299->305 310 7ff70a20f139-7ff70a20f13e 300->310 311 7ff70a20f44e-7ff70a20f455 300->311 307 7ff70a20f457 302->307 308 7ff70a20f189-7ff70a20f18e 302->308 303->305 309 7ff70a20f1aa-7ff70a20f1ad 303->309 312 7ff70a20f159-7ff70a20f168 304->312 313 7ff70a20f2ef-7ff70a20f2f5 304->313 329 7ff70a20f1dd-7ff70a20f1ed call 7ff70a1f45d0 305->329 330 7ff70a20f220-7ff70a20f226 305->330 316 7ff70a20f45a-7ff70a20f471 call 7ff70a1f37d0 307->316 308->293 308->295 309->313 317 7ff70a20f1b3-7ff70a20f1c2 309->317 310->293 310->298 311->316 312->310 319 7ff70a20f16a 312->319 320 7ff70a20f2f7-7ff70a20f304 313->320 321 7ff70a20f368-7ff70a20f373 Sleep 313->321 315->314 322 7ff70a20f4ee-7ff70a20f4f2 call 7ff70a1f4060 315->322 328 7ff70a20f473-7ff70a20f479 316->328 317->305 317->308 319->305 325 7ff70a20f325-7ff70a20f328 320->325 326 7ff70a20f306-7ff70a20f30b 320->326 324 7ff70a20f426-7ff70a20f434 321->324 322->314 324->292 324->293 325->324 334 7ff70a20f32e 325->334 333 7ff70a20f310-7ff70a20f323 326->333 328->293 335 7ff70a20f47b-7ff70a20f487 call 7ff70a1f4060 328->335 329->330 343 7ff70a20f1ef-7ff70a20f21c call 7ff70a1f50f0 329->343 331 7ff70a20f228-7ff70a20f22d call 7ff70a20f7c0 330->331 332 7ff70a20f230-7ff70a20f245 330->332 331->332 339 7ff70a20f489-7ff70a20f498 call 7ff70a210940 332->339 340 7ff70a20f24b-7ff70a20f263 332->340 333->325 333->333 341 7ff70a20f330-7ff70a20f334 334->341 335->293 339->296 346 7ff70a20f26d-7ff70a20f273 340->346 347 7ff70a20f265-7ff70a20f268 call 7ff70a20f820 340->347 341->341 348 7ff70a20f336 341->348 343->330 353 7ff70a20f2a0-7ff70a20f2a9 346->353 354 7ff70a20f275-7ff70a20f286 346->354 347->346 348->324 356 7ff70a20f33b-7ff70a20f34c 353->356 357 7ff70a20f2af-7ff70a20f2db 353->357 354->330 358 7ff70a20f288-7ff70a20f28b 354->358 361 7ff70a20f410-7ff70a20f415 356->361 362 7ff70a20f352-7ff70a20f355 356->362 359 7ff70a20f378-7ff70a20f37c 357->359 360 7ff70a20f2e1-7ff70a20f2ea 357->360 358->330 363 7ff70a20f28d-7ff70a20f295 call 7ff70a20f9d0 358->363 367 7ff70a20f380-7ff70a20f399 359->367 360->367 365 7ff70a20f417-7ff70a20f41b call 7ff70a1f53c0 361->365 366 7ff70a20f420-7ff70a20f422 361->366 362->361 368 7ff70a20f35b-7ff70a20f363 call 7ff70a20f9d0 362->368 363->330 365->366 366->324 372 7ff70a20f3a8-7ff70a20f3b4 367->372 373 7ff70a20f39b-7ff70a20f39e 367->373 368->361 376 7ff70a20f3c8-7ff70a20f3cf 372->376 377 7ff70a20f3b6-7ff70a20f3c6 372->377 373->372 375 7ff70a20f3a0-7ff70a20f3a3 call 7ff70a20f9d0 373->375 375->372 376->361 379 7ff70a20f3d1-7ff70a20f3d5 376->379 377->361 381 7ff70a20f3e0-7ff70a20f404 379->381 383 7ff70a20f406 381->383 383->361
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • Once instance has previously been poisonedC:\Users\tvry2\.cargo\registry\src\index.crates.io-6f17d22bba15001f\parking_lot-0.11.2\src\once.rs, xrefs: 00007FF70A20F49A
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID: Once instance has previously been poisonedC:\Users\tvry2\.cargo\registry\src\index.crates.io-6f17d22bba15001f\parking_lot-0.11.2\src\once.rs
                                                                                                                                                                                                                                    • API String ID: 0-2860405084
                                                                                                                                                                                                                                    • Opcode ID: 02525fbfb081665eb7c63c900c2e02d951f0ae77a26171a19918550c01d8e5c7
                                                                                                                                                                                                                                    • Instruction ID: 44c879569a59fbed86b4eae3192180dd3ea8e790ac514bbaedbfb8115c9ace8b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 02525fbfb081665eb7c63c900c2e02d951f0ae77a26171a19918550c01d8e5c7
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C4C12723A4869345FB75AB29DE04BBDA760AF91768F844275DE5D837C2CF3C9481D310

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 385 7ff70a1f2c80-7ff70a1f2c98 386 7ff70a1f2cb3-7ff70a1f2cb6 385->386 387 7ff70a1f2c9a-7ff70a1f2c9d 385->387 388 7ff70a1f2cc9-7ff70a1f2cd6 386->388 389 7ff70a1f2cb8-7ff70a209202 386->389 387->389 390 7ff70a1f2c9f-7ff70a1f2ca2 387->390 392 7ff70a1f2cf8 388->392 393 7ff70a1f2cd8 388->393 397 7ff70a209208-7ff70a209214 389->397 398 7ff70a2092d0-7ff70a2092d5 389->398 390->389 394 7ff70a1f2ca4-7ff70a1f2cb1 390->394 399 7ff70a1f2cfe 392->399 395 7ff70a1f2d23 call 7ff70a208cc0 393->395 396 7ff70a1f2cda-7ff70a1f2cf1 call 7ff70a1f27e0 393->396 394->399 410 7ff70a1f2d28-7ff70a1f2d5e call 7ff70a2106e0 call 7ff70a1f5970 395->410 396->410 411 7ff70a1f2cf3-7ff70a1f2cf6 396->411 401 7ff70a20921d-7ff70a20922a 397->401 402 7ff70a209216-7ff70a20921b 397->402 403 7ff70a2092d7-7ff70a2092fc call 7ff70a20a760 398->403 404 7ff70a1f2d00-7ff70a1f2d22 memmove 399->404 408 7ff70a209230-7ff70a20924a 401->408 407 7ff70a20924c-7ff70a20924f 402->407 417 7ff70a209319-7ff70a209341 call 7ff70a210bd0 403->417 418 7ff70a2092fe-7ff70a209318 403->418 412 7ff70a20927d-7ff70a209282 407->412 413 7ff70a209251-7ff70a209264 407->413 408->407 408->408 431 7ff70a1f2d60-7ff70a1f2d75 call 7ff70a1f5680 410->431 432 7ff70a1f2dbe-7ff70a1f2dc7 410->432 411->404 419 7ff70a20929f-7ff70a2092a2 412->419 420 7ff70a209284-7ff70a209296 412->420 416 7ff70a209270-7ff70a20927b 413->416 416->412 416->416 429 7ff70a209343-7ff70a209368 call 7ff70a208cc0 417->429 419->398 422 7ff70a2092a4 419->422 420->398 424 7ff70a209298-7ff70a20929a 420->424 428 7ff70a2092aa-7ff70a2092c1 call 7ff70a1f27e0 422->428 422->429 424->398 426 7ff70a20929c 424->426 426->419 428->403 441 7ff70a2092c3-7ff70a2092cb call 7ff70a2106e0 428->441 439 7ff70a209379-7ff70a209382 429->439 440 7ff70a20936a-7ff70a209374 call 7ff70a1f27f0 429->440 442 7ff70a1f2d7d-7ff70a1f2d92 call 7ff70a1f5650 431->442 443 7ff70a1f2d77-7ff70a1f2d7b 431->443 440->439 441->398 446 7ff70a1f2d94-7ff70a1f2d9c 442->446 450 7ff70a1f2da9-7ff70a1f2db1 442->450 443->446 446->432 449 7ff70a1f2d9e-7ff70a1f2da7 call 7ff70a1f2820 446->449 449->432 453 7ff70a1f2db3-7ff70a1f2db7 call 7ff70a1f2820 450->453 454 7ff70a1f2dbc 450->454 453->454 454->432
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ConsoleModememmove
                                                                                                                                                                                                                                    • String ID: terminal height too large
                                                                                                                                                                                                                                    • API String ID: 3411022649-3818694659
                                                                                                                                                                                                                                    • Opcode ID: 72ef7ab2f0bcf2de99dff6341b9cfc5dddaa630a0e3caded684df3287ca15fae
                                                                                                                                                                                                                                    • Instruction ID: 406298e2491fa2f338251c81578709ded812de372a540f2ed5a63a39ef43752a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 72ef7ab2f0bcf2de99dff6341b9cfc5dddaa630a0e3caded684df3287ca15fae
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 31315E23B0AA8794FA15AB51EC402F9A670AF807A4FC845B1DF1D177D5DF3CE9829360

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorLast
                                                                                                                                                                                                                                    • String ID: CONIN$
                                                                                                                                                                                                                                    • API String ID: 1452528299-3033795042
                                                                                                                                                                                                                                    • Opcode ID: 0894aa7f505329a50284996d685e1f80f717496d8de01236da355e4487b99869
                                                                                                                                                                                                                                    • Instruction ID: f7be41e5d65da4db30fc0fc7a849897f80fd71a62308702ac89fcd70bd4a5a5e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0894aa7f505329a50284996d685e1f80f717496d8de01236da355e4487b99869
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0831BFA3B04A5289F710AB60EC443ADAA71BF907E8F588275DEAD177D9DF3CD4418360

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ConsoleHandleMode
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 674689721-0
                                                                                                                                                                                                                                    • Opcode ID: ebad50c678170898e497b43013c68cc8122b5e6ba60b4cee5fd0baedec156261
                                                                                                                                                                                                                                    • Instruction ID: 41bc1f46b2ad17d45568cb52e6e90397104c6abb22151bf6f8462220e0aa15df
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ebad50c678170898e497b43013c68cc8122b5e6ba60b4cee5fd0baedec156261
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C4217E22A1869244F7219F21FC007A9A260BF55BE8F888771EEAD167C9DF7CD1858210

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Thread$CurrentDescription
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 654298328-0
                                                                                                                                                                                                                                    • Opcode ID: cd4c7614ee3f466afec2fc647a0def00ed07121c7eea72c3c73090b04b3b72f9
                                                                                                                                                                                                                                    • Instruction ID: 8f6cbc57ffffe5401cf744516424dc44b2fc493b64988afdce6ffc587a758dd2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cd4c7614ee3f466afec2fc647a0def00ed07121c7eea72c3c73090b04b3b72f9
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 14017C53A0C59681FA20B715EC047AAD760AF91BC0F904072EF4E17BAADF2CD9878710

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ConsoleErrorLastMode
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 953036326-0
                                                                                                                                                                                                                                    • Opcode ID: 035bbab39b92b20db9259c22745c4a79d7d32dc1c9092f7161190f48f6388dfc
                                                                                                                                                                                                                                    • Instruction ID: a5fce4654e570527ad571e284ded17f656788f201973dc8cb78e439f7a8afba5
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 035bbab39b92b20db9259c22745c4a79d7d32dc1c9092f7161190f48f6388dfc
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 14D0C946F1568782FA247732DDC347955616FD8B90FD508B0CA1C863A2DE4CD1928720

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                      • Part of subcall function 00007FF70A1FF850: GetStdHandle.KERNEL32 ref: 00007FF70A1FF87F
                                                                                                                                                                                                                                    • memmove.VCRUNTIME140(?,?,?,?,?,00000008,?,?,00000001,00000000,00000000,?,00007FF70A210069), ref: 00007FF70A1F9198
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Handlememmove
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3195996460-0
                                                                                                                                                                                                                                    • Opcode ID: d544c62e02487680cb71c09916bd8d33c4f1da0854814b789fc115ba2b24e8d9
                                                                                                                                                                                                                                    • Instruction ID: 53a26f1aafa3c038b29b236f3b29df69eb1cf0ef1d8eddf3d6c228aaccb3b2db
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d544c62e02487680cb71c09916bd8d33c4f1da0854814b789fc115ba2b24e8d9
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1A51BC23B08A9695FF11ABA6EC043ADA770BF44BA8F944972DF1C13794CF38D582C210

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                      • Part of subcall function 00007FF70A1FF850: GetStdHandle.KERNEL32 ref: 00007FF70A1FF87F
                                                                                                                                                                                                                                    • memmove.VCRUNTIME140(?,?,?,?,?,00000008,?,?,00000001,00000000,00000000,?,00007FF70A210069), ref: 00007FF70A1F9198
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Handlememmove
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3195996460-0
                                                                                                                                                                                                                                    • Opcode ID: cad9aacfb76018c21340043912fae4174b6f714129e74344781726dc6002d3b7
                                                                                                                                                                                                                                    • Instruction ID: 95b482d5c1ef114f82d8e27fdb1daace4f1dd4019f4b8b203177b8e39d4e72b1
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cad9aacfb76018c21340043912fae4174b6f714129e74344781726dc6002d3b7
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FA315E67B0969784FE54ABA5EC443BC96B0AF45BA4F9408B2CE1D53784CF39D582C260
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CloseHandle
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2962429428-0
                                                                                                                                                                                                                                    • Opcode ID: e2c2bc7cb35c9af2e53e7ff030cbd82fd4005f51000c1ed04c4c34b846227771
                                                                                                                                                                                                                                    • Instruction ID: 586d654fe00137118d561c5d341101068a795659cf6b6fe8cdfaa237058a295b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e2c2bc7cb35c9af2e53e7ff030cbd82fd4005f51000c1ed04c4c34b846227771
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8CC01213E091C345F6147325CD8627585D00F94754FE944B0CB5C801D3FF0CA4878220
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorLast
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1452528299-0
                                                                                                                                                                                                                                    • Opcode ID: 1c50ff93bab32b48d138f3ab585250b189ba956e9ec0816c8657021a3c10ec76
                                                                                                                                                                                                                                    • Instruction ID: b5d9a9cdeb3b7c04244077167761014e278da4a10d49ea70c449d6f033b0d849
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1c50ff93bab32b48d138f3ab585250b189ba956e9ec0816c8657021a3c10ec76
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 89F0A073A086428AF720AF35F84026AE6A0EB88754F408470DBAC87755DE3CD0428B20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc$CurrentProcessmemset
                                                                                                                                                                                                                                    • String ID: ($($SymAddrIncludeInlineTrace$SymFromAddrW$SymFromInlineContextW$SymGetLineFromAddrW64$SymGetLineFromInlineContextW$SymQueryInlineTrace$X$X$called `Option::unwrap()` on a `None` value
                                                                                                                                                                                                                                    • API String ID: 3017635649-1221209987
                                                                                                                                                                                                                                    • Opcode ID: 61a1acb00d64a930bcbfdf2a79e11053413d616e6fe31a03461a56cd56b84ee4
                                                                                                                                                                                                                                    • Instruction ID: 75dd0561d7082b2836ebf53fc474f59e5b785a9d0b0ef3c84e6600920df00efc
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 61a1acb00d64a930bcbfdf2a79e11053413d616e6fe31a03461a56cd56b84ee4
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2742BC32A08A8281F775AB14E8417FAA3A0FFD4794F804276EA8D43795DF3DD195E710
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 313767242-0
                                                                                                                                                                                                                                    • Opcode ID: dd625d9e0baddbeb425b95cb224be2badd33eebc1e99e7ced5728f5ee0c90512
                                                                                                                                                                                                                                    • Instruction ID: 51fc20ecf1afaa5d4c8a56fabfa09d467950dde2353ea541a7de294e87af5c65
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dd625d9e0baddbeb425b95cb224be2badd33eebc1e99e7ced5728f5ee0c90512
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3D312C73609A828AEB609F60EC807A9A361FB94744F84447ADB4E47B95DF38D648D720
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • assertion failed: self.is_char_boundary(new_len)/rustc/07dca489ac2d933c78d3c5158e3f43beefeb02ce\library\alloc\src\string.rs, xrefs: 00007FF70A1FF305
                                                                                                                                                                                                                                    • NTDLL.DLL, xrefs: 00007FF70A1FEFC8
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorFormatHandleLastMessageModule
                                                                                                                                                                                                                                    • String ID: NTDLL.DLL$assertion failed: self.is_char_boundary(new_len)/rustc/07dca489ac2d933c78d3c5158e3f43beefeb02ce\library\alloc\src\string.rs
                                                                                                                                                                                                                                    • API String ID: 1273946083-3119671636
                                                                                                                                                                                                                                    • Opcode ID: b74149200ed637b8583a8f3536fcd973dc2c5cea83d907ba4370d444886d6584
                                                                                                                                                                                                                                    • Instruction ID: 23ad15e3a4f3e36cb5100b40592faf4dc28fe11013675a86fb39f405ad6d5e0d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b74149200ed637b8583a8f3536fcd973dc2c5cea83d907ba4370d444886d6584
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F1A18F37A09AC384F7319F20EC407F8A6A4BF54394F844176DB8D46B99DFB89686D320
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                    • String ID: S-xY+
                                                                                                                                                                                                                                    • API String ID: 2933794660-4286001931
                                                                                                                                                                                                                                    • Opcode ID: 1c674261f95af35137c0f1ca85089f891f8ef36ecd383aaa4e2be460bbdae211
                                                                                                                                                                                                                                    • Instruction ID: fd77ce2c182c78095eff2a6c224e98c6d067fd22e2a02f0ead8093f30ab856ff
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1c674261f95af35137c0f1ca85089f891f8ef36ecd383aaa4e2be460bbdae211
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F4117023B14F068AFB00EF60EC442B873A4FBA9758F840E35DA2D427A4DF38D1648350
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: memcmp
                                                                                                                                                                                                                                    • String ID: .llvm./rust/deps\rustc-demangle-0.1.23\src\lib.rs$/rustc/07dca489ac2d933c78d3c5158e3f43beefeb02ce\library\core\src\ops\function.rs$__ZN$`fmt::Error`s should be impossible without a `fmt::Formatter`
                                                                                                                                                                                                                                    • API String ID: 1475443563-663877426
                                                                                                                                                                                                                                    • Opcode ID: 4aa915c65d3c2ad737fc421a2e6002c39491f0e58d83e3cefdd605b09b38af9d
                                                                                                                                                                                                                                    • Instruction ID: 3ed1cca1d92f0080c3d82b235e65484e0a94d7444739541a3a61181762d16e3e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4aa915c65d3c2ad737fc421a2e6002c39491f0e58d83e3cefdd605b09b38af9d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1E425863A1CA9345F624AB10DC14B7BFA51AFD1390FC041B5EA9E866D6DF3CE544E320
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Heap$AllocFreeProcessmemmove
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 4130131589-0
                                                                                                                                                                                                                                    • Opcode ID: cec0438abd020cd9fa3204855f3a7a281a12acdeb25e2158f36c98e9ab84d836
                                                                                                                                                                                                                                    • Instruction ID: 76f2482ec0f6b9b0fa1d47642ec6879739a91efa8d112717ff8e17a29d82a288
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cec0438abd020cd9fa3204855f3a7a281a12acdeb25e2158f36c98e9ab84d836
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2611BF53B09A6281FA45EB53FE401B996A07FD8BE4F844579CE0D07B90DF3CE096A220
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorFileObjectSingleStatusWaitWrite
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3447438843-0
                                                                                                                                                                                                                                    • Opcode ID: ffa6063df7375342406303dd796d4addb2f889c954536023572025f68809e265
                                                                                                                                                                                                                                    • Instruction ID: 78d0d95c2ee57f0ae166cd4fa2f111b6dfa1495774694f5df08baafae49f2aac
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ffa6063df7375342406303dd796d4addb2f889c954536023572025f68809e265
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 33313032608BC286FB609B24F85036AB3A5FB94390F508175E7DD42BA8DF7CD0958B10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: memset
                                                                                                                                                                                                                                    • String ID: punycode{-}0
                                                                                                                                                                                                                                    • API String ID: 2221118986-2450133883
                                                                                                                                                                                                                                    • Opcode ID: 3820d85125742d04edec5c1d409bdd7bae7445f8114ad03835b5546a94f7390b
                                                                                                                                                                                                                                    • Instruction ID: 7893a8ced76600be1567c908d54026e9866d2baab7f38aa2d2f9a9504f581fe1
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3820d85125742d04edec5c1d409bdd7bae7445f8114ad03835b5546a94f7390b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D1E14423B2C64642FA24AB15E804B79E792BFD4784F90C171DE8D83B96DF3CE445A710
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID: called `Option::unwrap()` on a `None` value$called `Result::unwrap()` on an `Err` value
                                                                                                                                                                                                                                    • API String ID: 0-1380848348
                                                                                                                                                                                                                                    • Opcode ID: a1adb64df26f53a0e55c6fd3bcb65282a9b72b5f4552fa958830c94ffd8b9b7e
                                                                                                                                                                                                                                    • Instruction ID: 69b0def79c11e9002883dd1cc07c9cb734dce8eefa63f5255132a3d5fbcf000d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a1adb64df26f53a0e55c6fd3bcb65282a9b72b5f4552fa958830c94ffd8b9b7e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BA524463A1C68345FA28EA11DC44BB9EA41AFD1794FC441B1E99D8EBD6DF3CE540B320
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Handle
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2519475695-0
                                                                                                                                                                                                                                    • Opcode ID: a91f84c42ab6c17370d41cea3297ac65645c5e68805f61de64402418a843a8ca
                                                                                                                                                                                                                                    • Instruction ID: bee5ccc19a8b5709486e7046225b41f24d22abefd04068c83e84716e5979afcf
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a91f84c42ab6c17370d41cea3297ac65645c5e68805f61de64402418a843a8ca
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 79E1CB63B0968786FA10AB11FC006B9A6A1BF947D4FC48575EF1E17B94EF3CE5858310
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: memcmp
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1475443563-0
                                                                                                                                                                                                                                    • Opcode ID: ff196aaac4cff9e3173013c87393cfbbe9923ad13537a15d2e303e2fa8640124
                                                                                                                                                                                                                                    • Instruction ID: d637c3e2a4c792b704b7d71b4fc49f0d215e3ace820bf34262782d533a28dc13
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ff196aaac4cff9e3173013c87393cfbbe9923ad13537a15d2e303e2fa8640124
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B8C136A3B1C2A642FA15DA21DD14FBAA655BF91B90FC09770DD4E83BC2CF3CA551A310
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: c881ad21e0d52928b06e6f00d2f89b8f37bc29ac339c38f04fac11ef75b55792
                                                                                                                                                                                                                                    • Instruction ID: 59bda57e5ffdfc06eacc1c1feb232e55364322498790c82d2c6f9f355c4ff87e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c881ad21e0d52928b06e6f00d2f89b8f37bc29ac339c38f04fac11ef75b55792
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2CB16CD7E29B9701F62353399801BB599005FB37E4E81D332FC79B1FD2EB29A6426214
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: a7fd1d6896e719c6e30ccdd63c5bb3c82fd20cc95ac1f030efa560407070207d
                                                                                                                                                                                                                                    • Instruction ID: 8ee4fc1a29aaf1d7a0f63fb70284d271fa300f73c9fa63e9ac4c939569c3e6ca
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a7fd1d6896e719c6e30ccdd63c5bb3c82fd20cc95ac1f030efa560407070207d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9EA12263E186E395F7249B15EC007B9A6B1BF003B0F858376CF7D17AC4DB79A4919260
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: 73d2a96d7f9e1210754fe3962792ae8495b79b3367959676d3026bdc54c19451
                                                                                                                                                                                                                                    • Instruction ID: 3de88132acfc43654b19c08c5fcbf650bfed582bac118054b214cfd374ace493
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 73d2a96d7f9e1210754fe3962792ae8495b79b3367959676d3026bdc54c19451
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9A0012290884394F608AB00EC50420AA21BFA1340FC105B5C14E815A1DF3CA490E220
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • WaitForSingleObjectEx.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A200EA8
                                                                                                                                                                                                                                    • LoadLibraryA.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A200EC1
                                                                                                                                                                                                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A200EFA
                                                                                                                                                                                                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A200F32
                                                                                                                                                                                                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A200F6B
                                                                                                                                                                                                                                    • GetCurrentProcess.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A200F84
                                                                                                                                                                                                                                    • GetProcAddress.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A200FC2
                                                                                                                                                                                                                                    • GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A20101C
                                                                                                                                                                                                                                    • CreateMutexA.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A2010AE
                                                                                                                                                                                                                                    • CloseHandle.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A2010D3
                                                                                                                                                                                                                                    • ReleaseMutex.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,-31450000,?,?,?), ref: 00007FF70A201119
                                                                                                                                                                                                                                    • ReleaseMutex.KERNEL32(?,?,?,?,?,?), ref: 00007FF70A2011CE
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc$Mutex$CurrentProcessRelease$CloseCreateHandleLibraryLoadObjectSingleWait
                                                                                                                                                                                                                                    • String ID: SymAddrIncludeInlineTrace$SymGetOptions$SymInitializeW$SymSetOptions$called `Option::unwrap()` on a `None` value$dbghelp.dll
                                                                                                                                                                                                                                    • API String ID: 2119853198-1387109118
                                                                                                                                                                                                                                    • Opcode ID: 0b1f8d8ce87c35bdaeee9882bbe848f2a6532ab2d5e1baf9b551e4f073c74891
                                                                                                                                                                                                                                    • Instruction ID: 473381b21dba21a5f9c9cbad38c26f51bb86e36ab8c3ceb317e9221b19a775c1
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0b1f8d8ce87c35bdaeee9882bbe848f2a6532ab2d5e1baf9b551e4f073c74891
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 64A1BC23A08A9395FB51AB21EC007B8E3A1BFE4764F844275DD6C427A5DF3CE595E320
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc$Handle$CloseModule
                                                                                                                                                                                                                                    • String ID: NtCreateKeyedEvent$NtReleaseKeyedEvent$NtWaitForKeyedEvent$WaitOnAddress$WakeByAddressSingle$[$api-ms-win-core-synch-l1-2-0.dll$ntdll.dll$parking_lot requires either NT Keyed Events (WinXP+) or WaitOnAddress/WakeByAddress (Win8+)C:\Users\tvry2\.cargo\registry\src\index.crates.io-6f17d22bba15001f\parking_lot_core-0.8.6\src\thread_parker\windows\mod.rs
                                                                                                                                                                                                                                    • API String ID: 3447048809-101732387
                                                                                                                                                                                                                                    • Opcode ID: ace5f1c10dd923d1dbe5815690fd4ef1dade1221ca97c0d10a4e8100568a7b87
                                                                                                                                                                                                                                    • Instruction ID: fed9a7e7d601ca0f5eb014abb81d942a5ff30105b3573ab9e8f237b99320cc31
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ace5f1c10dd923d1dbe5815690fd4ef1dade1221ca97c0d10a4e8100568a7b87
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 49518B23A0964384FA25BB11ED517B9A6A0AFC4B94FC846B5DE4C437C6EF3CE541A320
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc$Handle$CloseModule
                                                                                                                                                                                                                                    • String ID: NtCreateKeyedEvent$NtReleaseKeyedEvent$NtWaitForKeyedEvent$WaitOnAddress$WakeByAddressSingle$api-ms-win-core-synch-l1-2-0.dll$ntdll.dll
                                                                                                                                                                                                                                    • API String ID: 3447048809-3409541999
                                                                                                                                                                                                                                    • Opcode ID: 2e4f306c9cea7875f5b3556a97b92ee4e2dc5990b253e9a61eab69044eaca1b3
                                                                                                                                                                                                                                    • Instruction ID: 13e4384d30b73e42b97f1fd17e42b461c28b04ee4c366ec102a65b1e46a15fd6
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2e4f306c9cea7875f5b3556a97b92ee4e2dc5990b253e9a61eab69044eaca1b3
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C8418F23F0A64384FA15BB11DD51BB8A6A0AFC4B94FC945B5DE4C477C6EF3CA541A320
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • internal error: entered unreachable code/rustc/07dca489ac2d933c78d3c5158e3f43beefeb02ce\library\alloc\src\vec\mod.rs, xrefs: 00007FF70A1F8EF6
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorLast$EnvironmentVariable
                                                                                                                                                                                                                                    • String ID: internal error: entered unreachable code/rustc/07dca489ac2d933c78d3c5158e3f43beefeb02ce\library\alloc\src\vec\mod.rs
                                                                                                                                                                                                                                    • API String ID: 2691138088-174366258
                                                                                                                                                                                                                                    • Opcode ID: a6693d7f5027077a036fa27862ed097cfca9cacfe7af2c7837d501948d3a446a
                                                                                                                                                                                                                                    • Instruction ID: 05de6bb449c995750f7dbcdb24cf905d9a3c13ff967b55344799c2a85214aaef
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a6693d7f5027077a036fa27862ed097cfca9cacfe7af2c7837d501948d3a446a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2F819063A04AC349FB71AF25EC047E9A3A4BF54BA8F844175DF5C5BB89DF3892858310
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • internal error: entered unreachable code/rustc/07dca489ac2d933c78d3c5158e3f43beefeb02ce\library\alloc\src\vec\mod.rs, xrefs: 00007FF70A1F8A85
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorLast$CurrentDirectory
                                                                                                                                                                                                                                    • String ID: internal error: entered unreachable code/rustc/07dca489ac2d933c78d3c5158e3f43beefeb02ce\library\alloc\src\vec\mod.rs
                                                                                                                                                                                                                                    • API String ID: 3993060814-174366258
                                                                                                                                                                                                                                    • Opcode ID: cdcff8424319c4154c2c49b0531964fe902eb4c56101b5381b39c628b3b6f039
                                                                                                                                                                                                                                    • Instruction ID: 5f641b653a56ed82cdb519fe7251d17651ab36a7e36fb8fc1f305be4bf945554
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cdcff8424319c4154c2c49b0531964fe902eb4c56101b5381b39c628b3b6f039
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5E51C063A08BC38AFB31AF25EC447E9A264BF54BA4F844276DE5C167C5DF3C92858310
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc$HandleModule
                                                                                                                                                                                                                                    • String ID: WaitOnAddress$WakeByAddressSingle$api-ms-win-core-synch-l1-2-0
                                                                                                                                                                                                                                    • API String ID: 667068680-1826242509
                                                                                                                                                                                                                                    • Opcode ID: 9ba4b75a1153e1c331af10ca1146ca35bb028510302cc6c198bff697fb1f5540
                                                                                                                                                                                                                                    • Instruction ID: 5c97d440c7773aa921225de3b0cfdd6b8df079dc8a8d279335f028d6d5d14f6d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9ba4b75a1153e1c331af10ca1146ca35bb028510302cc6c198bff697fb1f5540
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9DF05E12F4A68381FD15BB11FD04270A2A06FA4BC0FC445B8CA0D02BA4EF3CA455E360
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs, xrefs: 00007FF70A1FBCE0
                                                                                                                                                                                                                                    • called `Option::unwrap()` on a `None` value, xrefs: 00007FF70A1FBE30
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExclusiveLock$Release$Acquire
                                                                                                                                                                                                                                    • String ID: called `Option::unwrap()` on a `None` value$lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs
                                                                                                                                                                                                                                    • API String ID: 1021914862-2043005836
                                                                                                                                                                                                                                    • Opcode ID: 9595cb5a5db0dc47279560c00dbf44eab28760c41e3ac2c498e079ffd4df2fc9
                                                                                                                                                                                                                                    • Instruction ID: 773736424f1d2c3c7faddb20c4700b70db9dc5f786a52bd5262e75573584847b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9595cb5a5db0dc47279560c00dbf44eab28760c41e3ac2c498e079ffd4df2fc9
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F3511923E0CA87D9FB51EB24EC443B8A770AFA0718FC441B1CA5D063A5DF3CA585A360
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExclusiveLock$AcquireRelease
                                                                                                                                                                                                                                    • String ID: Box<dyn Any><unnamed>$cannot access a Thread Local Storage value during or after destructionlibrary\std\src\thread\local.rs
                                                                                                                                                                                                                                    • API String ID: 17069307-3513654867
                                                                                                                                                                                                                                    • Opcode ID: d9192a86db9543878fe2dd651032c6da6a8d280460f87fe32fc74bcff1157dca
                                                                                                                                                                                                                                    • Instruction ID: 70b4a4e9ac5a6d2e8a5ecd312a7018a3ef7717af7aad7bd3f75c17ccee836392
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d9192a86db9543878fe2dd651032c6da6a8d280460f87fe32fc74bcff1157dca
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 98B14823A09A8399FB51EB24EC403B8A7B1FF54798F8441B6DA4D07B94DF2CE555C360
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • AcquireSRWLockExclusive.KERNEL32(?,?,?,?,?,?,00007FF70A1F9863,?,?,?,?,00007FF70A1F1140), ref: 00007FF70A1F9A13
                                                                                                                                                                                                                                    • ReleaseSRWLockExclusive.KERNEL32(?,?,?,?,?,?,00007FF70A1F9863,?,?,?,?,00007FF70A1F1140), ref: 00007FF70A1F9A69
                                                                                                                                                                                                                                    • ReleaseSRWLockExclusive.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF70A1F9863), ref: 00007FF70A1F9AC6
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs, xrefs: 00007FF70A1F9A7B
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExclusiveLock$Release$Acquire
                                                                                                                                                                                                                                    • String ID: lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs
                                                                                                                                                                                                                                    • API String ID: 1021914862-2303981482
                                                                                                                                                                                                                                    • Opcode ID: 6081aad2e451656410f17a744fc61ff40310a5494c39ee67465cb2417b963bab
                                                                                                                                                                                                                                    • Instruction ID: a259d049c6ddcce86e4666e5c6543e0dc14e77e31813489cbd546ed79e63da53
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6081aad2e451656410f17a744fc61ff40310a5494c39ee67465cb2417b963bab
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EA317E33A04A8699EB40EF15EC407A87730FB98BA8F984571CE0E437A4DF38D496C720
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressHandleModuleProc
                                                                                                                                                                                                                                    • String ID: NtReleaseKeyedEvent$ntdll
                                                                                                                                                                                                                                    • API String ID: 1646373207-31681898
                                                                                                                                                                                                                                    • Opcode ID: e699d6ba1381e6e702e0febc07486abbecd6be14b47adf024a9d238df40aa40c
                                                                                                                                                                                                                                    • Instruction ID: dedd2023fe3812af516bd950140057e80e7d1a4528a61ba91bedfd4950334ca0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e699d6ba1381e6e702e0febc07486abbecd6be14b47adf024a9d238df40aa40c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 09117562F19B4698F701FB11EC406A8A7A4BFA87A4FC44275DD5C13B94EF3C9185D710
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressHandleModuleProc
                                                                                                                                                                                                                                    • String ID: NtWaitForKeyedEvent$ntdll
                                                                                                                                                                                                                                    • API String ID: 1646373207-2815205136
                                                                                                                                                                                                                                    • Opcode ID: 64394b801b81e6a0a984d4499d55364d9ac8c409084afe0741f23cf57a91e763
                                                                                                                                                                                                                                    • Instruction ID: f20e8f1f8f38ec5c5f36f2c5894bf54f42236dd749cc5252840c5b64b5e527cc
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 64394b801b81e6a0a984d4499d55364d9ac8c409084afe0741f23cf57a91e763
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 12116062B19B5698F600EB11EC407A8A3A4BFA87A4FC44275DD6C13B94EF3CA185D310
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressHandleModuleProc
                                                                                                                                                                                                                                    • String ID: NtCreateKeyedEvent$ntdll
                                                                                                                                                                                                                                    • API String ID: 1646373207-1373576770
                                                                                                                                                                                                                                    • Opcode ID: 74672ac36c9145f8aea7286157c1683f50e1800a45b2c499d0e8ef1cbefd4c5f
                                                                                                                                                                                                                                    • Instruction ID: 04a3fe59b30c152535aa617f2aa80a5b479d0a6b1fa737b8962214eb77457d09
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 74672ac36c9145f8aea7286157c1683f50e1800a45b2c499d0e8ef1cbefd4c5f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4FF08212F0A64391FA05EB46EC80AA096906FA8BD1FC58575CD0C43B65EF3C984AE310
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressHandleModuleProc
                                                                                                                                                                                                                                    • String ID: SetThreadDescription$kernel32
                                                                                                                                                                                                                                    • API String ID: 1646373207-1950310818
                                                                                                                                                                                                                                    • Opcode ID: 61ee8bfb5e01843a2e2f1a447082775c275d20ffc41f2e8e16720901a7b7d241
                                                                                                                                                                                                                                    • Instruction ID: 1c4e4e6efe232b3bb10718a1f8832de6abc5c271cc5d5f62525024b5dac77691
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 61ee8bfb5e01843a2e2f1a447082775c275d20ffc41f2e8e16720901a7b7d241
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 58E03012F0A64381FD05FB02ED4467492A1AFD8BD0FC04575CC0C42764EF2CA546E320
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • __rust_begin_short_backtrace__rust_end_short_backtrace [... omitted frame ...], xrefs: 00007FF70A20B4E6
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: memcmp
                                                                                                                                                                                                                                    • String ID: __rust_begin_short_backtrace__rust_end_short_backtrace [... omitted frame ...]
                                                                                                                                                                                                                                    • API String ID: 1475443563-995930526
                                                                                                                                                                                                                                    • Opcode ID: a0e3fe3658da8c94bb66333a6714d5eafdfd828cea799fd49303a2d2be01f1c8
                                                                                                                                                                                                                                    • Instruction ID: 08c06cdd9ac0bc2ec06633ac795f17623c2d1e90ab0d3b57e43c5020294fa582
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a0e3fe3658da8c94bb66333a6714d5eafdfd828cea799fd49303a2d2be01f1c8
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7502E263A1C7C340FA22A729E800BB9E760AF657D4F905371EF9D52AD5EF28D1858720
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorLast$CaptureContextCurrentDirectoryUnwindVirtualmemset
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 131827107-0
                                                                                                                                                                                                                                    • Opcode ID: db61a74fec9df8798d67fecd3ceb5dbc939ee1940100ec13c0f70b44886ad472
                                                                                                                                                                                                                                    • Instruction ID: 36ae35808e96313ef06c918e0bb862add4e2d9966d709b690ac6de54e588a4f0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: db61a74fec9df8798d67fecd3ceb5dbc939ee1940100ec13c0f70b44886ad472
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A9B12822604FC68CEB719F20EC403EA77A4EB55749F84016ADA8C5BB99EF389285D750
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: memmove
                                                                                                                                                                                                                                    • String ID: called `Result::unwrap()` on an `Err` value$capacity overflow
                                                                                                                                                                                                                                    • API String ID: 2162964266-2618782069
                                                                                                                                                                                                                                    • Opcode ID: 1aacad35d64685332415b81dc4c1bf541881bf353b7b7bf4e379db7216600f78
                                                                                                                                                                                                                                    • Instruction ID: 4c8b5861f0030982b5ebd1e6a783d7112f2d9c8809c69ac18ebe7dce0e03361f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1aacad35d64685332415b81dc4c1bf541881bf353b7b7bf4e379db7216600f78
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1D51B223A0964781FA60AB11ED007F9A650AF947A0FC04276DEAD477E1DF3DE186E360
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • use of std::thread::current() is not possible after the thread's local data has been destroyed, xrefs: 00007FF70A1F866C
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressCloseHandleWait
                                                                                                                                                                                                                                    • String ID: use of std::thread::current() is not possible after the thread's local data has been destroyed
                                                                                                                                                                                                                                    • API String ID: 592885855-1431102515
                                                                                                                                                                                                                                    • Opcode ID: bb88ac1fa9b7f4cb90ac99c1a32d02fc28def018a9ff580e1e811fd71806e4ba
                                                                                                                                                                                                                                    • Instruction ID: a6f7a3d0a561a54e901fac804dc8c0e639fbb575c8a9ce151b62814898e518cf
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bb88ac1fa9b7f4cb90ac99c1a32d02fc28def018a9ff580e1e811fd71806e4ba
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B0518C23A15A9398FB11AB61EC007ADA774BF94768F844372DE6C13BD4DF389046C360
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • AcquireSRWLockExclusive.KERNEL32(?,?,?,?,?,?,?,00007FF70A1FA0F4), ref: 00007FF70A1F9D64
                                                                                                                                                                                                                                    • ReleaseSRWLockExclusive.KERNEL32(?,?,?,?,?,?,?,00007FF70A1FA0F4), ref: 00007FF70A1F9DE1
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs, xrefs: 00007FF70A1F9E0D
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExclusiveLock$AcquireRelease
                                                                                                                                                                                                                                    • String ID: lock count overflow in reentrant mutexlibrary\std\src\sync\remutex.rs
                                                                                                                                                                                                                                    • API String ID: 17069307-2303981482
                                                                                                                                                                                                                                    • Opcode ID: 2e1258e8a3cb1d6d255efc34848cfdc53e597352546813490d7339e6a5665453
                                                                                                                                                                                                                                    • Instruction ID: 1974cf640db683b216ab41874f09d8b4a1c4f077ca033921d1836916591e3273
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2e1258e8a3cb1d6d255efc34848cfdc53e597352546813490d7339e6a5665453
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6F313736A04A429AFB50EB55E8403B86770FF98B98F904671CF1D53B94DF38E596C360
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorFrequencyLastPerformanceQuery
                                                                                                                                                                                                                                    • String ID: called `Result::unwrap()` on an `Err` value
                                                                                                                                                                                                                                    • API String ID: 3362413890-2333694755
                                                                                                                                                                                                                                    • Opcode ID: 39ea93d06bf1bb2753f72d145015fa0da87a7fc607cad0db232f24eff2639644
                                                                                                                                                                                                                                    • Instruction ID: 6f4cab5126bfb5345bdb0f56e6e471821f397e1e4390fa7b1cc52ff0bc11a303
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 39ea93d06bf1bb2753f72d145015fa0da87a7fc607cad0db232f24eff2639644
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6B31E4A3B08B4789FB04AB65EC003F4A266AFD4794F84C276C91D43B95DF3C9552D360
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 00000009.00000002.1887195622.00007FF70A1F1000.00000020.00000001.01000000.00000007.sdmp, Offset: 00007FF70A1F0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887115470.00007FF70A1F0000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887240069.00007FF70A211000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887279959.00007FF70A21D000.00000004.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 00000009.00000002.1887344374.00007FF70A21E000.00000002.00000001.01000000.00000007.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_9_2_7ff70a1f0000_pdf.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: PerformanceQuery$CounterErrorFrequencyLast
                                                                                                                                                                                                                                    • String ID: called `Result::unwrap()` on an `Err` value
                                                                                                                                                                                                                                    • API String ID: 158728112-2333694755
                                                                                                                                                                                                                                    • Opcode ID: 6c68f51b7059e0c36d74687cb0967f9761fd4d9b73deb470bf7d3ed6f4db34c6
                                                                                                                                                                                                                                    • Instruction ID: 2b6237f58b996d9719b8e299c133a601363d84b3612f0d97608a11fae8cf4d01
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6c68f51b7059e0c36d74687cb0967f9761fd4d9b73deb470bf7d3ed6f4db34c6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 11013C63E18A8299F710AB60EC012F8A774FB90314F944A72DA6D527D4DF389255C360

                                                                                                                                                                                                                                    Execution Graph

                                                                                                                                                                                                                                    Execution Coverage:11.2%
                                                                                                                                                                                                                                    Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                    Signature Coverage:1.9%
                                                                                                                                                                                                                                    Total number of Nodes:2000
                                                                                                                                                                                                                                    Total number of Limit Nodes:45
                                                                                                                                                                                                                                    execution_graph 19507 7ff71dbdb460 19508 7ff71dbdb470 19507->19508 19524 7ff71dbea3f8 19508->19524 19510 7ff71dbdb47c 19530 7ff71dbdb778 19510->19530 19512 7ff71dbdba5c 7 API calls 19516 7ff71dbdb515 19512->19516 19513 7ff71dbdb494 _RTC_Initialize 19522 7ff71dbdb4e9 19513->19522 19535 7ff71dbdb928 19513->19535 19515 7ff71dbdb4a9 19538 7ff71dbe9868 19515->19538 19522->19512 19523 7ff71dbdb505 19522->19523 19525 7ff71dbea409 19524->19525 19526 7ff71dbe7c48 _get_daylight 11 API calls 19525->19526 19527 7ff71dbea411 19525->19527 19528 7ff71dbea420 19526->19528 19527->19510 19529 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 19528->19529 19529->19527 19531 7ff71dbdb789 19530->19531 19534 7ff71dbdb78e __scrt_release_startup_lock 19530->19534 19532 7ff71dbdba5c 7 API calls 19531->19532 19531->19534 19533 7ff71dbdb802 19532->19533 19534->19513 19563 7ff71dbdb8ec 19535->19563 19537 7ff71dbdb931 19537->19515 19539 7ff71dbe9888 19538->19539 19561 7ff71dbdb4b5 19538->19561 19540 7ff71dbe98a6 GetModuleFileNameW 19539->19540 19541 7ff71dbe9890 19539->19541 19545 7ff71dbe98d1 19540->19545 19542 7ff71dbe7c48 _get_daylight 11 API calls 19541->19542 19543 7ff71dbe9895 19542->19543 19544 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 19543->19544 19544->19561 19546 7ff71dbe9808 11 API calls 19545->19546 19547 7ff71dbe9911 19546->19547 19548 7ff71dbe9919 19547->19548 19553 7ff71dbe9931 19547->19553 19549 7ff71dbe7c48 _get_daylight 11 API calls 19548->19549 19550 7ff71dbe991e 19549->19550 19551 7ff71dbeb1cc __free_lconv_mon 11 API calls 19550->19551 19551->19561 19552 7ff71dbe9953 19554 7ff71dbeb1cc __free_lconv_mon 11 API calls 19552->19554 19553->19552 19555 7ff71dbe997f 19553->19555 19556 7ff71dbe9998 19553->19556 19554->19561 19557 7ff71dbeb1cc __free_lconv_mon 11 API calls 19555->19557 19559 7ff71dbeb1cc __free_lconv_mon 11 API calls 19556->19559 19558 7ff71dbe9988 19557->19558 19560 7ff71dbeb1cc __free_lconv_mon 11 API calls 19558->19560 19559->19552 19560->19561 19561->19522 19562 7ff71dbdb9fc InitializeSListHead 19561->19562 19564 7ff71dbdb906 19563->19564 19566 7ff71dbdb8ff 19563->19566 19567 7ff71dbeaa3c 19564->19567 19566->19537 19570 7ff71dbea678 19567->19570 19577 7ff71dbf0ea8 EnterCriticalSection 19570->19577 18805 7ff71dbf86e0 18808 7ff71dbf2e50 18805->18808 18809 7ff71dbf2e5d 18808->18809 18810 7ff71dbf2ea2 18808->18810 18814 7ff71dbebaa4 18809->18814 18815 7ff71dbebab5 FlsGetValue 18814->18815 18816 7ff71dbebad0 FlsSetValue 18814->18816 18817 7ff71dbebac2 18815->18817 18818 7ff71dbebaca 18815->18818 18816->18817 18819 7ff71dbebadd 18816->18819 18820 7ff71dbebac8 18817->18820 18821 7ff71dbead5c __CxxCallCatchBlock 45 API calls 18817->18821 18818->18816 18822 7ff71dbef430 _get_daylight 11 API calls 18819->18822 18834 7ff71dbf2b24 18820->18834 18823 7ff71dbebb45 18821->18823 18824 7ff71dbebaec 18822->18824 18825 7ff71dbebb0a FlsSetValue 18824->18825 18826 7ff71dbebafa FlsSetValue 18824->18826 18828 7ff71dbebb16 FlsSetValue 18825->18828 18829 7ff71dbebb28 18825->18829 18827 7ff71dbebb03 18826->18827 18830 7ff71dbeb1cc __free_lconv_mon 11 API calls 18827->18830 18828->18827 18831 7ff71dbeb778 _get_daylight 11 API calls 18829->18831 18830->18817 18832 7ff71dbebb30 18831->18832 18833 7ff71dbeb1cc __free_lconv_mon 11 API calls 18832->18833 18833->18820 18857 7ff71dbf2d94 18834->18857 18836 7ff71dbf2b59 18872 7ff71dbf2824 18836->18872 18839 7ff71dbede7c _fread_nolock 12 API calls 18840 7ff71dbf2b87 18839->18840 18841 7ff71dbf2b8f 18840->18841 18842 7ff71dbf2b9e 18840->18842 18843 7ff71dbeb1cc __free_lconv_mon 11 API calls 18841->18843 18879 7ff71dbf2ecc 18842->18879 18856 7ff71dbf2b76 18843->18856 18846 7ff71dbf2c9a 18847 7ff71dbe7c48 _get_daylight 11 API calls 18846->18847 18848 7ff71dbf2c9f 18847->18848 18852 7ff71dbeb1cc __free_lconv_mon 11 API calls 18848->18852 18849 7ff71dbf2cf5 18851 7ff71dbf2d5c 18849->18851 18890 7ff71dbf2654 18849->18890 18850 7ff71dbf2cb4 18850->18849 18853 7ff71dbeb1cc __free_lconv_mon 11 API calls 18850->18853 18855 7ff71dbeb1cc __free_lconv_mon 11 API calls 18851->18855 18852->18856 18853->18849 18855->18856 18856->18810 18858 7ff71dbf2db7 18857->18858 18860 7ff71dbf2dc1 18858->18860 18905 7ff71dbf0ea8 EnterCriticalSection 18858->18905 18861 7ff71dbf2e33 18860->18861 18863 7ff71dbead5c __CxxCallCatchBlock 45 API calls 18860->18863 18861->18836 18865 7ff71dbf2e4b 18863->18865 18867 7ff71dbf2ea2 18865->18867 18869 7ff71dbebaa4 50 API calls 18865->18869 18867->18836 18870 7ff71dbf2e8c 18869->18870 18871 7ff71dbf2b24 65 API calls 18870->18871 18871->18867 18873 7ff71dbe5194 45 API calls 18872->18873 18874 7ff71dbf2838 18873->18874 18875 7ff71dbf2856 18874->18875 18876 7ff71dbf2844 GetOEMCP 18874->18876 18877 7ff71dbf286b 18875->18877 18878 7ff71dbf285b GetACP 18875->18878 18876->18877 18877->18839 18877->18856 18878->18877 18880 7ff71dbf2824 47 API calls 18879->18880 18881 7ff71dbf2ef9 18880->18881 18882 7ff71dbf304f 18881->18882 18884 7ff71dbf2f36 IsValidCodePage 18881->18884 18889 7ff71dbf2f50 memcpy_s 18881->18889 18883 7ff71dbdb190 _wfindfirst32i64 8 API calls 18882->18883 18886 7ff71dbf2c91 18883->18886 18884->18882 18885 7ff71dbf2f47 18884->18885 18887 7ff71dbf2f76 GetCPInfo 18885->18887 18885->18889 18886->18846 18886->18850 18887->18882 18887->18889 18906 7ff71dbf293c 18889->18906 18962 7ff71dbf0ea8 EnterCriticalSection 18890->18962 18907 7ff71dbf2a6f 18906->18907 18908 7ff71dbf2979 GetCPInfo 18906->18908 18909 7ff71dbdb190 _wfindfirst32i64 8 API calls 18907->18909 18908->18907 18912 7ff71dbf298c 18908->18912 18911 7ff71dbf2b0e 18909->18911 18910 7ff71dbf36a0 48 API calls 18913 7ff71dbf2a03 18910->18913 18911->18882 18912->18910 18917 7ff71dbf8644 18913->18917 18916 7ff71dbf8644 54 API calls 18916->18907 18918 7ff71dbe5194 45 API calls 18917->18918 18919 7ff71dbf8669 18918->18919 18922 7ff71dbf8310 18919->18922 18923 7ff71dbf8351 18922->18923 18924 7ff71dbefdf0 _fread_nolock MultiByteToWideChar 18923->18924 18926 7ff71dbf839b 18924->18926 18925 7ff71dbdb190 _wfindfirst32i64 8 API calls 18927 7ff71dbf2a36 18925->18927 18928 7ff71dbf8619 18926->18928 18929 7ff71dbf84d1 18926->18929 18930 7ff71dbede7c _fread_nolock 12 API calls 18926->18930 18932 7ff71dbf83d3 18926->18932 18927->18916 18928->18925 18929->18928 18931 7ff71dbeb1cc __free_lconv_mon 11 API calls 18929->18931 18930->18932 18931->18928 18932->18929 18933 7ff71dbefdf0 _fread_nolock MultiByteToWideChar 18932->18933 18934 7ff71dbf8446 18933->18934 18934->18929 18953 7ff71dbef87c 18934->18953 18937 7ff71dbf84e2 18939 7ff71dbede7c _fread_nolock 12 API calls 18937->18939 18941 7ff71dbf85b4 18937->18941 18942 7ff71dbf8500 18937->18942 18938 7ff71dbf8491 18938->18929 18940 7ff71dbef87c __crtLCMapStringW 6 API calls 18938->18940 18939->18942 18940->18929 18941->18929 18943 7ff71dbeb1cc __free_lconv_mon 11 API calls 18941->18943 18942->18929 18944 7ff71dbef87c __crtLCMapStringW 6 API calls 18942->18944 18943->18929 18945 7ff71dbf8580 18944->18945 18945->18941 18946 7ff71dbf85b6 18945->18946 18947 7ff71dbf85a0 18945->18947 18949 7ff71dbf06b8 WideCharToMultiByte 18946->18949 18948 7ff71dbf06b8 WideCharToMultiByte 18947->18948 18950 7ff71dbf85ae 18948->18950 18949->18950 18950->18941 18951 7ff71dbf85ce 18950->18951 18951->18929 18952 7ff71dbeb1cc __free_lconv_mon 11 API calls 18951->18952 18952->18929 18954 7ff71dbef4a8 __crtLCMapStringW 5 API calls 18953->18954 18955 7ff71dbef8ba 18954->18955 18958 7ff71dbef8c2 18955->18958 18959 7ff71dbef968 18955->18959 18957 7ff71dbef92b LCMapStringW 18957->18958 18958->18929 18958->18937 18958->18938 18960 7ff71dbef4a8 __crtLCMapStringW 5 API calls 18959->18960 18961 7ff71dbef996 __crtLCMapStringW 18960->18961 18961->18957 18736 7ff71dbefedc 18737 7ff71dbf00ce 18736->18737 18739 7ff71dbeff1e _isindst 18736->18739 18738 7ff71dbe7c48 _get_daylight 11 API calls 18737->18738 18756 7ff71dbf00be 18738->18756 18739->18737 18742 7ff71dbeff9e _isindst 18739->18742 18740 7ff71dbdb190 _wfindfirst32i64 8 API calls 18741 7ff71dbf00e9 18740->18741 18757 7ff71dbf6af4 18742->18757 18747 7ff71dbf00fa 18749 7ff71dbeb184 _wfindfirst32i64 17 API calls 18747->18749 18751 7ff71dbf010e 18749->18751 18754 7ff71dbefffb 18754->18756 18781 7ff71dbf6b38 18754->18781 18756->18740 18758 7ff71dbf6b03 18757->18758 18759 7ff71dbeffbc 18757->18759 18788 7ff71dbf0ea8 EnterCriticalSection 18758->18788 18763 7ff71dbf5ef8 18759->18763 18764 7ff71dbf5f01 18763->18764 18765 7ff71dbeffd1 18763->18765 18766 7ff71dbe7c48 _get_daylight 11 API calls 18764->18766 18765->18747 18769 7ff71dbf5f28 18765->18769 18767 7ff71dbf5f06 18766->18767 18768 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 18767->18768 18768->18765 18770 7ff71dbf5f31 18769->18770 18771 7ff71dbeffe2 18769->18771 18772 7ff71dbe7c48 _get_daylight 11 API calls 18770->18772 18771->18747 18775 7ff71dbf5f58 18771->18775 18773 7ff71dbf5f36 18772->18773 18774 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 18773->18774 18774->18771 18776 7ff71dbf5f61 18775->18776 18780 7ff71dbefff3 18775->18780 18777 7ff71dbe7c48 _get_daylight 11 API calls 18776->18777 18778 7ff71dbf5f66 18777->18778 18779 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 18778->18779 18779->18780 18780->18747 18780->18754 18789 7ff71dbf0ea8 EnterCriticalSection 18781->18789 19303 7ff71dbfacfd 19306 7ff71dbe5578 LeaveCriticalSection 19303->19306 19618 7ff71dbfab77 19619 7ff71dbfab87 19618->19619 19622 7ff71dbe5578 LeaveCriticalSection 19619->19622 15567 7ff71dbe8110 15568 7ff71dbe813e 15567->15568 15569 7ff71dbe8177 15567->15569 15647 7ff71dbe7c48 15568->15647 15569->15568 15571 7ff71dbe817c FindFirstFileExW 15569->15571 15572 7ff71dbe81e5 15571->15572 15573 7ff71dbe819e GetLastError 15571->15573 15627 7ff71dbe8380 15572->15627 15575 7ff71dbe81d5 15573->15575 15576 7ff71dbe81a9 15573->15576 15579 7ff71dbe7c48 _get_daylight 11 API calls 15575->15579 15576->15575 15582 7ff71dbe81c5 15576->15582 15583 7ff71dbe81b3 15576->15583 15584 7ff71dbe814e 15579->15584 15581 7ff71dbe8380 _wfindfirst32i64 10 API calls 15585 7ff71dbe820b 15581->15585 15587 7ff71dbe7c48 _get_daylight 11 API calls 15582->15587 15583->15575 15586 7ff71dbe81b8 15583->15586 15652 7ff71dbdb190 15584->15652 15589 7ff71dbe8380 _wfindfirst32i64 10 API calls 15585->15589 15590 7ff71dbe7c48 _get_daylight 11 API calls 15586->15590 15587->15584 15592 7ff71dbe8219 15589->15592 15590->15584 15634 7ff71dbf1044 15592->15634 15595 7ff71dbe8243 15643 7ff71dbeb184 IsProcessorFeaturePresent 15595->15643 15628 7ff71dbe839e FileTimeToSystemTime 15627->15628 15629 7ff71dbe8398 15627->15629 15630 7ff71dbe83ad SystemTimeToTzSpecificLocalTime 15628->15630 15631 7ff71dbe83c3 15628->15631 15629->15628 15629->15631 15630->15631 15632 7ff71dbdb190 _wfindfirst32i64 8 API calls 15631->15632 15633 7ff71dbe81fd 15632->15633 15633->15581 15635 7ff71dbf1051 15634->15635 15636 7ff71dbf105b 15634->15636 15635->15636 15639 7ff71dbf1077 15635->15639 15637 7ff71dbe7c48 _get_daylight 11 API calls 15636->15637 15642 7ff71dbf1063 15637->15642 15638 7ff71dbe8237 15638->15584 15638->15595 15639->15638 15641 7ff71dbe7c48 _get_daylight 11 API calls 15639->15641 15640 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 15640->15638 15641->15642 15642->15640 15644 7ff71dbeb197 15643->15644 15661 7ff71dbeae98 15644->15661 15669 7ff71dbebb48 GetLastError 15647->15669 15649 7ff71dbe7c51 15650 7ff71dbeb164 15649->15650 15727 7ff71dbeaffc 15650->15727 15653 7ff71dbdb199 15652->15653 15654 7ff71dbdb1a4 15653->15654 15655 7ff71dbdb1f0 IsProcessorFeaturePresent 15653->15655 15656 7ff71dbdb208 15655->15656 15765 7ff71dbdb3e4 RtlCaptureContext 15656->15765 15662 7ff71dbeaed2 _wfindfirst32i64 memcpy_s 15661->15662 15663 7ff71dbeaefa RtlCaptureContext RtlLookupFunctionEntry 15662->15663 15664 7ff71dbeaf34 RtlVirtualUnwind 15663->15664 15665 7ff71dbeaf6a IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 15663->15665 15664->15665 15666 7ff71dbeafbc _wfindfirst32i64 15665->15666 15667 7ff71dbdb190 _wfindfirst32i64 8 API calls 15666->15667 15668 7ff71dbeafdb GetCurrentProcess TerminateProcess 15667->15668 15670 7ff71dbebb6c 15669->15670 15671 7ff71dbebb89 FlsSetValue 15669->15671 15670->15671 15683 7ff71dbebb79 SetLastError 15670->15683 15672 7ff71dbebb9b 15671->15672 15671->15683 15686 7ff71dbef430 15672->15686 15676 7ff71dbebbc8 FlsSetValue 15678 7ff71dbebbe6 15676->15678 15679 7ff71dbebbd4 FlsSetValue 15676->15679 15677 7ff71dbebbb8 FlsSetValue 15680 7ff71dbebbc1 15677->15680 15699 7ff71dbeb778 15678->15699 15679->15680 15693 7ff71dbeb1cc 15680->15693 15683->15649 15692 7ff71dbef441 _get_daylight 15686->15692 15687 7ff71dbef492 15689 7ff71dbe7c48 _get_daylight 10 API calls 15687->15689 15688 7ff71dbef476 RtlAllocateHeap 15690 7ff71dbebbaa 15688->15690 15688->15692 15689->15690 15690->15676 15690->15677 15692->15687 15692->15688 15704 7ff71dbf3df0 15692->15704 15694 7ff71dbeb1d1 RtlRestoreThreadPreferredUILanguages 15693->15694 15695 7ff71dbeb200 15693->15695 15694->15695 15696 7ff71dbeb1ec GetLastError 15694->15696 15695->15683 15697 7ff71dbeb1f9 __free_lconv_mon 15696->15697 15698 7ff71dbe7c48 _get_daylight 9 API calls 15697->15698 15698->15695 15713 7ff71dbeb650 15699->15713 15707 7ff71dbf3e30 15704->15707 15712 7ff71dbf0ea8 EnterCriticalSection 15707->15712 15725 7ff71dbf0ea8 EnterCriticalSection 15713->15725 15728 7ff71dbeb027 15727->15728 15731 7ff71dbeb098 15728->15731 15730 7ff71dbeb04e 15739 7ff71dbeade0 15731->15739 15736 7ff71dbeb0d3 15736->15730 15737 7ff71dbeb184 _wfindfirst32i64 17 API calls 15738 7ff71dbeb163 15737->15738 15740 7ff71dbeadfc GetLastError 15739->15740 15741 7ff71dbeae37 15739->15741 15742 7ff71dbeae0c 15740->15742 15741->15736 15745 7ff71dbeae4c 15741->15745 15748 7ff71dbebc10 15742->15748 15746 7ff71dbeae68 GetLastError SetLastError 15745->15746 15747 7ff71dbeae80 15745->15747 15746->15747 15747->15736 15747->15737 15749 7ff71dbebc2f FlsGetValue 15748->15749 15750 7ff71dbebc4a FlsSetValue 15748->15750 15751 7ff71dbebc44 15749->15751 15752 7ff71dbeae27 SetLastError 15749->15752 15750->15752 15753 7ff71dbebc57 15750->15753 15751->15750 15752->15741 15754 7ff71dbef430 _get_daylight 11 API calls 15753->15754 15755 7ff71dbebc66 15754->15755 15756 7ff71dbebc84 FlsSetValue 15755->15756 15757 7ff71dbebc74 FlsSetValue 15755->15757 15758 7ff71dbebca2 15756->15758 15759 7ff71dbebc90 FlsSetValue 15756->15759 15760 7ff71dbebc7d 15757->15760 15761 7ff71dbeb778 _get_daylight 11 API calls 15758->15761 15759->15760 15762 7ff71dbeb1cc __free_lconv_mon 11 API calls 15760->15762 15763 7ff71dbebcaa 15761->15763 15762->15752 15764 7ff71dbeb1cc __free_lconv_mon 11 API calls 15763->15764 15764->15752 15766 7ff71dbdb3fe RtlLookupFunctionEntry 15765->15766 15767 7ff71dbdb414 RtlVirtualUnwind 15766->15767 15768 7ff71dbdb21b 15766->15768 15767->15766 15767->15768 15769 7ff71dbdb1b0 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 15768->15769 15770 7ff71dbda710 15771 7ff71dbda73e 15770->15771 15772 7ff71dbda725 15770->15772 15772->15771 15775 7ff71dbede7c 15772->15775 15776 7ff71dbedec7 15775->15776 15780 7ff71dbede8b _get_daylight 15775->15780 15778 7ff71dbe7c48 _get_daylight 11 API calls 15776->15778 15777 7ff71dbedeae RtlAllocateHeap 15779 7ff71dbda79c 15777->15779 15777->15780 15778->15779 15780->15776 15780->15777 15781 7ff71dbf3df0 _get_daylight 2 API calls 15780->15781 15781->15780 19310 7ff71dbe5510 19311 7ff71dbe551b 19310->19311 19319 7ff71dbefa44 19311->19319 19332 7ff71dbf0ea8 EnterCriticalSection 19319->19332 19623 7ff71dbfad92 19624 7ff71dbfada1 19623->19624 19625 7ff71dbfadab 19623->19625 19627 7ff71dbf0f08 LeaveCriticalSection 19624->19627 19333 7ff71dbf1f10 19344 7ff71dbf7ea4 19333->19344 19345 7ff71dbf7eb1 19344->19345 19346 7ff71dbeb1cc __free_lconv_mon 11 API calls 19345->19346 19348 7ff71dbf7ecd 19345->19348 19346->19345 19347 7ff71dbeb1cc __free_lconv_mon 11 API calls 19347->19348 19348->19347 19349 7ff71dbf1f19 19348->19349 19350 7ff71dbf0ea8 EnterCriticalSection 19349->19350 19357 7ff71dbea5a0 19360 7ff71dbea51c 19357->19360 19367 7ff71dbf0ea8 EnterCriticalSection 19360->19367 15782 7ff71dbea1b1 15794 7ff71dbeac28 15782->15794 15799 7ff71dbeb9d0 GetLastError 15794->15799 15800 7ff71dbeb9f4 FlsGetValue 15799->15800 15801 7ff71dbeba11 FlsSetValue 15799->15801 15802 7ff71dbeba0b 15800->15802 15818 7ff71dbeba01 15800->15818 15803 7ff71dbeba23 15801->15803 15801->15818 15802->15801 15805 7ff71dbef430 _get_daylight 11 API calls 15803->15805 15804 7ff71dbeba7d SetLastError 15806 7ff71dbeba9d 15804->15806 15807 7ff71dbeac31 15804->15807 15808 7ff71dbeba32 15805->15808 15809 7ff71dbead5c __CxxCallCatchBlock 38 API calls 15806->15809 15821 7ff71dbead5c 15807->15821 15810 7ff71dbeba50 FlsSetValue 15808->15810 15811 7ff71dbeba40 FlsSetValue 15808->15811 15814 7ff71dbebaa2 15809->15814 15812 7ff71dbeba6e 15810->15812 15813 7ff71dbeba5c FlsSetValue 15810->15813 15815 7ff71dbeba49 15811->15815 15817 7ff71dbeb778 _get_daylight 11 API calls 15812->15817 15813->15815 15816 7ff71dbeb1cc __free_lconv_mon 11 API calls 15815->15816 15816->15818 15819 7ff71dbeba76 15817->15819 15818->15804 15820 7ff71dbeb1cc __free_lconv_mon 11 API calls 15819->15820 15820->15804 15830 7ff71dbf3eb0 15821->15830 15856 7ff71dbf3e68 15830->15856 15861 7ff71dbf0ea8 EnterCriticalSection 15856->15861 19388 7ff71dbf1cc0 19406 7ff71dbf0ea8 EnterCriticalSection 19388->19406 20174 7ff71dbeb850 20175 7ff71dbeb855 20174->20175 20176 7ff71dbeb86a 20174->20176 20180 7ff71dbeb870 20175->20180 20181 7ff71dbeb8b2 20180->20181 20182 7ff71dbeb8ba 20180->20182 20183 7ff71dbeb1cc __free_lconv_mon 11 API calls 20181->20183 20184 7ff71dbeb1cc __free_lconv_mon 11 API calls 20182->20184 20183->20182 20185 7ff71dbeb8c7 20184->20185 20186 7ff71dbeb1cc __free_lconv_mon 11 API calls 20185->20186 20187 7ff71dbeb8d4 20186->20187 20188 7ff71dbeb1cc __free_lconv_mon 11 API calls 20187->20188 20189 7ff71dbeb8e1 20188->20189 20190 7ff71dbeb1cc __free_lconv_mon 11 API calls 20189->20190 20191 7ff71dbeb8ee 20190->20191 20192 7ff71dbeb1cc __free_lconv_mon 11 API calls 20191->20192 20193 7ff71dbeb8fb 20192->20193 20194 7ff71dbeb1cc __free_lconv_mon 11 API calls 20193->20194 20195 7ff71dbeb908 20194->20195 20196 7ff71dbeb1cc __free_lconv_mon 11 API calls 20195->20196 20197 7ff71dbeb915 20196->20197 20198 7ff71dbeb1cc __free_lconv_mon 11 API calls 20197->20198 20199 7ff71dbeb925 20198->20199 20200 7ff71dbeb1cc __free_lconv_mon 11 API calls 20199->20200 20201 7ff71dbeb935 20200->20201 20206 7ff71dbeb718 20201->20206 20220 7ff71dbf0ea8 EnterCriticalSection 20206->20220 15865 7ff71dbdb54c 15886 7ff71dbdb72c 15865->15886 15868 7ff71dbdb6a3 16008 7ff71dbdba5c IsProcessorFeaturePresent 15868->16008 15870 7ff71dbdb56d __scrt_acquire_startup_lock 15871 7ff71dbdb6ad 15870->15871 15877 7ff71dbdb58b __scrt_release_startup_lock 15870->15877 15872 7ff71dbdba5c 7 API calls 15871->15872 15874 7ff71dbdb6b8 __CxxCallCatchBlock 15872->15874 15873 7ff71dbdb5b0 15875 7ff71dbdb636 15894 7ff71dbe9fd0 15875->15894 15877->15873 15877->15875 15997 7ff71dbea37c 15877->15997 15879 7ff71dbdb63b 15900 7ff71dbd1000 15879->15900 15884 7ff71dbdb65f 15884->15874 16004 7ff71dbdb8c0 15884->16004 16015 7ff71dbdbcfc 15886->16015 15889 7ff71dbdb75b 16017 7ff71dbeabdc 15889->16017 15890 7ff71dbdb565 15890->15868 15890->15870 15895 7ff71dbe9fe0 15894->15895 15898 7ff71dbe9ff5 15894->15898 15895->15898 16060 7ff71dbe9a60 15895->16060 15898->15879 15901 7ff71dbd1011 15900->15901 16113 7ff71dbd7910 15901->16113 15903 7ff71dbd1023 16120 7ff71dbe60c0 15903->16120 15905 7ff71dbd2af0 16127 7ff71dbd1eb0 15905->16127 15909 7ff71dbdb190 _wfindfirst32i64 8 API calls 15910 7ff71dbd2bfa 15909->15910 16002 7ff71dbdbbb0 GetModuleHandleW 15910->16002 15911 7ff71dbd2b0f 15951 7ff71dbd2be6 15911->15951 16143 7ff71dbd6d60 15911->16143 15913 7ff71dbd2b3c 15914 7ff71dbd2b87 15913->15914 15916 7ff71dbd6d60 92 API calls 15913->15916 16158 7ff71dbd7240 15914->16158 15920 7ff71dbd2b5c __std_exception_copy 15916->15920 15917 7ff71dbd2b9c 16162 7ff71dbd1cb0 15917->16162 15920->15914 15923 7ff71dbd7240 89 API calls 15920->15923 15921 7ff71dbd2c8e 15928 7ff71dbd2cd7 15921->15928 15934 7ff71dbd2cbf 15921->15934 15935 7ff71dbd2cb8 15921->15935 15922 7ff71dbd1cb0 121 API calls 15924 7ff71dbd2bca 15922->15924 15923->15914 15925 7ff71dbd2bce 15924->15925 15929 7ff71dbd2c15 15924->15929 16263 7ff71dbd2010 15925->16263 15927 7ff71dbd2cfb 15932 7ff71dbd2d56 15927->15932 15927->15951 16188 7ff71dbd7fb0 15927->16188 15928->15927 16181 7ff71dbd14f0 15928->16181 15929->15921 16269 7ff71dbd31a0 15929->16269 16202 7ff71dbd5fe0 15932->16202 15934->15928 15946 7ff71dbd2cd2 15934->15946 16292 7ff71dbd7ab0 GetConsoleWindow 15935->16292 15938 7ff71dbd2c33 15947 7ff71dbd2010 86 API calls 15938->15947 15940 7ff71dbd2d33 15944 7ff71dbd2d38 15940->15944 15945 7ff71dbd2d49 SetDllDirectoryW 15940->15945 15949 7ff71dbd2010 86 API calls 15944->15949 15945->15932 16297 7ff71dbd7c00 GetConsoleWindow 15946->16297 15947->15951 15948 7ff71dbd2c61 15948->15921 15953 7ff71dbd2c66 15948->15953 15949->15951 15951->15909 16288 7ff71dbdf64c 15953->16288 15954 7ff71dbd2d70 15979 7ff71dbd2da2 15954->15979 16311 7ff71dbd57f0 15954->16311 15956 7ff71dbd2e9d 16206 7ff71dbd26d0 15956->16206 15961 7ff71dbd2dc1 15969 7ff71dbd2e05 15961->15969 16347 7ff71dbd1ef0 15961->16347 15962 7ff71dbd2da4 15963 7ff71dbd5a40 FreeLibrary 15962->15963 15963->15979 15967 7ff71dbd2e68 16351 7ff71dbd2670 15967->16351 15968 7ff71dbd2ec5 15971 7ff71dbd6d60 92 API calls 15968->15971 15969->15951 15969->15967 15973 7ff71dbd2e50 15969->15973 15974 7ff71dbd2e49 15969->15974 15982 7ff71dbd2ed1 15971->15982 15972 7ff71dbd2d93 16341 7ff71dbd5e30 15972->16341 15973->15967 15981 7ff71dbd2e63 15973->15981 15977 7ff71dbd7ab0 4 API calls 15974->15977 15980 7ff71dbd2e4e 15977->15980 15978 7ff71dbd2e78 15984 7ff71dbd5a40 FreeLibrary 15978->15984 15979->15956 15979->15961 15980->15967 15985 7ff71dbd7c00 4 API calls 15981->15985 15983 7ff71dbd2f0d 15982->15983 15988 7ff71dbd2ef5 15982->15988 15989 7ff71dbd2eee 15982->15989 16220 7ff71dbd7280 15983->16220 15984->15951 15985->15967 15988->15983 15993 7ff71dbd2f08 15988->15993 15991 7ff71dbd7ab0 4 API calls 15989->15991 15992 7ff71dbd2ef3 15991->15992 15992->15983 15995 7ff71dbd7c00 4 API calls 15993->15995 15995->15983 15998 7ff71dbea393 15997->15998 15999 7ff71dbea3b4 15997->15999 15998->15875 16000 7ff71dbeac28 45 API calls 15999->16000 16001 7ff71dbea3b9 16000->16001 16003 7ff71dbdbbc1 16002->16003 16003->15884 16005 7ff71dbdb8d1 16004->16005 16006 7ff71dbdb676 16005->16006 16007 7ff71dbdce58 __scrt_initialize_crt 7 API calls 16005->16007 16006->15873 16007->16006 16009 7ff71dbdba82 _wfindfirst32i64 memcpy_s 16008->16009 16010 7ff71dbdbaa1 RtlCaptureContext RtlLookupFunctionEntry 16009->16010 16011 7ff71dbdbaca RtlVirtualUnwind 16010->16011 16012 7ff71dbdbb06 memcpy_s 16010->16012 16011->16012 16013 7ff71dbdbb38 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 16012->16013 16014 7ff71dbdbb8a _wfindfirst32i64 16013->16014 16014->15871 16016 7ff71dbdb74e __scrt_dllmain_crt_thread_attach 16015->16016 16016->15889 16016->15890 16018 7ff71dbf3d0c 16017->16018 16019 7ff71dbdb760 16018->16019 16027 7ff71dbecda0 16018->16027 16019->15890 16021 7ff71dbdce58 16019->16021 16022 7ff71dbdce60 16021->16022 16023 7ff71dbdce6a 16021->16023 16039 7ff71dbdd1d4 16022->16039 16023->15890 16038 7ff71dbf0ea8 EnterCriticalSection 16027->16038 16040 7ff71dbdd1e3 16039->16040 16041 7ff71dbdce65 16039->16041 16047 7ff71dbdd410 16040->16047 16043 7ff71dbdd240 16041->16043 16044 7ff71dbdd26b 16043->16044 16045 7ff71dbdd26f 16044->16045 16046 7ff71dbdd24e DeleteCriticalSection 16044->16046 16045->16023 16046->16044 16051 7ff71dbdd278 16047->16051 16052 7ff71dbdd392 TlsFree 16051->16052 16058 7ff71dbdd2bc __vcrt_FlsAlloc 16051->16058 16053 7ff71dbdd2ea LoadLibraryExW 16055 7ff71dbdd361 16053->16055 16056 7ff71dbdd30b GetLastError 16053->16056 16054 7ff71dbdd381 GetProcAddress 16054->16052 16055->16054 16057 7ff71dbdd378 FreeLibrary 16055->16057 16056->16058 16057->16054 16058->16052 16058->16053 16058->16054 16059 7ff71dbdd32d LoadLibraryExW 16058->16059 16059->16055 16059->16058 16061 7ff71dbe9a79 16060->16061 16072 7ff71dbe9a75 16060->16072 16081 7ff71dbf329c GetEnvironmentStringsW 16061->16081 16064 7ff71dbe9a86 16066 7ff71dbeb1cc __free_lconv_mon 11 API calls 16064->16066 16065 7ff71dbe9a92 16088 7ff71dbe9be0 16065->16088 16066->16072 16069 7ff71dbeb1cc __free_lconv_mon 11 API calls 16070 7ff71dbe9ab9 16069->16070 16071 7ff71dbeb1cc __free_lconv_mon 11 API calls 16070->16071 16071->16072 16072->15898 16073 7ff71dbe9e20 16072->16073 16074 7ff71dbe9e43 16073->16074 16079 7ff71dbe9e5a 16073->16079 16074->15898 16075 7ff71dbefdf0 MultiByteToWideChar _fread_nolock 16075->16079 16076 7ff71dbef430 _get_daylight 11 API calls 16076->16079 16077 7ff71dbe9ece 16078 7ff71dbeb1cc __free_lconv_mon 11 API calls 16077->16078 16078->16074 16079->16074 16079->16075 16079->16076 16079->16077 16080 7ff71dbeb1cc __free_lconv_mon 11 API calls 16079->16080 16080->16079 16082 7ff71dbe9a7e 16081->16082 16083 7ff71dbf32c0 16081->16083 16082->16064 16082->16065 16084 7ff71dbede7c _fread_nolock 12 API calls 16083->16084 16085 7ff71dbf32f7 memcpy_s 16084->16085 16086 7ff71dbeb1cc __free_lconv_mon 11 API calls 16085->16086 16087 7ff71dbf3317 FreeEnvironmentStringsW 16086->16087 16087->16082 16089 7ff71dbe9c08 16088->16089 16090 7ff71dbef430 _get_daylight 11 API calls 16089->16090 16101 7ff71dbe9c43 16090->16101 16091 7ff71dbe9c4b 16092 7ff71dbeb1cc __free_lconv_mon 11 API calls 16091->16092 16094 7ff71dbe9a9a 16092->16094 16093 7ff71dbe9cc5 16095 7ff71dbeb1cc __free_lconv_mon 11 API calls 16093->16095 16094->16069 16095->16094 16096 7ff71dbef430 _get_daylight 11 API calls 16096->16101 16097 7ff71dbe9cb4 16107 7ff71dbe9cfc 16097->16107 16098 7ff71dbf1044 _wfindfirst32i64 37 API calls 16098->16101 16101->16091 16101->16093 16101->16096 16101->16097 16101->16098 16102 7ff71dbe9ce8 16101->16102 16105 7ff71dbeb1cc __free_lconv_mon 11 API calls 16101->16105 16104 7ff71dbeb184 _wfindfirst32i64 17 API calls 16102->16104 16103 7ff71dbeb1cc __free_lconv_mon 11 API calls 16103->16091 16106 7ff71dbe9cfa 16104->16106 16105->16101 16108 7ff71dbe9d01 16107->16108 16109 7ff71dbe9cbc 16107->16109 16110 7ff71dbe9d2a 16108->16110 16111 7ff71dbeb1cc __free_lconv_mon 11 API calls 16108->16111 16109->16103 16112 7ff71dbeb1cc __free_lconv_mon 11 API calls 16110->16112 16111->16108 16112->16109 16114 7ff71dbd792f 16113->16114 16115 7ff71dbd7937 __std_exception_copy 16114->16115 16116 7ff71dbd7980 WideCharToMultiByte 16114->16116 16118 7ff71dbd79d4 WideCharToMultiByte 16114->16118 16119 7ff71dbd7a26 16114->16119 16115->15903 16116->16114 16116->16119 16118->16114 16118->16119 16378 7ff71dbd2070 16119->16378 16123 7ff71dbf0240 16120->16123 16121 7ff71dbf0293 16122 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16121->16122 16125 7ff71dbf02bc 16122->16125 16123->16121 16124 7ff71dbf02e6 16123->16124 16706 7ff71dbf0118 16124->16706 16125->15905 16128 7ff71dbd1ec5 16127->16128 16130 7ff71dbd1ee0 16128->16130 16714 7ff71dbd1fd0 16128->16714 16130->15951 16131 7ff71dbd3090 16130->16131 16737 7ff71dbdb130 16131->16737 16134 7ff71dbd30e2 16739 7ff71dbd80c0 16134->16739 16135 7ff71dbd30cb 16137 7ff71dbd2070 86 API calls 16135->16137 16139 7ff71dbd30de 16137->16139 16141 7ff71dbdb190 _wfindfirst32i64 8 API calls 16139->16141 16140 7ff71dbd2010 86 API calls 16140->16139 16142 7ff71dbd311f 16141->16142 16142->15911 16144 7ff71dbd6d6a 16143->16144 16145 7ff71dbd7fb0 88 API calls 16144->16145 16146 7ff71dbd6d8c GetEnvironmentVariableW 16145->16146 16147 7ff71dbd6da4 ExpandEnvironmentStringsW 16146->16147 16148 7ff71dbd6df6 16146->16148 16150 7ff71dbd80c0 88 API calls 16147->16150 16149 7ff71dbdb190 _wfindfirst32i64 8 API calls 16148->16149 16151 7ff71dbd6e08 16149->16151 16152 7ff71dbd6dcc 16150->16152 16151->15913 16152->16148 16153 7ff71dbd6dd6 16152->16153 16750 7ff71dbeac5c 16153->16750 16156 7ff71dbdb190 _wfindfirst32i64 8 API calls 16157 7ff71dbd6dee 16156->16157 16157->15913 16159 7ff71dbd7fb0 88 API calls 16158->16159 16160 7ff71dbd7257 SetEnvironmentVariableW 16159->16160 16161 7ff71dbd726f __std_exception_copy 16160->16161 16161->15917 16163 7ff71dbd1cbe 16162->16163 16164 7ff71dbd1ef0 49 API calls 16163->16164 16165 7ff71dbd1cf4 16164->16165 16166 7ff71dbd1ef0 49 API calls 16165->16166 16175 7ff71dbd1dde 16165->16175 16168 7ff71dbd1d1a 16166->16168 16167 7ff71dbdb190 _wfindfirst32i64 8 API calls 16169 7ff71dbd1e6c 16167->16169 16168->16175 16757 7ff71dbd1aa0 16168->16757 16169->15921 16169->15922 16173 7ff71dbd1dcc 16174 7ff71dbd3010 49 API calls 16173->16174 16174->16175 16175->16167 16176 7ff71dbd1d8f 16176->16173 16177 7ff71dbd1e34 16176->16177 16178 7ff71dbd3010 49 API calls 16177->16178 16179 7ff71dbd1e41 16178->16179 16793 7ff71dbd3220 16179->16793 16182 7ff71dbd157f 16181->16182 16183 7ff71dbd1506 16181->16183 16182->15927 16835 7ff71dbd6b50 16183->16835 16186 7ff71dbd2010 86 API calls 16187 7ff71dbd1564 16186->16187 16187->15927 16189 7ff71dbd7fd1 MultiByteToWideChar 16188->16189 16190 7ff71dbd8057 MultiByteToWideChar 16188->16190 16191 7ff71dbd7ff7 16189->16191 16198 7ff71dbd801c 16189->16198 16192 7ff71dbd809f 16190->16192 16193 7ff71dbd807a 16190->16193 16195 7ff71dbd2070 86 API calls 16191->16195 16192->15940 16194 7ff71dbd2070 86 API calls 16193->16194 16196 7ff71dbd808d 16194->16196 16197 7ff71dbd800a 16195->16197 16196->15940 16197->15940 16198->16190 16199 7ff71dbd8032 16198->16199 16200 7ff71dbd2070 86 API calls 16199->16200 16201 7ff71dbd8045 16200->16201 16201->15940 16203 7ff71dbd5ff5 16202->16203 16204 7ff71dbd2d5b 16203->16204 16205 7ff71dbd1fd0 86 API calls 16203->16205 16204->15979 16302 7ff71dbd5c90 16204->16302 16205->16204 16207 7ff71dbd2743 16206->16207 16208 7ff71dbd2784 16206->16208 16207->16208 17369 7ff71dbd1710 16207->17369 17411 7ff71dbd2190 16207->17411 16209 7ff71dbdb190 _wfindfirst32i64 8 API calls 16208->16209 16210 7ff71dbd27d5 16209->16210 16210->15951 16213 7ff71dbd71d0 16210->16213 16214 7ff71dbd7fb0 88 API calls 16213->16214 16215 7ff71dbd71ef 16214->16215 16216 7ff71dbd7fb0 88 API calls 16215->16216 16217 7ff71dbd71ff 16216->16217 16218 7ff71dbe80b0 38 API calls 16217->16218 16219 7ff71dbd720d __std_exception_copy 16218->16219 16219->15968 16221 7ff71dbd7290 16220->16221 16222 7ff71dbd7fb0 88 API calls 16221->16222 16223 7ff71dbd72c1 SetConsoleCtrlHandler GetStartupInfoW 16222->16223 16224 7ff71dbd7322 16223->16224 17894 7ff71dbeacd4 16224->17894 16228 7ff71dbd7331 16264 7ff71dbd202e 16263->16264 16265 7ff71dbd1f50 78 API calls 16264->16265 16266 7ff71dbd204c 16265->16266 16267 7ff71dbd20c0 86 API calls 16266->16267 16268 7ff71dbd205b 16267->16268 16268->15951 16270 7ff71dbd31ac 16269->16270 16271 7ff71dbd7fb0 88 API calls 16270->16271 16272 7ff71dbd31d7 16271->16272 16273 7ff71dbd7fb0 88 API calls 16272->16273 16274 7ff71dbd31ea 16273->16274 17950 7ff71dbe66f8 16274->17950 16277 7ff71dbdb190 _wfindfirst32i64 8 API calls 16278 7ff71dbd2c2b 16277->16278 16278->15938 16279 7ff71dbd74b0 16278->16279 16280 7ff71dbd74d4 16279->16280 16281 7ff71dbdfcd4 73 API calls 16280->16281 16284 7ff71dbd75ab __std_exception_copy 16280->16284 16282 7ff71dbd74ee 16281->16282 16282->16284 18329 7ff71dbe9334 16282->18329 16284->15948 16285 7ff71dbdfcd4 73 API calls 16287 7ff71dbd7503 16285->16287 16286 7ff71dbdf99c _fread_nolock 53 API calls 16286->16287 16287->16284 16287->16285 16287->16286 16289 7ff71dbdf67c 16288->16289 18344 7ff71dbdf428 16289->18344 16291 7ff71dbdf695 16291->15938 16293 7ff71dbd7ac4 GetCurrentProcessId GetWindowThreadProcessId 16292->16293 16294 7ff71dbd2cbd 16292->16294 16293->16294 16295 7ff71dbd7ae3 16293->16295 16294->15928 16295->16294 16296 7ff71dbd7ae9 ShowWindow 16295->16296 16296->16294 16298 7ff71dbd7c14 GetCurrentProcessId GetWindowThreadProcessId 16297->16298 16299 7ff71dbd7c47 16297->16299 16298->16299 16300 7ff71dbd7c33 16298->16300 16299->15928 16300->16299 16301 7ff71dbd7c39 ShowWindow 16300->16301 16301->16299 16303 7ff71dbd5cb3 16302->16303 16304 7ff71dbd5cca 16302->16304 16303->16304 18355 7ff71dbd15a0 16303->18355 16304->15954 16306 7ff71dbd5cd4 16306->16304 16307 7ff71dbd3220 49 API calls 16306->16307 16308 7ff71dbd5d35 16307->16308 16309 7ff71dbd2010 86 API calls 16308->16309 16310 7ff71dbd5da5 __std_exception_copy memcpy_s 16308->16310 16309->16304 16310->15954 16325 7ff71dbd580a memcpy_s 16311->16325 16313 7ff71dbd592f 16315 7ff71dbd3220 49 API calls 16313->16315 16314 7ff71dbd594b 16317 7ff71dbd2010 86 API calls 16314->16317 16316 7ff71dbd59a8 16315->16316 16320 7ff71dbd3220 49 API calls 16316->16320 16321 7ff71dbd5941 __std_exception_copy 16317->16321 16318 7ff71dbd3220 49 API calls 16318->16325 16319 7ff71dbd5910 16319->16313 16322 7ff71dbd3220 49 API calls 16319->16322 16323 7ff71dbd59d8 16320->16323 16324 7ff71dbdb190 _wfindfirst32i64 8 API calls 16321->16324 16322->16313 16327 7ff71dbd3220 49 API calls 16323->16327 16326 7ff71dbd2d81 16324->16326 16325->16313 16325->16314 16325->16318 16325->16319 16325->16325 16328 7ff71dbd1710 140 API calls 16325->16328 16329 7ff71dbd5931 16325->16329 18379 7ff71dbd1950 16325->18379 16326->15962 16331 7ff71dbd5770 16326->16331 16327->16321 16328->16325 16330 7ff71dbd2010 86 API calls 16329->16330 16330->16321 18383 7ff71dbd7460 16331->18383 16333 7ff71dbd578c 16334 7ff71dbd7460 89 API calls 16333->16334 16335 7ff71dbd579f 16334->16335 16336 7ff71dbd57d5 16335->16336 16337 7ff71dbd57b7 16335->16337 16338 7ff71dbd2010 86 API calls 16336->16338 18387 7ff71dbd60f0 GetProcAddress 16337->18387 16340 7ff71dbd2d8f 16338->16340 16340->15962 16340->15972 16342 7ff71dbd5e54 16341->16342 16343 7ff71dbd2010 86 API calls 16342->16343 16346 7ff71dbd5eca 16342->16346 16344 7ff71dbd5eae 16343->16344 16345 7ff71dbd5a40 FreeLibrary 16344->16345 16345->16346 16346->15979 16348 7ff71dbd1f15 16347->16348 16349 7ff71dbe4cc0 49 API calls 16348->16349 16350 7ff71dbd1f38 16349->16350 16350->15969 18446 7ff71dbd4dc0 16351->18446 16354 7ff71dbd26bd 16354->15978 16356 7ff71dbd2694 16356->16354 18515 7ff71dbd4b20 16356->18515 16358 7ff71dbd26a0 16358->16354 16385 7ff71dbd20c0 16378->16385 16386 7ff71dbd20d0 16385->16386 16410 7ff71dbe4cc0 16386->16410 16390 7ff71dbd2130 16443 7ff71dbd1f50 16390->16443 16393 7ff71dbdb190 _wfindfirst32i64 8 API calls 16394 7ff71dbd2097 GetLastError 16393->16394 16395 7ff71dbd77c0 16394->16395 16396 7ff71dbd77cc 16395->16396 16397 7ff71dbd77ed FormatMessageW 16396->16397 16398 7ff71dbd77e7 GetLastError 16396->16398 16399 7ff71dbd7820 16397->16399 16400 7ff71dbd783c WideCharToMultiByte 16397->16400 16398->16397 16401 7ff71dbd2070 83 API calls 16399->16401 16402 7ff71dbd7876 16400->16402 16405 7ff71dbd7833 16400->16405 16401->16405 16403 7ff71dbd2070 83 API calls 16402->16403 16403->16405 16404 7ff71dbdb190 _wfindfirst32i64 8 API calls 16406 7ff71dbd20a4 16404->16406 16405->16404 16407 7ff71dbd1fa0 16406->16407 16408 7ff71dbd20c0 86 API calls 16407->16408 16409 7ff71dbd1fc2 16408->16409 16409->16115 16413 7ff71dbe4d1a 16410->16413 16411 7ff71dbe4d3f 16412 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16411->16412 16427 7ff71dbe4d69 16412->16427 16413->16411 16414 7ff71dbe4d7b 16413->16414 16447 7ff71dbe2704 16414->16447 16416 7ff71dbdb190 _wfindfirst32i64 8 API calls 16419 7ff71dbd2118 16416->16419 16417 7ff71dbeb1cc __free_lconv_mon 11 API calls 16417->16427 16428 7ff71dbd7df0 MultiByteToWideChar 16419->16428 16420 7ff71dbe4e58 16420->16417 16421 7ff71dbe4e2d 16424 7ff71dbeb1cc __free_lconv_mon 11 API calls 16421->16424 16422 7ff71dbe4e7c 16422->16420 16423 7ff71dbe4e86 16422->16423 16426 7ff71dbeb1cc __free_lconv_mon 11 API calls 16423->16426 16424->16427 16425 7ff71dbe4e24 16425->16420 16425->16421 16426->16427 16427->16416 16429 7ff71dbd7e56 16428->16429 16430 7ff71dbd7e3c 16428->16430 16432 7ff71dbd7e85 MultiByteToWideChar 16429->16432 16433 7ff71dbd7e6b 16429->16433 16431 7ff71dbd2070 82 API calls 16430->16431 16442 7ff71dbd7e4f __std_exception_copy 16431->16442 16435 7ff71dbd7ec2 WideCharToMultiByte 16432->16435 16436 7ff71dbd7ea8 16432->16436 16434 7ff71dbd2070 82 API calls 16433->16434 16434->16442 16438 7ff71dbd7ef8 16435->16438 16441 7ff71dbd7eef 16435->16441 16437 7ff71dbd2070 82 API calls 16436->16437 16437->16442 16440 7ff71dbd7f1d WideCharToMultiByte 16438->16440 16438->16441 16439 7ff71dbd2070 82 API calls 16439->16442 16440->16441 16440->16442 16441->16439 16442->16390 16444 7ff71dbd1f76 16443->16444 16691 7ff71dbe4b9c 16444->16691 16446 7ff71dbd1f8c 16446->16393 16448 7ff71dbe2742 16447->16448 16449 7ff71dbe2732 16447->16449 16450 7ff71dbe274b 16448->16450 16457 7ff71dbe2779 16448->16457 16453 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16449->16453 16451 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16450->16451 16452 7ff71dbe2771 16451->16452 16452->16420 16452->16421 16452->16422 16452->16425 16453->16452 16456 7ff71dbe2a28 16459 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16456->16459 16457->16449 16457->16452 16457->16456 16461 7ff71dbe3654 16457->16461 16487 7ff71dbe2ee4 16457->16487 16517 7ff71dbe224c 16457->16517 16520 7ff71dbe4870 16457->16520 16459->16449 16462 7ff71dbe3696 16461->16462 16463 7ff71dbe3709 16461->16463 16464 7ff71dbe3733 16462->16464 16465 7ff71dbe369c 16462->16465 16466 7ff71dbe3763 16463->16466 16467 7ff71dbe370e 16463->16467 16544 7ff71dbe1190 16464->16544 16474 7ff71dbe36a1 16465->16474 16478 7ff71dbe3772 16465->16478 16466->16464 16466->16478 16485 7ff71dbe36cc 16466->16485 16468 7ff71dbe3743 16467->16468 16469 7ff71dbe3710 16467->16469 16551 7ff71dbe0d80 16468->16551 16471 7ff71dbe36b1 16469->16471 16477 7ff71dbe371f 16469->16477 16486 7ff71dbe37a1 16471->16486 16526 7ff71dbe3fb8 16471->16526 16474->16471 16476 7ff71dbe36e4 16474->16476 16474->16485 16476->16486 16536 7ff71dbe4474 16476->16536 16477->16464 16480 7ff71dbe3724 16477->16480 16478->16486 16558 7ff71dbe15a0 16478->16558 16480->16486 16540 7ff71dbe460c 16480->16540 16481 7ff71dbdb190 _wfindfirst32i64 8 API calls 16483 7ff71dbe3a37 16481->16483 16483->16457 16485->16486 16565 7ff71dbef0d8 16485->16565 16486->16481 16488 7ff71dbe2f05 16487->16488 16489 7ff71dbe2eef 16487->16489 16492 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16488->16492 16493 7ff71dbe2f43 16488->16493 16490 7ff71dbe3696 16489->16490 16491 7ff71dbe3709 16489->16491 16489->16493 16494 7ff71dbe3733 16490->16494 16495 7ff71dbe369c 16490->16495 16496 7ff71dbe3763 16491->16496 16497 7ff71dbe370e 16491->16497 16492->16493 16493->16457 16500 7ff71dbe1190 38 API calls 16494->16500 16504 7ff71dbe36a1 16495->16504 16506 7ff71dbe3772 16495->16506 16496->16494 16496->16506 16515 7ff71dbe36cc 16496->16515 16498 7ff71dbe3743 16497->16498 16499 7ff71dbe3710 16497->16499 16502 7ff71dbe0d80 38 API calls 16498->16502 16501 7ff71dbe36b1 16499->16501 16508 7ff71dbe371f 16499->16508 16500->16515 16503 7ff71dbe3fb8 47 API calls 16501->16503 16516 7ff71dbe37a1 16501->16516 16502->16515 16503->16515 16504->16501 16505 7ff71dbe36e4 16504->16505 16504->16515 16509 7ff71dbe4474 47 API calls 16505->16509 16505->16516 16507 7ff71dbe15a0 38 API calls 16506->16507 16506->16516 16507->16515 16508->16494 16510 7ff71dbe3724 16508->16510 16509->16515 16512 7ff71dbe460c 37 API calls 16510->16512 16510->16516 16511 7ff71dbdb190 _wfindfirst32i64 8 API calls 16513 7ff71dbe3a37 16511->16513 16512->16515 16513->16457 16514 7ff71dbef0d8 47 API calls 16514->16515 16515->16514 16515->16516 16516->16511 16650 7ff71dbe0354 16517->16650 16521 7ff71dbe4887 16520->16521 16667 7ff71dbee238 16521->16667 16527 7ff71dbe3fda 16526->16527 16575 7ff71dbe01c0 16527->16575 16531 7ff71dbe4117 16534 7ff71dbe4870 45 API calls 16531->16534 16535 7ff71dbe41a0 16531->16535 16533 7ff71dbe4870 45 API calls 16533->16531 16534->16535 16535->16485 16537 7ff71dbe44f4 16536->16537 16538 7ff71dbe448c 16536->16538 16537->16485 16538->16537 16539 7ff71dbef0d8 47 API calls 16538->16539 16539->16537 16542 7ff71dbe462d 16540->16542 16541 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16543 7ff71dbe465e 16541->16543 16542->16541 16542->16543 16543->16485 16545 7ff71dbe11c3 16544->16545 16546 7ff71dbe11f2 16545->16546 16548 7ff71dbe12af 16545->16548 16547 7ff71dbe01c0 12 API calls 16546->16547 16550 7ff71dbe122f 16546->16550 16547->16550 16549 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16548->16549 16549->16550 16550->16485 16552 7ff71dbe0db3 16551->16552 16553 7ff71dbe0de2 16552->16553 16555 7ff71dbe0e9f 16552->16555 16554 7ff71dbe01c0 12 API calls 16553->16554 16557 7ff71dbe0e1f 16553->16557 16554->16557 16556 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16555->16556 16556->16557 16557->16485 16559 7ff71dbe15d3 16558->16559 16560 7ff71dbe1602 16559->16560 16562 7ff71dbe16bf 16559->16562 16561 7ff71dbe01c0 12 API calls 16560->16561 16564 7ff71dbe163f 16560->16564 16561->16564 16563 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16562->16563 16563->16564 16564->16485 16566 7ff71dbef100 16565->16566 16567 7ff71dbef145 16566->16567 16568 7ff71dbe4870 45 API calls 16566->16568 16570 7ff71dbef12e memcpy_s 16566->16570 16572 7ff71dbef105 memcpy_s 16566->16572 16567->16570 16567->16572 16647 7ff71dbf06b8 16567->16647 16568->16567 16569 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16569->16572 16570->16569 16570->16572 16572->16485 16576 7ff71dbe01f7 16575->16576 16577 7ff71dbe01e6 16575->16577 16576->16577 16578 7ff71dbede7c _fread_nolock 12 API calls 16576->16578 16583 7ff71dbeedf0 16577->16583 16579 7ff71dbe0224 16578->16579 16580 7ff71dbe0238 16579->16580 16581 7ff71dbeb1cc __free_lconv_mon 11 API calls 16579->16581 16582 7ff71dbeb1cc __free_lconv_mon 11 API calls 16580->16582 16581->16580 16582->16577 16584 7ff71dbeee40 16583->16584 16585 7ff71dbeee0d 16583->16585 16584->16585 16587 7ff71dbeee72 16584->16587 16586 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16585->16586 16596 7ff71dbe40f5 16586->16596 16590 7ff71dbeef85 16587->16590 16600 7ff71dbeeeba 16587->16600 16588 7ff71dbef077 16638 7ff71dbee2dc 16588->16638 16590->16588 16591 7ff71dbef03d 16590->16591 16593 7ff71dbef00c 16590->16593 16595 7ff71dbeefcf 16590->16595 16598 7ff71dbeefc5 16590->16598 16631 7ff71dbee674 16591->16631 16624 7ff71dbee954 16593->16624 16614 7ff71dbeeb84 16595->16614 16596->16531 16596->16533 16598->16591 16599 7ff71dbeefca 16598->16599 16599->16593 16599->16595 16600->16596 16605 7ff71dbeacfc 16600->16605 16603 7ff71dbeb184 _wfindfirst32i64 17 API calls 16604 7ff71dbef0d4 16603->16604 16606 7ff71dbead13 16605->16606 16607 7ff71dbead09 16605->16607 16608 7ff71dbe7c48 _get_daylight 11 API calls 16606->16608 16607->16606 16611 7ff71dbead2e 16607->16611 16613 7ff71dbead1a 16608->16613 16609 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 16610 7ff71dbead26 16609->16610 16610->16596 16610->16603 16611->16610 16612 7ff71dbe7c48 _get_daylight 11 API calls 16611->16612 16612->16613 16613->16609 16615 7ff71dbf490c 38 API calls 16614->16615 16616 7ff71dbeebd1 16615->16616 16617 7ff71dbf4354 37 API calls 16616->16617 16618 7ff71dbeec2c 16617->16618 16619 7ff71dbeec81 16618->16619 16622 7ff71dbeec4c 16618->16622 16623 7ff71dbeec30 16618->16623 16620 7ff71dbee770 45 API calls 16619->16620 16620->16623 16621 7ff71dbeea2c 45 API calls 16621->16623 16622->16621 16623->16596 16625 7ff71dbf490c 38 API calls 16624->16625 16626 7ff71dbee99e 16625->16626 16627 7ff71dbf4354 37 API calls 16626->16627 16628 7ff71dbee9ee 16627->16628 16629 7ff71dbee9f2 16628->16629 16630 7ff71dbeea2c 45 API calls 16628->16630 16629->16596 16630->16629 16632 7ff71dbf490c 38 API calls 16631->16632 16633 7ff71dbee6bf 16632->16633 16634 7ff71dbf4354 37 API calls 16633->16634 16635 7ff71dbee717 16634->16635 16636 7ff71dbee71b 16635->16636 16637 7ff71dbee770 45 API calls 16635->16637 16636->16596 16637->16636 16639 7ff71dbee354 16638->16639 16640 7ff71dbee321 16638->16640 16642 7ff71dbee36c 16639->16642 16644 7ff71dbee3ed 16639->16644 16641 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16640->16641 16646 7ff71dbee34d memcpy_s 16641->16646 16643 7ff71dbee674 46 API calls 16642->16643 16643->16646 16645 7ff71dbe4870 45 API calls 16644->16645 16644->16646 16645->16646 16646->16596 16649 7ff71dbf06dc WideCharToMultiByte 16647->16649 16651 7ff71dbe0393 16650->16651 16652 7ff71dbe0381 16650->16652 16655 7ff71dbe03a0 16651->16655 16658 7ff71dbe03dd 16651->16658 16653 7ff71dbe7c48 _get_daylight 11 API calls 16652->16653 16654 7ff71dbe0386 16653->16654 16657 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 16654->16657 16656 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16655->16656 16666 7ff71dbe0391 16656->16666 16657->16666 16659 7ff71dbe0486 16658->16659 16660 7ff71dbe7c48 _get_daylight 11 API calls 16658->16660 16661 7ff71dbe7c48 _get_daylight 11 API calls 16659->16661 16659->16666 16662 7ff71dbe047b 16660->16662 16663 7ff71dbe0530 16661->16663 16664 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 16662->16664 16665 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 16663->16665 16664->16659 16665->16666 16666->16457 16668 7ff71dbee251 16667->16668 16669 7ff71dbe48af 16667->16669 16668->16669 16675 7ff71dbf3b64 16668->16675 16671 7ff71dbee2a4 16669->16671 16672 7ff71dbee2bd 16671->16672 16674 7ff71dbe48bf 16671->16674 16672->16674 16688 7ff71dbf2eb0 16672->16688 16674->16457 16676 7ff71dbeb9d0 __CxxCallCatchBlock 45 API calls 16675->16676 16677 7ff71dbf3b73 16676->16677 16678 7ff71dbf3bbe 16677->16678 16687 7ff71dbf0ea8 EnterCriticalSection 16677->16687 16678->16669 16689 7ff71dbeb9d0 __CxxCallCatchBlock 45 API calls 16688->16689 16690 7ff71dbf2eb9 16689->16690 16692 7ff71dbe4bc6 16691->16692 16693 7ff71dbe4bfe 16692->16693 16695 7ff71dbe4c31 16692->16695 16694 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16693->16694 16697 7ff71dbe4c27 16694->16697 16698 7ff71dbe0180 16695->16698 16697->16446 16705 7ff71dbe556c EnterCriticalSection 16698->16705 16713 7ff71dbe556c EnterCriticalSection 16706->16713 16715 7ff71dbd20c0 86 API calls 16714->16715 16716 7ff71dbd1ff7 16715->16716 16719 7ff71dbe56c0 16716->16719 16720 7ff71dbe56eb 16719->16720 16723 7ff71dbe5584 16720->16723 16736 7ff71dbe85e8 EnterCriticalSection 16723->16736 16738 7ff71dbd309c GetModuleFileNameW 16737->16738 16738->16134 16738->16135 16740 7ff71dbd80e4 WideCharToMultiByte 16739->16740 16741 7ff71dbd8152 WideCharToMultiByte 16739->16741 16743 7ff71dbd8125 16740->16743 16744 7ff71dbd810e 16740->16744 16742 7ff71dbd817f 16741->16742 16746 7ff71dbd30f5 16741->16746 16745 7ff71dbd2070 86 API calls 16742->16745 16743->16741 16748 7ff71dbd813b 16743->16748 16747 7ff71dbd2070 86 API calls 16744->16747 16745->16746 16746->16139 16746->16140 16747->16746 16749 7ff71dbd2070 86 API calls 16748->16749 16749->16746 16751 7ff71dbeac73 16750->16751 16754 7ff71dbd6dde 16750->16754 16752 7ff71dbeacfc __std_exception_copy 37 API calls 16751->16752 16751->16754 16753 7ff71dbeaca0 16752->16753 16753->16754 16755 7ff71dbeb184 _wfindfirst32i64 17 API calls 16753->16755 16754->16156 16756 7ff71dbeacd0 16755->16756 16758 7ff71dbd31a0 120 API calls 16757->16758 16759 7ff71dbd1ad6 16758->16759 16761 7ff71dbd74b0 83 API calls 16759->16761 16766 7ff71dbd1c84 16759->16766 16760 7ff71dbdb190 _wfindfirst32i64 8 API calls 16762 7ff71dbd1c98 16760->16762 16763 7ff71dbd1b0e 16761->16763 16762->16175 16790 7ff71dbd3010 16762->16790 16789 7ff71dbd1b3f 16763->16789 16796 7ff71dbdfcd4 16763->16796 16764 7ff71dbdf64c 74 API calls 16764->16766 16766->16760 16767 7ff71dbd1b28 16768 7ff71dbd1b44 16767->16768 16769 7ff71dbd1b2c 16767->16769 16800 7ff71dbdf99c 16768->16800 16770 7ff71dbd1fd0 86 API calls 16769->16770 16770->16789 16773 7ff71dbd1b5f 16775 7ff71dbd1fd0 86 API calls 16773->16775 16774 7ff71dbd1b77 16776 7ff71dbdfcd4 73 API calls 16774->16776 16775->16789 16777 7ff71dbd1bc4 16776->16777 16778 7ff71dbd1bd6 16777->16778 16779 7ff71dbd1bee 16777->16779 16781 7ff71dbd1fd0 86 API calls 16778->16781 16780 7ff71dbdf99c _fread_nolock 53 API calls 16779->16780 16782 7ff71dbd1c03 16780->16782 16781->16789 16783 7ff71dbd1c1e 16782->16783 16784 7ff71dbd1c09 16782->16784 16803 7ff71dbdf710 16783->16803 16785 7ff71dbd1fd0 86 API calls 16784->16785 16785->16789 16788 7ff71dbd2010 86 API calls 16788->16789 16789->16764 16791 7ff71dbd1ef0 49 API calls 16790->16791 16792 7ff71dbd302d 16791->16792 16792->16176 16794 7ff71dbd1ef0 49 API calls 16793->16794 16795 7ff71dbd3250 16794->16795 16795->16175 16797 7ff71dbdfd04 16796->16797 16809 7ff71dbdfa64 16797->16809 16799 7ff71dbdfd1d 16799->16767 16821 7ff71dbdf9bc 16800->16821 16804 7ff71dbd1c32 16803->16804 16805 7ff71dbdf719 16803->16805 16804->16788 16804->16789 16806 7ff71dbe7c48 _get_daylight 11 API calls 16805->16806 16807 7ff71dbdf71e 16806->16807 16808 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 16807->16808 16808->16804 16810 7ff71dbdface 16809->16810 16811 7ff71dbdfa8e 16809->16811 16810->16811 16813 7ff71dbdfada 16810->16813 16812 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16811->16812 16819 7ff71dbdfab5 16812->16819 16820 7ff71dbe556c EnterCriticalSection 16813->16820 16819->16799 16822 7ff71dbdf9e6 16821->16822 16833 7ff71dbd1b59 16821->16833 16823 7ff71dbdf9f5 memcpy_s 16822->16823 16824 7ff71dbdfa32 16822->16824 16822->16833 16827 7ff71dbe7c48 _get_daylight 11 API calls 16823->16827 16834 7ff71dbe556c EnterCriticalSection 16824->16834 16828 7ff71dbdfa0a 16827->16828 16830 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 16828->16830 16830->16833 16833->16773 16833->16774 16836 7ff71dbd6b66 16835->16836 16837 7ff71dbd6bdd GetTempPathW GetCurrentProcessId 16836->16837 16838 7ff71dbd6b8a 16836->16838 16873 7ff71dbd7760 16837->16873 16840 7ff71dbd6d60 92 API calls 16838->16840 16841 7ff71dbd6b96 16840->16841 16897 7ff71dbd6620 16841->16897 16847 7ff71dbd6bbc __std_exception_copy 16847->16837 16853 7ff71dbd6bca 16847->16853 16848 7ff71dbdb190 _wfindfirst32i64 8 API calls 16851 7ff71dbd154f 16848->16851 16849 7ff71dbd6cb6 16852 7ff71dbd80c0 88 API calls 16849->16852 16850 7ff71dbd6c0b __std_exception_copy 16850->16849 16854 7ff71dbd6c41 16850->16854 16877 7ff71dbe8d68 16850->16877 16880 7ff71dbd7c60 16850->16880 16851->16182 16851->16186 16858 7ff71dbd6cc7 __std_exception_copy 16852->16858 16855 7ff71dbd2010 86 API calls 16853->16855 16857 7ff71dbd7fb0 88 API calls 16854->16857 16872 7ff71dbd6c7a __std_exception_copy 16854->16872 16856 7ff71dbd6bd6 16855->16856 16856->16872 16859 7ff71dbd6c57 16857->16859 16860 7ff71dbd7fb0 88 API calls 16858->16860 16858->16872 16861 7ff71dbd6c5c 16859->16861 16862 7ff71dbd6c99 SetEnvironmentVariableW 16859->16862 16863 7ff71dbd6ce5 16860->16863 16866 7ff71dbd7fb0 88 API calls 16861->16866 16862->16872 16864 7ff71dbd6d1d SetEnvironmentVariableW 16863->16864 16865 7ff71dbd6cea 16863->16865 16864->16872 16867 7ff71dbd7fb0 88 API calls 16865->16867 16868 7ff71dbd6c6c 16866->16868 16869 7ff71dbd6cfa 16867->16869 16870 7ff71dbe80b0 38 API calls 16868->16870 16871 7ff71dbe80b0 38 API calls 16869->16871 16870->16872 16871->16872 16872->16848 16874 7ff71dbd7785 16873->16874 16931 7ff71dbe4f14 16874->16931 17125 7ff71dbe8994 16877->17125 16881 7ff71dbdb130 16880->16881 16882 7ff71dbd7c70 GetCurrentProcess OpenProcessToken 16881->16882 16883 7ff71dbd7d31 __std_exception_copy 16882->16883 16884 7ff71dbd7cbb GetTokenInformation 16882->16884 16887 7ff71dbd7d44 FindCloseChangeNotification 16883->16887 16888 7ff71dbd7d4a 16883->16888 16885 7ff71dbd7cdd GetLastError 16884->16885 16886 7ff71dbd7ce8 16884->16886 16885->16883 16885->16886 16886->16883 16889 7ff71dbd7cfe GetTokenInformation 16886->16889 16887->16888 17256 7ff71dbd78b0 16888->17256 16889->16883 16891 7ff71dbd7d24 ConvertSidToStringSidW 16889->16891 16891->16883 16893 7ff71dbd7da6 CreateDirectoryW 16894 7ff71dbd7dbe 16893->16894 16895 7ff71dbdb190 _wfindfirst32i64 8 API calls 16894->16895 16896 7ff71dbd7dd3 16895->16896 16896->16850 16898 7ff71dbd662c 16897->16898 16899 7ff71dbd7fb0 88 API calls 16898->16899 16900 7ff71dbd664e 16899->16900 16901 7ff71dbd6656 16900->16901 16902 7ff71dbd6669 ExpandEnvironmentStringsW 16900->16902 16903 7ff71dbd2010 86 API calls 16901->16903 16904 7ff71dbd668f __std_exception_copy 16902->16904 16910 7ff71dbd6662 16903->16910 16905 7ff71dbd6693 16904->16905 16906 7ff71dbd66a6 16904->16906 16908 7ff71dbd2010 86 API calls 16905->16908 16911 7ff71dbd66b4 16906->16911 16912 7ff71dbd66c0 16906->16912 16907 7ff71dbdb190 _wfindfirst32i64 8 API calls 16909 7ff71dbd6788 16907->16909 16908->16910 16909->16872 16921 7ff71dbe80b0 16909->16921 16910->16907 17260 7ff71dbe7c68 16911->17260 17267 7ff71dbe6578 16912->17267 16915 7ff71dbd66be 16916 7ff71dbd66da 16915->16916 16919 7ff71dbd66ed memcpy_s 16915->16919 16917 7ff71dbd2010 86 API calls 16916->16917 16917->16910 16918 7ff71dbd6762 CreateDirectoryW 16918->16910 16919->16918 16920 7ff71dbd673c CreateDirectoryW 16919->16920 16920->16919 16922 7ff71dbe80d0 16921->16922 16923 7ff71dbe80bd 16921->16923 17361 7ff71dbe7d34 16922->17361 16924 7ff71dbe7c48 _get_daylight 11 API calls 16923->16924 16926 7ff71dbe80c2 16924->16926 16927 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 16926->16927 16928 7ff71dbe80ce 16927->16928 16928->16847 16935 7ff71dbe4f6e 16931->16935 16932 7ff71dbe4f93 16933 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16932->16933 16937 7ff71dbe4fbd 16933->16937 16934 7ff71dbe4fcf 16949 7ff71dbe2a84 16934->16949 16935->16932 16935->16934 16938 7ff71dbdb190 _wfindfirst32i64 8 API calls 16937->16938 16940 7ff71dbd77a4 16938->16940 16939 7ff71dbeb1cc __free_lconv_mon 11 API calls 16939->16937 16940->16850 16942 7ff71dbe50d6 16944 7ff71dbe50e0 16942->16944 16948 7ff71dbe50b0 16942->16948 16943 7ff71dbe5085 16945 7ff71dbeb1cc __free_lconv_mon 11 API calls 16943->16945 16947 7ff71dbeb1cc __free_lconv_mon 11 API calls 16944->16947 16945->16937 16946 7ff71dbe507c 16946->16943 16946->16948 16947->16937 16948->16939 16950 7ff71dbe2ac2 16949->16950 16951 7ff71dbe2ab2 16949->16951 16952 7ff71dbe2acb 16950->16952 16957 7ff71dbe2af9 16950->16957 16955 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16951->16955 16953 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16952->16953 16954 7ff71dbe2af1 16953->16954 16954->16942 16954->16943 16954->16946 16954->16948 16955->16954 16957->16951 16957->16954 16960 7ff71dbe3a58 16957->16960 16993 7ff71dbe306c 16957->16993 17030 7ff71dbe22dc 16957->17030 16961 7ff71dbe3b0b 16960->16961 16962 7ff71dbe3a9a 16960->16962 16965 7ff71dbe3b64 16961->16965 16966 7ff71dbe3b10 16961->16966 16963 7ff71dbe3b35 16962->16963 16964 7ff71dbe3aa0 16962->16964 17049 7ff71dbe1394 16963->17049 16967 7ff71dbe3ad4 16964->16967 16968 7ff71dbe3aa5 16964->16968 16972 7ff71dbe3b7b 16965->16972 16974 7ff71dbe3b6e 16965->16974 16978 7ff71dbe3b73 16965->16978 16969 7ff71dbe3b45 16966->16969 16970 7ff71dbe3b12 16966->16970 16975 7ff71dbe3aab 16967->16975 16967->16978 16968->16972 16968->16975 17056 7ff71dbe0f84 16969->17056 16973 7ff71dbe3ab4 16970->16973 16982 7ff71dbe3b21 16970->16982 17063 7ff71dbe4760 16972->17063 16991 7ff71dbe3ba4 16973->16991 17033 7ff71dbe420c 16973->17033 16974->16963 16974->16978 16975->16973 16981 7ff71dbe3ae6 16975->16981 16989 7ff71dbe3acf 16975->16989 16978->16991 17067 7ff71dbe17a4 16978->17067 16981->16991 17043 7ff71dbe4548 16981->17043 16982->16963 16984 7ff71dbe3b26 16982->16984 16987 7ff71dbe460c 37 API calls 16984->16987 16984->16991 16985 7ff71dbdb190 _wfindfirst32i64 8 API calls 16986 7ff71dbe3e9e 16985->16986 16986->16957 16987->16989 16988 7ff71dbe4870 45 API calls 16992 7ff71dbe3d90 16988->16992 16989->16988 16989->16991 16989->16992 16991->16985 16992->16991 17074 7ff71dbef288 16992->17074 16994 7ff71dbe3090 16993->16994 16995 7ff71dbe307a 16993->16995 16998 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 16994->16998 16999 7ff71dbe30d0 16994->16999 16996 7ff71dbe3b0b 16995->16996 16997 7ff71dbe3a9a 16995->16997 16995->16999 17002 7ff71dbe3b64 16996->17002 17003 7ff71dbe3b10 16996->17003 17000 7ff71dbe3b35 16997->17000 17001 7ff71dbe3aa0 16997->17001 16998->16999 16999->16957 17008 7ff71dbe1394 38 API calls 17000->17008 17004 7ff71dbe3ad4 17001->17004 17005 7ff71dbe3aa5 17001->17005 17009 7ff71dbe3b7b 17002->17009 17011 7ff71dbe3b6e 17002->17011 17015 7ff71dbe3b73 17002->17015 17006 7ff71dbe3b45 17003->17006 17007 7ff71dbe3b12 17003->17007 17012 7ff71dbe3aab 17004->17012 17004->17015 17005->17009 17005->17012 17013 7ff71dbe0f84 38 API calls 17006->17013 17010 7ff71dbe3ab4 17007->17010 17018 7ff71dbe3b21 17007->17018 17026 7ff71dbe3acf 17008->17026 17016 7ff71dbe4760 45 API calls 17009->17016 17014 7ff71dbe420c 47 API calls 17010->17014 17025 7ff71dbe3ba4 17010->17025 17011->17000 17011->17015 17012->17010 17019 7ff71dbe3ae6 17012->17019 17012->17026 17013->17026 17014->17026 17017 7ff71dbe17a4 38 API calls 17015->17017 17015->17025 17016->17026 17017->17026 17018->17000 17021 7ff71dbe3b26 17018->17021 17020 7ff71dbe4548 46 API calls 17019->17020 17019->17025 17020->17026 17023 7ff71dbe460c 37 API calls 17021->17023 17021->17025 17022 7ff71dbdb190 _wfindfirst32i64 8 API calls 17024 7ff71dbe3e9e 17022->17024 17023->17026 17024->16957 17025->17022 17026->17025 17027 7ff71dbe4870 45 API calls 17026->17027 17029 7ff71dbe3d90 17026->17029 17027->17029 17028 7ff71dbef288 46 API calls 17028->17029 17029->17025 17029->17028 17108 7ff71dbe0608 17030->17108 17034 7ff71dbe4232 17033->17034 17035 7ff71dbe01c0 12 API calls 17034->17035 17036 7ff71dbe4282 17035->17036 17037 7ff71dbeedf0 46 API calls 17036->17037 17039 7ff71dbe4355 17037->17039 17038 7ff71dbe4377 17041 7ff71dbe4870 45 API calls 17038->17041 17042 7ff71dbe4405 17038->17042 17039->17038 17040 7ff71dbe4870 45 API calls 17039->17040 17040->17038 17041->17042 17042->16989 17044 7ff71dbe457d 17043->17044 17045 7ff71dbe459b 17044->17045 17046 7ff71dbe4870 45 API calls 17044->17046 17048 7ff71dbe45c2 17044->17048 17047 7ff71dbef288 46 API calls 17045->17047 17046->17045 17047->17048 17048->16989 17050 7ff71dbe13c7 17049->17050 17051 7ff71dbe13f6 17050->17051 17053 7ff71dbe14b3 17050->17053 17055 7ff71dbe1433 17051->17055 17086 7ff71dbe0268 17051->17086 17054 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 17053->17054 17054->17055 17055->16989 17057 7ff71dbe0fb7 17056->17057 17058 7ff71dbe0fe6 17057->17058 17060 7ff71dbe10a3 17057->17060 17059 7ff71dbe0268 12 API calls 17058->17059 17062 7ff71dbe1023 17058->17062 17059->17062 17061 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 17060->17061 17061->17062 17062->16989 17064 7ff71dbe47a3 17063->17064 17066 7ff71dbe47a7 __crtLCMapStringW 17064->17066 17094 7ff71dbe47fc 17064->17094 17066->16989 17068 7ff71dbe17d7 17067->17068 17069 7ff71dbe1806 17068->17069 17071 7ff71dbe18c3 17068->17071 17070 7ff71dbe0268 12 API calls 17069->17070 17073 7ff71dbe1843 17069->17073 17070->17073 17072 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 17071->17072 17072->17073 17073->16989 17075 7ff71dbef2b9 17074->17075 17083 7ff71dbef2c7 17074->17083 17076 7ff71dbef2e7 17075->17076 17077 7ff71dbe4870 45 API calls 17075->17077 17075->17083 17078 7ff71dbef31f 17076->17078 17079 7ff71dbef2f8 17076->17079 17077->17076 17081 7ff71dbef349 17078->17081 17082 7ff71dbef3aa 17078->17082 17078->17083 17098 7ff71dbf0c70 17079->17098 17081->17083 17101 7ff71dbefdf0 17081->17101 17084 7ff71dbefdf0 _fread_nolock MultiByteToWideChar 17082->17084 17083->16992 17084->17083 17087 7ff71dbe029f 17086->17087 17088 7ff71dbe028e 17086->17088 17087->17088 17089 7ff71dbede7c _fread_nolock 12 API calls 17087->17089 17088->17055 17090 7ff71dbe02d0 17089->17090 17091 7ff71dbe02e4 17090->17091 17092 7ff71dbeb1cc __free_lconv_mon 11 API calls 17090->17092 17093 7ff71dbeb1cc __free_lconv_mon 11 API calls 17091->17093 17092->17091 17093->17088 17095 7ff71dbe481a 17094->17095 17097 7ff71dbe4822 17094->17097 17096 7ff71dbe4870 45 API calls 17095->17096 17096->17097 17097->17066 17104 7ff71dbf78d0 17098->17104 17103 7ff71dbefdf9 MultiByteToWideChar 17101->17103 17107 7ff71dbf7934 17104->17107 17105 7ff71dbdb190 _wfindfirst32i64 8 API calls 17106 7ff71dbf0c8d 17105->17106 17106->17083 17107->17105 17109 7ff71dbe064f 17108->17109 17110 7ff71dbe063d 17108->17110 17112 7ff71dbe065d 17109->17112 17116 7ff71dbe0699 17109->17116 17111 7ff71dbe7c48 _get_daylight 11 API calls 17110->17111 17113 7ff71dbe0642 17111->17113 17114 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 17112->17114 17115 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17113->17115 17122 7ff71dbe064d 17114->17122 17115->17122 17117 7ff71dbe0a15 17116->17117 17119 7ff71dbe7c48 _get_daylight 11 API calls 17116->17119 17118 7ff71dbe7c48 _get_daylight 11 API calls 17117->17118 17117->17122 17120 7ff71dbe0ca9 17118->17120 17121 7ff71dbe0a0a 17119->17121 17123 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17120->17123 17124 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17121->17124 17122->16957 17123->17122 17124->17117 17166 7ff71dbf1db8 17125->17166 17225 7ff71dbf1b30 17166->17225 17246 7ff71dbf0ea8 EnterCriticalSection 17225->17246 17257 7ff71dbd78d5 17256->17257 17258 7ff71dbe4f14 48 API calls 17257->17258 17259 7ff71dbd78f8 LocalFree ConvertStringSecurityDescriptorToSecurityDescriptorW 17258->17259 17259->16893 17259->16894 17261 7ff71dbe7c86 17260->17261 17264 7ff71dbe7cb9 17260->17264 17262 7ff71dbf1044 _wfindfirst32i64 37 API calls 17261->17262 17261->17264 17263 7ff71dbe7cb5 17262->17263 17263->17264 17265 7ff71dbeb184 _wfindfirst32i64 17 API calls 17263->17265 17264->16915 17266 7ff71dbe7ce9 17265->17266 17268 7ff71dbe6594 17267->17268 17269 7ff71dbe6602 17267->17269 17268->17269 17270 7ff71dbe6599 17268->17270 17304 7ff71dbf0690 17269->17304 17272 7ff71dbe65b1 17270->17272 17273 7ff71dbe65ce 17270->17273 17279 7ff71dbe6348 GetFullPathNameW 17272->17279 17287 7ff71dbe63bc GetFullPathNameW 17273->17287 17278 7ff71dbe65c6 __std_exception_copy 17278->16915 17280 7ff71dbe636e GetLastError 17279->17280 17283 7ff71dbe6384 17279->17283 17281 7ff71dbe7bbc _fread_nolock 11 API calls 17280->17281 17282 7ff71dbe637b 17281->17282 17284 7ff71dbe7c48 _get_daylight 11 API calls 17282->17284 17285 7ff71dbe7c48 _get_daylight 11 API calls 17283->17285 17286 7ff71dbe6380 17283->17286 17284->17286 17285->17286 17286->17278 17288 7ff71dbe63ef GetLastError 17287->17288 17293 7ff71dbe6405 __std_exception_copy 17287->17293 17289 7ff71dbe7bbc _fread_nolock 11 API calls 17288->17289 17290 7ff71dbe63fc 17289->17290 17291 7ff71dbe7c48 _get_daylight 11 API calls 17290->17291 17292 7ff71dbe6401 17291->17292 17295 7ff71dbe6494 17292->17295 17293->17292 17294 7ff71dbe645f GetFullPathNameW 17293->17294 17294->17288 17294->17292 17299 7ff71dbe6508 memcpy_s 17295->17299 17300 7ff71dbe64bd memcpy_s 17295->17300 17296 7ff71dbe64f1 17297 7ff71dbe7c48 _get_daylight 11 API calls 17296->17297 17298 7ff71dbe64f6 17297->17298 17301 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17298->17301 17299->17278 17300->17296 17300->17299 17302 7ff71dbe652a 17300->17302 17301->17299 17302->17299 17303 7ff71dbe7c48 _get_daylight 11 API calls 17302->17303 17303->17298 17307 7ff71dbf04a0 17304->17307 17308 7ff71dbf04e2 17307->17308 17309 7ff71dbf04cb 17307->17309 17311 7ff71dbf04e6 17308->17311 17312 7ff71dbf0507 17308->17312 17310 7ff71dbe7c48 _get_daylight 11 API calls 17309->17310 17314 7ff71dbf04d0 17310->17314 17333 7ff71dbf060c 17311->17333 17345 7ff71dbefb08 17312->17345 17319 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17314->17319 17316 7ff71dbf050c 17322 7ff71dbf05b1 17316->17322 17328 7ff71dbf0533 17316->17328 17318 7ff71dbf04ef 17320 7ff71dbe7c28 _fread_nolock 11 API calls 17318->17320 17332 7ff71dbf04db __std_exception_copy 17319->17332 17321 7ff71dbf04f4 17320->17321 17324 7ff71dbe7c48 _get_daylight 11 API calls 17321->17324 17322->17309 17325 7ff71dbf05b9 17322->17325 17323 7ff71dbdb190 _wfindfirst32i64 8 API calls 17326 7ff71dbf0601 17323->17326 17324->17314 17327 7ff71dbe6348 13 API calls 17325->17327 17326->17278 17327->17332 17329 7ff71dbe63bc 14 API calls 17328->17329 17330 7ff71dbf0577 17329->17330 17331 7ff71dbe6494 37 API calls 17330->17331 17330->17332 17331->17332 17332->17323 17334 7ff71dbf0656 17333->17334 17335 7ff71dbf0626 17333->17335 17336 7ff71dbf0661 GetDriveTypeW 17334->17336 17338 7ff71dbf0641 17334->17338 17337 7ff71dbe7c28 _fread_nolock 11 API calls 17335->17337 17336->17338 17339 7ff71dbf062b 17337->17339 17340 7ff71dbdb190 _wfindfirst32i64 8 API calls 17338->17340 17341 7ff71dbe7c48 _get_daylight 11 API calls 17339->17341 17342 7ff71dbf04eb 17340->17342 17343 7ff71dbf0636 17341->17343 17342->17316 17342->17318 17344 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17343->17344 17344->17338 17359 7ff71dbdc8b0 17345->17359 17348 7ff71dbefb55 17352 7ff71dbdb190 _wfindfirst32i64 8 API calls 17348->17352 17349 7ff71dbefb7c 17350 7ff71dbef430 _get_daylight 11 API calls 17349->17350 17351 7ff71dbefb8b 17350->17351 17353 7ff71dbefb95 GetCurrentDirectoryW 17351->17353 17354 7ff71dbefba4 17351->17354 17355 7ff71dbefbe9 17352->17355 17353->17354 17356 7ff71dbefba9 17353->17356 17357 7ff71dbe7c48 _get_daylight 11 API calls 17354->17357 17355->17316 17358 7ff71dbeb1cc __free_lconv_mon 11 API calls 17356->17358 17357->17356 17358->17348 17360 7ff71dbdc890 GetCurrentDirectoryW 17359->17360 17360->17348 17360->17349 17368 7ff71dbf0ea8 EnterCriticalSection 17361->17368 17370 7ff71dbd1726 17369->17370 17371 7ff71dbd173e 17369->17371 17372 7ff71dbd2010 86 API calls 17370->17372 17373 7ff71dbd1744 17371->17373 17374 7ff71dbd1768 17371->17374 17375 7ff71dbd1732 17372->17375 17501 7ff71dbd12b0 17373->17501 17462 7ff71dbd6e10 17374->17462 17375->16207 17380 7ff71dbd178d 17383 7ff71dbd1fd0 86 API calls 17380->17383 17381 7ff71dbd17b9 17384 7ff71dbd31a0 120 API calls 17381->17384 17382 7ff71dbd175f 17382->16207 17386 7ff71dbd17a3 17383->17386 17387 7ff71dbd17ce 17384->17387 17385 7ff71dbd2010 86 API calls 17385->17382 17386->16207 17388 7ff71dbd17d6 17387->17388 17389 7ff71dbd17ee 17387->17389 17390 7ff71dbd2010 86 API calls 17388->17390 17391 7ff71dbdfcd4 73 API calls 17389->17391 17392 7ff71dbd17e5 17390->17392 17393 7ff71dbd17ff 17391->17393 17398 7ff71dbdf64c 74 API calls 17392->17398 17394 7ff71dbd1823 17393->17394 17395 7ff71dbd1803 17393->17395 17396 7ff71dbd1829 17394->17396 17401 7ff71dbd1841 17394->17401 17397 7ff71dbd1fd0 86 API calls 17395->17397 17481 7ff71dbd1050 17396->17481 17405 7ff71dbd1819 __std_exception_copy 17397->17405 17399 7ff71dbd1937 17398->17399 17399->16207 17402 7ff71dbd1863 17401->17402 17409 7ff71dbd1882 17401->17409 17404 7ff71dbd1fd0 86 API calls 17402->17404 17403 7ff71dbdf64c 74 API calls 17403->17392 17404->17405 17405->17403 17406 7ff71dbdf99c _fread_nolock 53 API calls 17406->17409 17407 7ff71dbd18e5 17410 7ff71dbd1fd0 86 API calls 17407->17410 17409->17405 17409->17406 17409->17407 17540 7ff71dbe00dc 17409->17540 17410->17405 17412 7ff71dbd21a6 17411->17412 17413 7ff71dbd1ef0 49 API calls 17412->17413 17414 7ff71dbd21d9 17413->17414 17415 7ff71dbd3010 49 API calls 17414->17415 17461 7ff71dbd250a 17414->17461 17416 7ff71dbd2247 17415->17416 17417 7ff71dbd3010 49 API calls 17416->17417 17418 7ff71dbd2258 17417->17418 17419 7ff71dbd22b5 17418->17419 17420 7ff71dbd2279 17418->17420 17421 7ff71dbd25d0 75 API calls 17419->17421 17627 7ff71dbd25d0 17420->17627 17423 7ff71dbd22b3 17421->17423 17424 7ff71dbd22f4 17423->17424 17425 7ff71dbd2336 17423->17425 17635 7ff71dbd67a0 17424->17635 17427 7ff71dbd25d0 75 API calls 17425->17427 17430 7ff71dbd2360 17427->17430 17429 7ff71dbd2317 17432 7ff71dbd25d0 75 API calls 17430->17432 17439 7ff71dbd23fc 17430->17439 17435 7ff71dbd2392 17432->17435 17433 7ff71dbd2591 17438 7ff71dbd2010 86 API calls 17433->17438 17434 7ff71dbd2331 17441 7ff71dbdb190 _wfindfirst32i64 8 API calls 17434->17441 17435->17439 17440 7ff71dbd25d0 75 API calls 17435->17440 17436 7ff71dbd1eb0 86 API calls 17437 7ff71dbd244f 17436->17437 17443 7ff71dbd1ef0 49 API calls 17437->17443 17437->17461 17438->17461 17439->17436 17454 7ff71dbd250f 17439->17454 17442 7ff71dbd23c0 17440->17442 17444 7ff71dbd23f1 17441->17444 17442->17439 17445 7ff71dbd23c4 17442->17445 17446 7ff71dbd2477 17443->17446 17444->16207 17447 7ff71dbd2010 86 API calls 17445->17447 17446->17433 17448 7ff71dbd1ef0 49 API calls 17446->17448 17447->17434 17450 7ff71dbd24a4 17448->17450 17449 7ff71dbd2010 86 API calls 17452 7ff71dbd2568 17449->17452 17450->17433 17453 7ff71dbd1ef0 49 API calls 17450->17453 17452->17433 17452->17449 17455 7ff71dbd1710 140 API calls 17452->17455 17456 7ff71dbd24d1 17453->17456 17454->17452 17672 7ff71dbe526c 17454->17672 17455->17452 17456->17433 17457 7ff71dbd1aa0 121 API calls 17456->17457 17463 7ff71dbd6e20 17462->17463 17464 7ff71dbd1ef0 49 API calls 17463->17464 17465 7ff71dbd6e61 17464->17465 17480 7ff71dbd6ee1 17465->17480 17544 7ff71dbd3130 17465->17544 17467 7ff71dbdb190 _wfindfirst32i64 8 API calls 17469 7ff71dbd1785 17467->17469 17469->17380 17469->17381 17470 7ff71dbd6f1b 17550 7ff71dbd69c0 17470->17550 17472 7ff71dbd6d60 92 API calls 17477 7ff71dbd6e92 __std_exception_copy 17472->17477 17474 7ff71dbd6ed0 17478 7ff71dbd2010 86 API calls 17474->17478 17475 7ff71dbd6f04 17476 7ff71dbd2010 86 API calls 17475->17476 17476->17470 17477->17474 17477->17475 17478->17480 17479 7ff71dbd31a0 120 API calls 17479->17480 17480->17467 17482 7ff71dbd10a6 17481->17482 17483 7ff71dbd10d3 17482->17483 17484 7ff71dbd10ad 17482->17484 17487 7ff71dbd10ed 17483->17487 17488 7ff71dbd1109 17483->17488 17485 7ff71dbd2010 86 API calls 17484->17485 17486 7ff71dbd10c0 17485->17486 17486->17405 17489 7ff71dbd1fd0 86 API calls 17487->17489 17490 7ff71dbd111b 17488->17490 17500 7ff71dbd1137 memcpy_s 17488->17500 17494 7ff71dbd1104 17489->17494 17491 7ff71dbd1fd0 86 API calls 17490->17491 17491->17494 17493 7ff71dbdf99c _fread_nolock 53 API calls 17493->17500 17495 7ff71dbdf710 37 API calls 17495->17500 17497 7ff71dbd11fe 17499 7ff71dbe00dc 76 API calls 17499->17500 17500->17493 17500->17494 17500->17495 17500->17497 17500->17499 17502 7ff71dbd12c2 17501->17502 17503 7ff71dbd31a0 120 API calls 17502->17503 17504 7ff71dbd12f2 17503->17504 17505 7ff71dbd1311 17504->17505 17506 7ff71dbd12fa 17504->17506 17508 7ff71dbdfcd4 73 API calls 17505->17508 17507 7ff71dbd2010 86 API calls 17506->17507 17513 7ff71dbd130a __std_exception_copy 17507->17513 17509 7ff71dbd1323 17508->17509 17510 7ff71dbd134d 17509->17510 17511 7ff71dbd1327 17509->17511 17516 7ff71dbd1390 17510->17516 17517 7ff71dbd1368 17510->17517 17512 7ff71dbd1fd0 86 API calls 17511->17512 17514 7ff71dbd133e 17512->17514 17518 7ff71dbdb190 _wfindfirst32i64 8 API calls 17513->17518 17515 7ff71dbdf64c 74 API calls 17514->17515 17515->17513 17520 7ff71dbd13aa 17516->17520 17532 7ff71dbd1463 17516->17532 17519 7ff71dbd1fd0 86 API calls 17517->17519 17521 7ff71dbd1454 17518->17521 17523 7ff71dbd1383 17519->17523 17524 7ff71dbd1050 94 API calls 17520->17524 17521->17382 17521->17385 17522 7ff71dbd13c3 17527 7ff71dbdf64c 74 API calls 17522->17527 17525 7ff71dbdf64c 74 API calls 17523->17525 17526 7ff71dbd13bb 17524->17526 17525->17513 17526->17522 17530 7ff71dbd14d2 __std_exception_copy 17526->17530 17528 7ff71dbd13cf 17527->17528 17531 7ff71dbd69c0 102 API calls 17528->17531 17529 7ff71dbdf99c _fread_nolock 53 API calls 17529->17532 17536 7ff71dbdf64c 74 API calls 17530->17536 17533 7ff71dbd13de 17531->17533 17532->17522 17532->17529 17534 7ff71dbd14bb 17532->17534 17533->17513 17537 7ff71dbd1ef0 49 API calls 17533->17537 17535 7ff71dbd1fd0 86 API calls 17534->17535 17535->17530 17536->17513 17538 7ff71dbd140c 17537->17538 17538->17513 17598 7ff71dbd3340 17538->17598 17541 7ff71dbe010c 17540->17541 17612 7ff71dbdfe2c 17541->17612 17543 7ff71dbe012a 17543->17409 17545 7ff71dbd313a 17544->17545 17546 7ff71dbd7fb0 88 API calls 17545->17546 17547 7ff71dbd3162 17546->17547 17548 7ff71dbdb190 _wfindfirst32i64 8 API calls 17547->17548 17549 7ff71dbd318a 17548->17549 17549->17470 17549->17472 17549->17477 17551 7ff71dbd69d0 17550->17551 17552 7ff71dbd1ef0 49 API calls 17551->17552 17553 7ff71dbd6a01 17552->17553 17554 7ff71dbd1ef0 49 API calls 17553->17554 17559 7ff71dbd6b19 17553->17559 17556 7ff71dbd6a28 17554->17556 17555 7ff71dbdb190 _wfindfirst32i64 8 API calls 17557 7ff71dbd6b2e 17555->17557 17556->17559 17564 7ff71dbe6318 17556->17564 17557->17479 17557->17480 17559->17555 17565 7ff71dbeb9d0 __CxxCallCatchBlock 45 API calls 17564->17565 17567 7ff71dbe632d 17565->17567 17566 7ff71dbf0497 17567->17566 17570 7ff71dbf03b6 17567->17570 17599 7ff71dbd3350 17598->17599 17600 7ff71dbd7fb0 88 API calls 17599->17600 17601 7ff71dbd337e 17600->17601 17613 7ff71dbdfe4c 17612->17613 17614 7ff71dbdfe79 17612->17614 17613->17614 17615 7ff71dbdfe56 17613->17615 17616 7ff71dbdfe81 17613->17616 17614->17543 17628 7ff71dbd2604 17627->17628 17629 7ff71dbe4cc0 49 API calls 17628->17629 17630 7ff71dbd262a 17629->17630 17631 7ff71dbd263b 17630->17631 17687 7ff71dbe5fb4 17630->17687 17633 7ff71dbdb190 _wfindfirst32i64 8 API calls 17631->17633 17634 7ff71dbd2659 17633->17634 17634->17423 17636 7ff71dbd67ae 17635->17636 17637 7ff71dbd31a0 120 API calls 17636->17637 17638 7ff71dbd67dd 17637->17638 17639 7ff71dbd1ef0 49 API calls 17638->17639 17640 7ff71dbd6806 17639->17640 17641 7ff71dbd680d 17640->17641 17642 7ff71dbd3130 88 API calls 17640->17642 17643 7ff71dbd6989 17641->17643 17646 7ff71dbd68e9 17641->17646 17644 7ff71dbd6820 17642->17644 17645 7ff71dbd6985 17643->17645 17648 7ff71dbdf64c 74 API calls 17643->17648 17647 7ff71dbd68a4 17644->17647 17655 7ff71dbd6d60 92 API calls 17644->17655 17660 7ff71dbd683e __std_exception_copy 17644->17660 17653 7ff71dbdb190 _wfindfirst32i64 8 API calls 17645->17653 17868 7ff71dbdf6e4 17646->17868 17650 7ff71dbd69c0 102 API calls 17647->17650 17648->17645 17654 7ff71dbd68af 17650->17654 17651 7ff71dbd688d 17659 7ff71dbd2010 86 API calls 17651->17659 17652 7ff71dbd6877 17656 7ff71dbd2010 86 API calls 17652->17656 17658 7ff71dbd230e 17653->17658 17654->17641 17662 7ff71dbd31a0 120 API calls 17654->17662 17655->17660 17656->17641 17657 7ff71dbd6966 17658->17429 17658->17433 17659->17647 17660->17651 17660->17652 17662->17641 17663 7ff71dbdf99c _fread_nolock 53 API calls 17670 7ff71dbd68ee 17663->17670 17666 7ff71dbe00dc 76 API calls 17666->17670 17667 7ff71dbd692c 17668 7ff71dbdf710 37 API calls 17668->17670 17669 7ff71dbdf6e4 37 API calls 17669->17670 17670->17657 17670->17663 17670->17666 17670->17667 17670->17668 17670->17669 17673 7ff71dbe52a6 17672->17673 17674 7ff71dbe5279 17672->17674 17676 7ff71dbe52c9 17673->17676 17677 7ff71dbe52e5 17673->17677 17675 7ff71dbe7c48 _get_daylight 11 API calls 17674->17675 17684 7ff71dbe5230 17674->17684 17678 7ff71dbe5283 17675->17678 17679 7ff71dbe7c48 _get_daylight 11 API calls 17676->17679 17680 7ff71dbe5194 45 API calls 17677->17680 17681 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17678->17681 17682 7ff71dbe52ce 17679->17682 17686 7ff71dbe52d9 17680->17686 17683 7ff71dbe528e 17681->17683 17685 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17682->17685 17683->17454 17684->17454 17685->17686 17686->17454 17688 7ff71dbe5fd1 17687->17688 17689 7ff71dbe5fdd 17687->17689 17704 7ff71dbe58c8 17688->17704 17729 7ff71dbe5194 17689->17729 17694 7ff71dbe6015 17740 7ff71dbe574c 17694->17740 17697 7ff71dbe6085 17700 7ff71dbe58c8 69 API calls 17697->17700 17698 7ff71dbe6071 17699 7ff71dbe5fd6 17698->17699 17702 7ff71dbeb1cc __free_lconv_mon 11 API calls 17698->17702 17699->17631 17701 7ff71dbe6091 17700->17701 17701->17699 17702->17699 17705 7ff71dbe58ff 17704->17705 17706 7ff71dbe58e2 17704->17706 17705->17706 17708 7ff71dbe5912 CreateFileW 17705->17708 17707 7ff71dbe7c28 _fread_nolock 11 API calls 17706->17707 17709 7ff71dbe58e7 17707->17709 17710 7ff71dbe5946 17708->17710 17711 7ff71dbe597c 17708->17711 17714 7ff71dbe7c48 _get_daylight 11 API calls 17709->17714 17762 7ff71dbe5a1c GetFileType 17710->17762 17788 7ff71dbe5ea4 17711->17788 17717 7ff71dbe58ef 17714->17717 17722 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17717->17722 17723 7ff71dbe58fa 17722->17723 17723->17699 17730 7ff71dbe51b3 17729->17730 17731 7ff71dbe51b8 17729->17731 17730->17694 17737 7ff71dbef6bc 17730->17737 17731->17730 17732 7ff71dbeb9d0 __CxxCallCatchBlock 45 API calls 17731->17732 17733 7ff71dbe51d3 17732->17733 17850 7ff71dbee204 17733->17850 17858 7ff71dbef4a8 17737->17858 17741 7ff71dbe5776 17740->17741 17742 7ff71dbe579a 17740->17742 17746 7ff71dbeb1cc __free_lconv_mon 11 API calls 17741->17746 17747 7ff71dbe5785 17741->17747 17743 7ff71dbe57f4 17742->17743 17744 7ff71dbe579f 17742->17744 17745 7ff71dbefdf0 _fread_nolock MultiByteToWideChar 17743->17745 17744->17747 17748 7ff71dbe57b4 17744->17748 17751 7ff71dbeb1cc __free_lconv_mon 11 API calls 17744->17751 17749 7ff71dbe5810 17745->17749 17746->17747 17747->17697 17747->17698 17752 7ff71dbede7c _fread_nolock 12 API calls 17748->17752 17750 7ff71dbe5817 GetLastError 17749->17750 17755 7ff71dbe5845 17749->17755 17758 7ff71dbeb1cc __free_lconv_mon 11 API calls 17749->17758 17761 7ff71dbe5852 17749->17761 17751->17748 17752->17747 17758->17755 17761->17747 17763 7ff71dbe5b27 17762->17763 17764 7ff71dbe5a6a 17762->17764 17765 7ff71dbe5b2f 17763->17765 17766 7ff71dbe5b51 17763->17766 17767 7ff71dbe5a96 GetFileInformationByHandle 17764->17767 17768 7ff71dbe5da0 21 API calls 17764->17768 17769 7ff71dbe5b33 17765->17769 17770 7ff71dbe5b42 GetLastError 17765->17770 17772 7ff71dbe5b74 PeekNamedPipe 17766->17772 17778 7ff71dbe5b12 17766->17778 17767->17770 17771 7ff71dbe5abf 17767->17771 17777 7ff71dbe5a84 17768->17777 17773 7ff71dbe7c48 _get_daylight 11 API calls 17769->17773 17775 7ff71dbe7bbc _fread_nolock 11 API calls 17770->17775 17774 7ff71dbe5c64 51 API calls 17771->17774 17772->17778 17773->17778 17775->17778 17776 7ff71dbdb190 _wfindfirst32i64 8 API calls 17777->17767 17777->17778 17778->17776 17789 7ff71dbe5eda 17788->17789 17790 7ff71dbe5f72 __std_exception_copy 17789->17790 17791 7ff71dbe7c48 _get_daylight 11 API calls 17789->17791 17792 7ff71dbdb190 _wfindfirst32i64 8 API calls 17790->17792 17793 7ff71dbe5eec 17791->17793 17795 7ff71dbe5981 17792->17795 17794 7ff71dbe7c48 _get_daylight 11 API calls 17793->17794 17851 7ff71dbee219 17850->17851 17853 7ff71dbe51f6 17850->17853 17852 7ff71dbf3b64 45 API calls 17851->17852 17851->17853 17852->17853 17854 7ff71dbee270 17853->17854 17855 7ff71dbee285 17854->17855 17856 7ff71dbee298 17854->17856 17855->17856 17857 7ff71dbf2eb0 45 API calls 17855->17857 17856->17730 17857->17856 17859 7ff71dbef505 17858->17859 17866 7ff71dbef500 __vcrt_FlsAlloc 17858->17866 17859->17694 17860 7ff71dbef535 LoadLibraryW 17862 7ff71dbef60a 17860->17862 17863 7ff71dbef55a GetLastError 17860->17863 17861 7ff71dbef62a GetProcAddress 17861->17859 17865 7ff71dbef63b 17861->17865 17862->17861 17864 7ff71dbef621 FreeLibrary 17862->17864 17863->17866 17864->17861 17865->17859 17866->17859 17866->17860 17866->17861 17867 7ff71dbef594 LoadLibraryExW 17866->17867 17867->17862 17867->17866 17869 7ff71dbdf6ed 17868->17869 17873 7ff71dbdf6fd 17868->17873 17870 7ff71dbe7c48 _get_daylight 11 API calls 17869->17870 17871 7ff71dbdf6f2 17870->17871 17873->17670 17895 7ff71dbd732a 17894->17895 17896 7ff71dbeacdd 17894->17896 17900 7ff71dbe88f4 17895->17900 17897 7ff71dbe7c48 _get_daylight 11 API calls 17896->17897 17898 7ff71dbeace2 17897->17898 17899 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17898->17899 17899->17895 17901 7ff71dbe8912 17900->17901 17902 7ff71dbe88fd 17900->17902 17905 7ff71dbe7c28 _fread_nolock 11 API calls 17901->17905 17908 7ff71dbe890a 17901->17908 17903 7ff71dbe7c28 _fread_nolock 11 API calls 17902->17903 17904 7ff71dbe8902 17903->17904 17907 7ff71dbe894d 17905->17907 17908->16228 17952 7ff71dbe662c 17950->17952 17951 7ff71dbe6652 17953 7ff71dbe7c48 _get_daylight 11 API calls 17951->17953 17952->17951 17955 7ff71dbe6685 17952->17955 17954 7ff71dbe6657 17953->17954 17956 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 17954->17956 17957 7ff71dbe668b 17955->17957 17958 7ff71dbe6698 17955->17958 17959 7ff71dbd31f9 17956->17959 17960 7ff71dbe7c48 _get_daylight 11 API calls 17957->17960 17969 7ff71dbeb4ac 17958->17969 17959->16277 17960->17959 17982 7ff71dbf0ea8 EnterCriticalSection 17969->17982 18330 7ff71dbe9364 18329->18330 18333 7ff71dbe8e40 18330->18333 18332 7ff71dbe937d 18332->16287 18334 7ff71dbe8e5b 18333->18334 18335 7ff71dbe8e8a 18333->18335 18337 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 18334->18337 18343 7ff71dbe556c EnterCriticalSection 18335->18343 18338 7ff71dbe8e7b 18337->18338 18338->18332 18345 7ff71dbdf443 18344->18345 18346 7ff71dbdf471 18344->18346 18347 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 18345->18347 18348 7ff71dbdf463 18346->18348 18354 7ff71dbe556c EnterCriticalSection 18346->18354 18347->18348 18348->16291 18356 7ff71dbd31a0 120 API calls 18355->18356 18357 7ff71dbd15c7 18356->18357 18358 7ff71dbd15cf 18357->18358 18359 7ff71dbd15f0 18357->18359 18360 7ff71dbd2010 86 API calls 18358->18360 18361 7ff71dbdfcd4 73 API calls 18359->18361 18362 7ff71dbd15df 18360->18362 18363 7ff71dbd1601 18361->18363 18362->16306 18364 7ff71dbd1605 18363->18364 18365 7ff71dbd1621 18363->18365 18366 7ff71dbd1fd0 86 API calls 18364->18366 18367 7ff71dbd1651 18365->18367 18368 7ff71dbd1631 18365->18368 18376 7ff71dbd161c __std_exception_copy 18366->18376 18369 7ff71dbd1666 18367->18369 18375 7ff71dbd167d 18367->18375 18371 7ff71dbd1fd0 86 API calls 18368->18371 18372 7ff71dbd1050 94 API calls 18369->18372 18370 7ff71dbdf64c 74 API calls 18373 7ff71dbd16f7 18370->18373 18371->18376 18372->18376 18373->16306 18374 7ff71dbdf99c _fread_nolock 53 API calls 18374->18375 18375->18374 18375->18376 18377 7ff71dbd16be 18375->18377 18376->18370 18378 7ff71dbd1fd0 86 API calls 18377->18378 18378->18376 18381 7ff71dbd19d3 18379->18381 18382 7ff71dbd196f 18379->18382 18380 7ff71dbe526c 45 API calls 18380->18382 18381->16325 18382->18380 18382->18381 18384 7ff71dbd7fb0 88 API calls 18383->18384 18385 7ff71dbd7477 LoadLibraryExW 18384->18385 18386 7ff71dbd7494 __std_exception_copy 18385->18386 18386->16333 18388 7ff71dbd613c GetProcAddress 18387->18388 18389 7ff71dbd6119 18387->18389 18388->18389 18390 7ff71dbd6161 GetProcAddress 18388->18390 18391 7ff71dbd2070 86 API calls 18389->18391 18390->18389 18392 7ff71dbd6186 GetProcAddress 18390->18392 18393 7ff71dbd612c 18391->18393 18392->18389 18394 7ff71dbd61ae GetProcAddress 18392->18394 18393->16340 18394->18389 18395 7ff71dbd61d6 GetProcAddress 18394->18395 18395->18389 18396 7ff71dbd61fe GetProcAddress 18395->18396 18397 7ff71dbd6226 GetProcAddress 18396->18397 18398 7ff71dbd621a 18396->18398 18399 7ff71dbd6242 18397->18399 18400 7ff71dbd624e GetProcAddress 18397->18400 18398->18397 18399->18400 18447 7ff71dbd4dd0 18446->18447 18448 7ff71dbd1ef0 49 API calls 18447->18448 18449 7ff71dbd4e02 18448->18449 18450 7ff71dbd4e2b 18449->18450 18451 7ff71dbd4e0b 18449->18451 18452 7ff71dbd4e82 18450->18452 18454 7ff71dbd3220 49 API calls 18450->18454 18453 7ff71dbd2010 86 API calls 18451->18453 18455 7ff71dbd3220 49 API calls 18452->18455 18473 7ff71dbd4e21 18453->18473 18456 7ff71dbd4e4c 18454->18456 18457 7ff71dbd4e9b 18455->18457 18458 7ff71dbd4e6a 18456->18458 18462 7ff71dbd2010 86 API calls 18456->18462 18460 7ff71dbd4eb9 18457->18460 18465 7ff71dbd2010 86 API calls 18457->18465 18463 7ff71dbd3130 88 API calls 18458->18463 18459 7ff71dbdb190 _wfindfirst32i64 8 API calls 18464 7ff71dbd267e 18459->18464 18461 7ff71dbd7460 89 API calls 18460->18461 18466 7ff71dbd4ec6 18461->18466 18462->18458 18467 7ff71dbd4e74 18463->18467 18464->16354 18474 7ff71dbd4f20 18464->18474 18465->18460 18468 7ff71dbd4ecb 18466->18468 18469 7ff71dbd4eed 18466->18469 18467->18452 18472 7ff71dbd7460 89 API calls 18467->18472 18470 7ff71dbd2070 86 API calls 18468->18470 18530 7ff71dbd43b0 GetProcAddress 18469->18530 18470->18473 18472->18452 18473->18459 18614 7ff71dbd3fb0 18474->18614 18476 7ff71dbd4f44 18477 7ff71dbd4f4c 18476->18477 18478 7ff71dbd4f5d 18476->18478 18479 7ff71dbd2010 86 API calls 18477->18479 18621 7ff71dbd3700 18478->18621 18513 7ff71dbd4f58 18479->18513 18482 7ff71dbd4f69 18484 7ff71dbd2010 86 API calls 18482->18484 18483 7ff71dbd4f7a 18485 7ff71dbd4f87 18483->18485 18486 7ff71dbd4f98 18483->18486 18484->18513 18487 7ff71dbd2010 86 API calls 18485->18487 18625 7ff71dbd3a40 18486->18625 18487->18513 18513->16356 18516 7ff71dbd4b37 18515->18516 18516->18516 18517 7ff71dbd4b60 18516->18517 18523 7ff71dbd4b77 __std_exception_copy 18516->18523 18518 7ff71dbd2010 86 API calls 18517->18518 18519 7ff71dbd4b6c 18518->18519 18519->16358 18520 7ff71dbd4c67 18520->16358 18521 7ff71dbd15a0 120 API calls 18521->18523 18522 7ff71dbd2010 86 API calls 18522->18523 18523->18520 18523->18521 18523->18522 18531 7ff71dbd43f0 GetProcAddress 18530->18531 18539 7ff71dbd43d2 18530->18539 18532 7ff71dbd4415 GetProcAddress 18531->18532 18531->18539 18533 7ff71dbd443a GetProcAddress 18532->18533 18532->18539 18535 7ff71dbd4462 GetProcAddress 18533->18535 18533->18539 18534 7ff71dbd2070 86 API calls 18536 7ff71dbd43e5 18534->18536 18537 7ff71dbd448a GetProcAddress 18535->18537 18535->18539 18536->18473 18538 7ff71dbd44b2 GetProcAddress 18537->18538 18537->18539 18538->18539 18540 7ff71dbd44da GetProcAddress 18538->18540 18539->18534 18541 7ff71dbd44f6 18540->18541 18542 7ff71dbd4502 GetProcAddress 18540->18542 18541->18542 18543 7ff71dbd451e 18542->18543 18544 7ff71dbd452a GetProcAddress 18542->18544 18543->18544 18545 7ff71dbd4546 18544->18545 18546 7ff71dbd4552 GetProcAddress 18544->18546 18545->18546 18617 7ff71dbd3fd5 18614->18617 18615 7ff71dbd3fdd 18615->18476 18616 7ff71dbd431a __std_exception_copy 18616->18476 18617->18615 18619 7ff71dbd416f 18617->18619 18656 7ff71dbe7208 18617->18656 18618 7ff71dbd3420 47 API calls 18618->18619 18619->18616 18619->18618 18622 7ff71dbd3730 18621->18622 18623 7ff71dbdb190 _wfindfirst32i64 8 API calls 18622->18623 18624 7ff71dbd3792 18623->18624 18624->18482 18624->18483 18626 7ff71dbd3ab1 18625->18626 18629 7ff71dbd3a54 18625->18629 18657 7ff71dbe7238 18656->18657 18660 7ff71dbe6704 18657->18660 18659 7ff71dbe7268 18659->18617 18661 7ff71dbe6735 18660->18661 18664 7ff71dbe6747 18660->18664 18662 7ff71dbe7c48 _get_daylight 11 API calls 18661->18662 18665 7ff71dbe673a 18662->18665 18663 7ff71dbe6791 18667 7ff71dbe67ac 18663->18667 18671 7ff71dbe4870 45 API calls 18663->18671 18664->18663 18666 7ff71dbe6754 18664->18666 18669 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 18665->18669 18670 7ff71dbeb098 _invalid_parameter_noinfo 37 API calls 18666->18670 18672 7ff71dbe67ce 18667->18672 18681 7ff71dbe7190 18667->18681 18678 7ff71dbe6745 18669->18678 18670->18678 18671->18667 18673 7ff71dbe686f 18672->18673 18674 7ff71dbe7c48 _get_daylight 11 API calls 18672->18674 18675 7ff71dbe7c48 _get_daylight 11 API calls 18673->18675 18673->18678 18676 7ff71dbe6864 18674->18676 18677 7ff71dbe691a 18675->18677 18679 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 18676->18679 18680 7ff71dbeb164 _invalid_parameter_noinfo 37 API calls 18677->18680 18678->18659 18679->18673 18680->18678 18682 7ff71dbe71b3 18681->18682 18683 7ff71dbe71ca 18681->18683 18687 7ff71dbf0b38 18682->18687 18685 7ff71dbe71b8 18683->18685 18692 7ff71dbf0b68 18683->18692 18685->18667 18688 7ff71dbeb9d0 __CxxCallCatchBlock 45 API calls 18687->18688 18689 7ff71dbf0b41 18688->18689 18690 7ff71dbee204 45 API calls 18689->18690 18693 7ff71dbe5194 45 API calls 18692->18693 18694 7ff71dbf0ba1 18693->18694

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 310 7ff71dbf6560-7ff71dbf659b call 7ff71dbf5ee8 call 7ff71dbf5ef0 call 7ff71dbf5f58 317 7ff71dbf67c5-7ff71dbf6811 call 7ff71dbeb184 call 7ff71dbf5ee8 call 7ff71dbf5ef0 call 7ff71dbf5f58 310->317 318 7ff71dbf65a1-7ff71dbf65ac call 7ff71dbf5ef8 310->318 344 7ff71dbf694f-7ff71dbf69bd call 7ff71dbeb184 call 7ff71dbf1dd8 317->344 345 7ff71dbf6817-7ff71dbf6822 call 7ff71dbf5ef8 317->345 318->317 323 7ff71dbf65b2-7ff71dbf65bc 318->323 325 7ff71dbf65de-7ff71dbf65e2 323->325 326 7ff71dbf65be-7ff71dbf65c1 323->326 329 7ff71dbf65e5-7ff71dbf65ed 325->329 328 7ff71dbf65c4-7ff71dbf65cf 326->328 331 7ff71dbf65d1-7ff71dbf65d8 328->331 332 7ff71dbf65da-7ff71dbf65dc 328->332 329->329 333 7ff71dbf65ef-7ff71dbf6602 call 7ff71dbede7c 329->333 331->328 331->332 332->325 335 7ff71dbf660b-7ff71dbf6619 332->335 340 7ff71dbf6604-7ff71dbf6606 call 7ff71dbeb1cc 333->340 341 7ff71dbf661a-7ff71dbf6626 call 7ff71dbeb1cc 333->341 340->335 350 7ff71dbf662d-7ff71dbf6635 341->350 364 7ff71dbf69bf-7ff71dbf69c6 344->364 365 7ff71dbf69cb-7ff71dbf69ce 344->365 345->344 353 7ff71dbf6828-7ff71dbf6833 call 7ff71dbf5f28 345->353 350->350 354 7ff71dbf6637-7ff71dbf6648 call 7ff71dbf1044 350->354 353->344 362 7ff71dbf6839-7ff71dbf685c call 7ff71dbeb1cc GetTimeZoneInformation 353->362 354->317 363 7ff71dbf664e-7ff71dbf66a4 call 7ff71dbdc8b0 * 4 call 7ff71dbf647c 354->363 378 7ff71dbf6924-7ff71dbf694e call 7ff71dbf5ee0 call 7ff71dbf5ed0 call 7ff71dbf5ed8 362->378 379 7ff71dbf6862-7ff71dbf6883 362->379 422 7ff71dbf66a6-7ff71dbf66aa 363->422 368 7ff71dbf6a5b-7ff71dbf6a5e 364->368 369 7ff71dbf6a05-7ff71dbf6a18 call 7ff71dbede7c 365->369 370 7ff71dbf69d0 365->370 371 7ff71dbf69d3 368->371 375 7ff71dbf6a64-7ff71dbf6a6c call 7ff71dbf6560 368->375 386 7ff71dbf6a23-7ff71dbf6a3e call 7ff71dbf1dd8 369->386 387 7ff71dbf6a1a 369->387 370->371 376 7ff71dbf69d8-7ff71dbf6a04 call 7ff71dbeb1cc call 7ff71dbdb190 371->376 377 7ff71dbf69d3 call 7ff71dbf67dc 371->377 375->376 377->376 384 7ff71dbf6885-7ff71dbf688b 379->384 385 7ff71dbf688e-7ff71dbf6895 379->385 384->385 392 7ff71dbf68a9 385->392 393 7ff71dbf6897-7ff71dbf689f 385->393 409 7ff71dbf6a45-7ff71dbf6a57 call 7ff71dbeb1cc 386->409 410 7ff71dbf6a40-7ff71dbf6a43 386->410 391 7ff71dbf6a1c-7ff71dbf6a21 call 7ff71dbeb1cc 387->391 391->370 402 7ff71dbf68ab-7ff71dbf691f call 7ff71dbdc8b0 * 4 call 7ff71dbf33bc call 7ff71dbf6a74 * 2 392->402 393->392 399 7ff71dbf68a1-7ff71dbf68a7 393->399 399->402 402->378 409->368 410->391 424 7ff71dbf66b0-7ff71dbf66b4 422->424 425 7ff71dbf66ac 422->425 424->422 427 7ff71dbf66b6-7ff71dbf66db call 7ff71dbe72bc 424->427 425->424 433 7ff71dbf66de-7ff71dbf66e2 427->433 435 7ff71dbf66e4-7ff71dbf66ef 433->435 436 7ff71dbf66f1-7ff71dbf66f5 433->436 435->436 438 7ff71dbf66f7-7ff71dbf66fb 435->438 436->433 441 7ff71dbf66fd-7ff71dbf6725 call 7ff71dbe72bc 438->441 442 7ff71dbf677c-7ff71dbf6780 438->442 450 7ff71dbf6743-7ff71dbf6747 441->450 451 7ff71dbf6727 441->451 443 7ff71dbf6782-7ff71dbf6784 442->443 444 7ff71dbf6787-7ff71dbf6794 442->444 443->444 446 7ff71dbf6796-7ff71dbf67ac call 7ff71dbf647c 444->446 447 7ff71dbf67af-7ff71dbf67be call 7ff71dbf5ee0 call 7ff71dbf5ed0 444->447 446->447 447->317 450->442 453 7ff71dbf6749-7ff71dbf6767 call 7ff71dbe72bc 450->453 455 7ff71dbf672a-7ff71dbf6731 451->455 462 7ff71dbf6773-7ff71dbf677a 453->462 455->450 459 7ff71dbf6733-7ff71dbf6741 455->459 459->450 459->455 462->442 463 7ff71dbf6769-7ff71dbf676d 462->463 463->442 464 7ff71dbf676f 463->464 464->462
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF65A5
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBF5EF8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF71DBF5F0C
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB1CC: RtlRestoreThreadPreferredUILanguages.NTDLL(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1E2
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB1CC: GetLastError.KERNEL32(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1EC
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB184: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF71DBEB163,?,?,?,?,?,00007FF71DBE2A80), ref: 00007FF71DBEB18D
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB184: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF71DBEB163,?,?,?,?,?,00007FF71DBE2A80), ref: 00007FF71DBEB1B2
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF6594
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBF5F58: _invalid_parameter_noinfo.LIBCMT ref: 00007FF71DBF5F6C
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF680A
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF681B
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF682C
                                                                                                                                                                                                                                    • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF71DBF6A6C), ref: 00007FF71DBF6853
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureInformationLanguagesLastPreferredPresentProcessProcessorRestoreThreadTimeZone
                                                                                                                                                                                                                                    • String ID: W. Europe Standard Time$W. Europe Summer Time
                                                                                                                                                                                                                                    • API String ID: 1458651798-690618308
                                                                                                                                                                                                                                    • Opcode ID: 0992fc228e43ad0e5175039d5836c994e019806c4e98bfffcd809552ce95d6a9
                                                                                                                                                                                                                                    • Instruction ID: a855a26a9260ac69862cfb69f7ec6129d0becddc6fde4e7e62ccdd5e42d3f160
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0992fc228e43ad0e5175039d5836c994e019806c4e98bfffcd809552ce95d6a9
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 27D1B026A1CA5286EB34FF35D4505F9A6A1EF887A4FC08135DE4E43685FE3CE449CB60

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • GetTempPathW.KERNEL32(00000000,00000000,00000000,00000000,?,00007FF71DBD154F), ref: 00007FF71DBD6BE7
                                                                                                                                                                                                                                    • GetCurrentProcessId.KERNEL32 ref: 00007FF71DBD6BED
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD6D60: GetEnvironmentVariableW.KERNEL32(00007FF71DBD2B3C), ref: 00007FF71DBD6D9A
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD6D60: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF71DBD6DB7
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBE80B0: _invalid_parameter_noinfo.LIBCMT ref: 00007FF71DBE80C9
                                                                                                                                                                                                                                    • SetEnvironmentVariableW.KERNEL32 ref: 00007FF71DBD6CA1
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Environment$Variable$CurrentExpandPathProcessStringsTemp_invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: LOADER: Failed to set the TMP environment variable.$TMP$TMP$_MEI%d
                                                                                                                                                                                                                                    • API String ID: 1556224225-1116378104
                                                                                                                                                                                                                                    • Opcode ID: c7967893d07960644c29b8a5ac606b6d8ae90e8d70e398be795f5bb08e05351f
                                                                                                                                                                                                                                    • Instruction ID: ef668bdf8ade04fff386dc579d2dc771b5218948d8e14c359bb47fec2ce9a5c8
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c7967893d07960644c29b8a5ac606b6d8ae90e8d70e398be795f5bb08e05351f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FA517111B0DE5711FE34B72668212BAC2819F89BE4FC44435EE0F57796FD2CE4098B60

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 564 7ff71dbf74ac-7ff71dbf751f call 7ff71dbf71e0 567 7ff71dbf7521-7ff71dbf752a call 7ff71dbe7c28 564->567 568 7ff71dbf7539-7ff71dbf7543 call 7ff71dbe86f8 564->568 573 7ff71dbf752d-7ff71dbf7534 call 7ff71dbe7c48 567->573 574 7ff71dbf7545-7ff71dbf755c call 7ff71dbe7c28 call 7ff71dbe7c48 568->574 575 7ff71dbf755e-7ff71dbf75c7 CreateFileW 568->575 591 7ff71dbf787a-7ff71dbf789a 573->591 574->573 576 7ff71dbf7644-7ff71dbf764f GetFileType 575->576 577 7ff71dbf75c9-7ff71dbf75cf 575->577 584 7ff71dbf7651-7ff71dbf768c GetLastError call 7ff71dbe7bbc CloseHandle 576->584 585 7ff71dbf76a2-7ff71dbf76a9 576->585 581 7ff71dbf7611-7ff71dbf763f GetLastError call 7ff71dbe7bbc 577->581 582 7ff71dbf75d1-7ff71dbf75d5 577->582 581->573 582->581 589 7ff71dbf75d7-7ff71dbf760f CreateFileW 582->589 584->573 599 7ff71dbf7692-7ff71dbf769d call 7ff71dbe7c48 584->599 587 7ff71dbf76b1-7ff71dbf76b4 585->587 588 7ff71dbf76ab-7ff71dbf76af 585->588 594 7ff71dbf76ba-7ff71dbf770f call 7ff71dbe8610 587->594 595 7ff71dbf76b6 587->595 588->594 589->576 589->581 603 7ff71dbf7711-7ff71dbf771d call 7ff71dbf73e8 594->603 604 7ff71dbf772e-7ff71dbf775f call 7ff71dbf6f60 594->604 595->594 599->573 603->604 611 7ff71dbf771f 603->611 609 7ff71dbf7765-7ff71dbf77a7 604->609 610 7ff71dbf7761-7ff71dbf7763 604->610 613 7ff71dbf77c9-7ff71dbf77d4 609->613 614 7ff71dbf77a9-7ff71dbf77ad 609->614 612 7ff71dbf7721-7ff71dbf7729 call 7ff71dbeb344 610->612 611->612 612->591 616 7ff71dbf77da-7ff71dbf77de 613->616 617 7ff71dbf7878 613->617 614->613 615 7ff71dbf77af-7ff71dbf77c4 614->615 615->613 616->617 619 7ff71dbf77e4-7ff71dbf7829 CloseHandle CreateFileW 616->619 617->591 621 7ff71dbf785e-7ff71dbf7873 619->621 622 7ff71dbf782b-7ff71dbf7859 GetLastError call 7ff71dbe7bbc call 7ff71dbe8838 619->622 621->617 622->621
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1617910340-0
                                                                                                                                                                                                                                    • Opcode ID: 8afc4846cd620552121b56385621ad3827c937315e643adb1c03d6c87c062f34
                                                                                                                                                                                                                                    • Instruction ID: c2758c3d06defe034a4e21fb57643618b64519ae6d3f9baa8241929c65f279e0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8afc4846cd620552121b56385621ad3827c937315e643adb1c03d6c87c062f34
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 47C1D236B28E4185EF30DF68C4906AC7761E749BA8B901235DE2F97794EF38D45ACB10

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 826 7ff71dbf67dc-7ff71dbf6811 call 7ff71dbf5ee8 call 7ff71dbf5ef0 call 7ff71dbf5f58 833 7ff71dbf694f-7ff71dbf69bd call 7ff71dbeb184 call 7ff71dbf1dd8 826->833 834 7ff71dbf6817-7ff71dbf6822 call 7ff71dbf5ef8 826->834 846 7ff71dbf69bf-7ff71dbf69c6 833->846 847 7ff71dbf69cb-7ff71dbf69ce 833->847 834->833 839 7ff71dbf6828-7ff71dbf6833 call 7ff71dbf5f28 834->839 839->833 845 7ff71dbf6839-7ff71dbf685c call 7ff71dbeb1cc GetTimeZoneInformation 839->845 858 7ff71dbf6924-7ff71dbf694e call 7ff71dbf5ee0 call 7ff71dbf5ed0 call 7ff71dbf5ed8 845->858 859 7ff71dbf6862-7ff71dbf6883 845->859 849 7ff71dbf6a5b-7ff71dbf6a5e 846->849 850 7ff71dbf6a05-7ff71dbf6a18 call 7ff71dbede7c 847->850 851 7ff71dbf69d0 847->851 852 7ff71dbf69d3 849->852 855 7ff71dbf6a64-7ff71dbf6a6c call 7ff71dbf6560 849->855 865 7ff71dbf6a23-7ff71dbf6a3e call 7ff71dbf1dd8 850->865 866 7ff71dbf6a1a 850->866 851->852 856 7ff71dbf69d8-7ff71dbf6a04 call 7ff71dbeb1cc call 7ff71dbdb190 852->856 857 7ff71dbf69d3 call 7ff71dbf67dc 852->857 855->856 857->856 863 7ff71dbf6885-7ff71dbf688b 859->863 864 7ff71dbf688e-7ff71dbf6895 859->864 863->864 870 7ff71dbf68a9 864->870 871 7ff71dbf6897-7ff71dbf689f 864->871 884 7ff71dbf6a45-7ff71dbf6a57 call 7ff71dbeb1cc 865->884 885 7ff71dbf6a40-7ff71dbf6a43 865->885 869 7ff71dbf6a1c-7ff71dbf6a21 call 7ff71dbeb1cc 866->869 869->851 878 7ff71dbf68ab-7ff71dbf691f call 7ff71dbdc8b0 * 4 call 7ff71dbf33bc call 7ff71dbf6a74 * 2 870->878 871->870 876 7ff71dbf68a1-7ff71dbf68a7 871->876 876->878 878->858 884->849 885->869
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF680A
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBF5F58: _invalid_parameter_noinfo.LIBCMT ref: 00007FF71DBF5F6C
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF681B
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBF5EF8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF71DBF5F0C
                                                                                                                                                                                                                                    • _get_daylight.LIBCMT ref: 00007FF71DBF682C
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBF5F28: _invalid_parameter_noinfo.LIBCMT ref: 00007FF71DBF5F3C
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB1CC: RtlRestoreThreadPreferredUILanguages.NTDLL(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1E2
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB1CC: GetLastError.KERNEL32(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1EC
                                                                                                                                                                                                                                    • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF71DBF6A6C), ref: 00007FF71DBF6853
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _get_daylight_invalid_parameter_noinfo$ErrorInformationLanguagesLastPreferredRestoreThreadTimeZone
                                                                                                                                                                                                                                    • String ID: W. Europe Standard Time$W. Europe Summer Time
                                                                                                                                                                                                                                    • API String ID: 2248164782-690618308
                                                                                                                                                                                                                                    • Opcode ID: db174c4128b3a7a4552f986b7bba05e7d482cfcee159e29a1967446997e4cdde
                                                                                                                                                                                                                                    • Instruction ID: 7e6741b9d0fe342e4653f0017389b86fc23d48088e5116ac12d5fb2effd9453a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: db174c4128b3a7a4552f986b7bba05e7d482cfcee159e29a1967446997e4cdde
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5E514532A1CA5286E730FF31D4905A9A761FB887A4FC44635DA4E83695EF3CE449CF60
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Find$CloseFileFirst
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2295610775-0
                                                                                                                                                                                                                                    • Opcode ID: 11c8737c5447c46409b4ad6f1658ea81d4cf5819c889836a1f8e1472af053c13
                                                                                                                                                                                                                                    • Instruction ID: f0139a6d4f7b3cde7f293b6d249982c94697b6a4d314e77b17a4b1b003bd4dd6
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 11c8737c5447c46409b4ad6f1658ea81d4cf5819c889836a1f8e1472af053c13
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3BF0862651CA8586FB709F60A4557A5B351EB44738F404235D57F066D4FF3CD40C8F14

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 0 7ff71dbd1710-7ff71dbd1724 1 7ff71dbd1726-7ff71dbd173d call 7ff71dbd2010 0->1 2 7ff71dbd173e-7ff71dbd1742 0->2 4 7ff71dbd1744-7ff71dbd174d call 7ff71dbd12b0 2->4 5 7ff71dbd1768-7ff71dbd178b call 7ff71dbd6e10 2->5 13 7ff71dbd175f-7ff71dbd1767 4->13 14 7ff71dbd174f-7ff71dbd175a call 7ff71dbd2010 4->14 11 7ff71dbd178d-7ff71dbd17b8 call 7ff71dbd1fd0 5->11 12 7ff71dbd17b9-7ff71dbd17d4 call 7ff71dbd31a0 5->12 20 7ff71dbd17d6-7ff71dbd17e9 call 7ff71dbd2010 12->20 21 7ff71dbd17ee-7ff71dbd1801 call 7ff71dbdfcd4 12->21 14->13 26 7ff71dbd192f-7ff71dbd1932 call 7ff71dbdf64c 20->26 27 7ff71dbd1823-7ff71dbd1827 21->27 28 7ff71dbd1803-7ff71dbd181e call 7ff71dbd1fd0 21->28 33 7ff71dbd1937-7ff71dbd194e 26->33 29 7ff71dbd1841-7ff71dbd1861 call 7ff71dbe518c 27->29 30 7ff71dbd1829-7ff71dbd1835 call 7ff71dbd1050 27->30 39 7ff71dbd1927-7ff71dbd192a call 7ff71dbdf64c 28->39 40 7ff71dbd1863-7ff71dbd187d call 7ff71dbd1fd0 29->40 41 7ff71dbd1882-7ff71dbd1888 29->41 37 7ff71dbd183a-7ff71dbd183c 30->37 37->39 39->26 49 7ff71dbd191d-7ff71dbd1922 40->49 44 7ff71dbd1915-7ff71dbd1918 call 7ff71dbe5178 41->44 45 7ff71dbd188e-7ff71dbd1897 41->45 44->49 48 7ff71dbd18a0-7ff71dbd18c2 call 7ff71dbdf99c 45->48 52 7ff71dbd18c4-7ff71dbd18dc call 7ff71dbe00dc 48->52 53 7ff71dbd18f5-7ff71dbd18fc 48->53 49->39 58 7ff71dbd18e5-7ff71dbd18f3 52->58 59 7ff71dbd18de-7ff71dbd18e1 52->59 54 7ff71dbd1903-7ff71dbd190b call 7ff71dbd1fd0 53->54 62 7ff71dbd1910 54->62 58->54 59->48 61 7ff71dbd18e3 59->61 61->62 62->44
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID: Failed to create symbolic link %s!$Failed to extract %s: failed to allocate temporary buffer!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to open target file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$Failed to extract %s: failed to write data chunk!$fopen$fread$fseek$fwrite$malloc$pyi_arch_extract2fs was called before temporary directory was initialized!
                                                                                                                                                                                                                                    • API String ID: 0-3833288071
                                                                                                                                                                                                                                    • Opcode ID: 313a5f6fb4dd00cccb4bbc8c0f597bbcf09b6dcfc4e1776d072891652f401271
                                                                                                                                                                                                                                    • Instruction ID: 15e538c5e435b7d04bccc2310f387e6920444229fdecfcf327b0b300fc2c2a34
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 313a5f6fb4dd00cccb4bbc8c0f597bbcf09b6dcfc4e1776d072891652f401271
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0C516E61B0CE8682EA30BB15E8602B9E351AF457E8FC44231DE4E47695FE2CE54D8B24

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 63 7ff71dbd1000-7ff71dbd2afb call 7ff71dbdf420 call 7ff71dbdf418 call 7ff71dbd7910 call 7ff71dbdb130 call 7ff71dbe54f0 call 7ff71dbe60c0 call 7ff71dbd1eb0 79 7ff71dbd2be6 63->79 80 7ff71dbd2b01-7ff71dbd2b11 call 7ff71dbd3090 63->80 81 7ff71dbd2beb-7ff71dbd2c14 call 7ff71dbdb190 79->81 80->79 86 7ff71dbd2b17-7ff71dbd2b2a call 7ff71dbd2f60 80->86 86->79 89 7ff71dbd2b30-7ff71dbd2b4e call 7ff71dbd6d60 86->89 92 7ff71dbd2b90-7ff71dbd2bb0 call 7ff71dbd7240 call 7ff71dbd1cb0 89->92 93 7ff71dbd2b50-7ff71dbd2b5f call 7ff71dbd6d60 89->93 104 7ff71dbd2bb6-7ff71dbd2bcc call 7ff71dbd1cb0 92->104 105 7ff71dbd2c8e-7ff71dbd2ca3 call 7ff71dbd1a00 92->105 93->92 98 7ff71dbd2b61-7ff71dbd2b67 93->98 100 7ff71dbd2b73-7ff71dbd2b8d call 7ff71dbe5178 call 7ff71dbd7240 98->100 101 7ff71dbd2b69-7ff71dbd2b71 98->101 100->92 101->100 112 7ff71dbd2c15-7ff71dbd2c18 104->112 113 7ff71dbd2bce-7ff71dbd2be1 call 7ff71dbd2010 104->113 115 7ff71dbd2ca5-7ff71dbd2cb6 call 7ff71dbe6100 105->115 116 7ff71dbd2cd7-7ff71dbd2ce8 105->116 112->105 120 7ff71dbd2c1a-7ff71dbd2c31 call 7ff71dbd31a0 112->120 113->79 131 7ff71dbd2cbf-7ff71dbd2cd0 call 7ff71dbe6100 115->131 132 7ff71dbd2cb8-7ff71dbd2cbd call 7ff71dbd7ab0 115->132 118 7ff71dbd2d04-7ff71dbd2d07 116->118 119 7ff71dbd2cea-7ff71dbd2cf1 116->119 123 7ff71dbd2d1e-7ff71dbd2d36 call 7ff71dbd7fb0 118->123 124 7ff71dbd2d09-7ff71dbd2d10 118->124 119->118 122 7ff71dbd2cf3-7ff71dbd2cf6 call 7ff71dbd14f0 119->122 136 7ff71dbd2c33-7ff71dbd2c36 120->136 137 7ff71dbd2c38-7ff71dbd2c64 call 7ff71dbd74b0 120->137 135 7ff71dbd2cfb-7ff71dbd2cfe 122->135 145 7ff71dbd2d38-7ff71dbd2d44 call 7ff71dbd2010 123->145 146 7ff71dbd2d49-7ff71dbd2d50 SetDllDirectoryW 123->146 128 7ff71dbd2d56-7ff71dbd2d63 call 7ff71dbd5fe0 124->128 129 7ff71dbd2d12-7ff71dbd2d1c 124->129 150 7ff71dbd2d65-7ff71dbd2d72 call 7ff71dbd5c90 128->150 151 7ff71dbd2dae-7ff71dbd2db3 call 7ff71dbd5f60 128->151 129->123 129->128 131->116 148 7ff71dbd2cd2 call 7ff71dbd7c00 131->148 132->116 135->79 135->118 142 7ff71dbd2c73-7ff71dbd2c89 call 7ff71dbd2010 136->142 137->105 158 7ff71dbd2c66-7ff71dbd2c6e call 7ff71dbdf64c 137->158 142->79 145->79 146->128 148->116 150->151 166 7ff71dbd2d74-7ff71dbd2d83 call 7ff71dbd57f0 150->166 160 7ff71dbd2db8-7ff71dbd2dbb 151->160 158->142 164 7ff71dbd2dc1-7ff71dbd2dcf 160->164 165 7ff71dbd2e9d-7ff71dbd2eac call 7ff71dbd26d0 160->165 167 7ff71dbd2dd0-7ff71dbd2dda 164->167 165->79 174 7ff71dbd2eb2-7ff71dbd2ed9 call 7ff71dbd71d0 call 7ff71dbd6d60 call 7ff71dbd2830 165->174 177 7ff71dbd2da4-7ff71dbd2da9 call 7ff71dbd5a40 166->177 178 7ff71dbd2d85-7ff71dbd2d91 call 7ff71dbd5770 166->178 170 7ff71dbd2de3-7ff71dbd2de5 167->170 171 7ff71dbd2ddc-7ff71dbd2de1 167->171 175 7ff71dbd2e31-7ff71dbd2e34 170->175 176 7ff71dbd2de7-7ff71dbd2e0a call 7ff71dbd1ef0 170->176 171->167 171->170 212 7ff71dbd2edb-7ff71dbd2eec call 7ff71dbe6100 174->212 213 7ff71dbd2f0d-7ff71dbd2f3d call 7ff71dbd7280 call 7ff71dbd5a40 call 7ff71dbd5f60 174->213 183 7ff71dbd2e36-7ff71dbd2e47 call 7ff71dbe6100 175->183 184 7ff71dbd2e68-7ff71dbd2e98 call 7ff71dbd2830 call 7ff71dbd2670 call 7ff71dbd2820 call 7ff71dbd5a40 call 7ff71dbd5f60 175->184 176->79 192 7ff71dbd2e10-7ff71dbd2e1a 176->192 177->151 178->177 194 7ff71dbd2d93-7ff71dbd2da2 call 7ff71dbd5e30 178->194 195 7ff71dbd2e50-7ff71dbd2e61 call 7ff71dbe6100 183->195 196 7ff71dbd2e49-7ff71dbd2e4e call 7ff71dbd7ab0 183->196 184->81 198 7ff71dbd2e20-7ff71dbd2e2f 192->198 194->160 195->184 211 7ff71dbd2e63 call 7ff71dbd7c00 195->211 196->184 198->175 198->198 211->184 221 7ff71dbd2ef5-7ff71dbd2f06 call 7ff71dbe6100 212->221 222 7ff71dbd2eee-7ff71dbd2ef3 call 7ff71dbd7ab0 212->222 234 7ff71dbd2f3f-7ff71dbd2f46 call 7ff71dbd6f40 213->234 235 7ff71dbd2f4b-7ff71dbd2f4e call 7ff71dbd1e80 213->235 221->213 233 7ff71dbd2f08 call 7ff71dbd7c00 221->233 222->213 233->213 234->235 239 7ff71dbd2f53-7ff71dbd2f55 235->239 239->81
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD3090: GetModuleFileNameW.KERNEL32(?,00007FF71DBD2B0F), ref: 00007FF71DBD30C1
                                                                                                                                                                                                                                    • SetDllDirectoryW.KERNEL32 ref: 00007FF71DBD2D50
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD6D60: GetEnvironmentVariableW.KERNEL32(00007FF71DBD2B3C), ref: 00007FF71DBD6D9A
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD6D60: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF71DBD6DB7
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Environment$DirectoryExpandFileModuleNameStringsVariable
                                                                                                                                                                                                                                    • String ID: Cannot open PyInstaller archive from executable (%s) or external archive (%s)$Cannot side-load external archive %s (code %d)!$Failed to convert DLL search path!$MEI$_MEIPASS2$_PYI_ONEDIR_MODE$hide-early$hide-late$minimize-early$minimize-late$pyi-hide-console
                                                                                                                                                                                                                                    • API String ID: 2344891160-1364127678
                                                                                                                                                                                                                                    • Opcode ID: 1dccd711b07bad05ef8906e65f2b115fca1395e25e946f194c0af35c821daeba
                                                                                                                                                                                                                                    • Instruction ID: 0d75532df754825f994bcb089ecf64edbb8c230cac14c9f5612f6b3fd2376772
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1dccd711b07bad05ef8906e65f2b115fca1395e25e946f194c0af35c821daeba
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EFD17F21A1CE8355EA74BB2199A12F9D291AF447B8FC44131E94F47696FE2CE90DCF30

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • GetCurrentProcess.KERNEL32(0000000100000001,00007FF71DBD331C,00007FF71DBD6B11,?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7CA0
                                                                                                                                                                                                                                    • OpenProcessToken.ADVAPI32(?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7CB1
                                                                                                                                                                                                                                    • GetTokenInformation.KERNELBASE(?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7CD3
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7CDD
                                                                                                                                                                                                                                    • GetTokenInformation.KERNELBASE(?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7D1A
                                                                                                                                                                                                                                    • ConvertSidToStringSidW.ADVAPI32 ref: 00007FF71DBD7D2C
                                                                                                                                                                                                                                    • FindCloseChangeNotification.KERNELBASE(?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7D44
                                                                                                                                                                                                                                    • LocalFree.KERNEL32(?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7D76
                                                                                                                                                                                                                                    • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32 ref: 00007FF71DBD7D9D
                                                                                                                                                                                                                                    • CreateDirectoryW.KERNELBASE(?,00007FF71DBD6F26,?,00007FF71DBD1785), ref: 00007FF71DBD7DAE
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Token$ConvertDescriptorInformationProcessSecurityString$ChangeCloseCreateCurrentDirectoryErrorFindFreeLastLocalNotificationOpen
                                                                                                                                                                                                                                    • String ID: D:(A;;FA;;;%s)$S-1-3-4
                                                                                                                                                                                                                                    • API String ID: 2187719417-2855260032
                                                                                                                                                                                                                                    • Opcode ID: c49b53b47b33b28df59b0cea2bd685458743d024825b2f4c4d8a6a27e68c54cf
                                                                                                                                                                                                                                    • Instruction ID: 0b5df19f1a2e491c9ddac6e4560c2881e8cef3318e007ce57c2d5fca313db963
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c49b53b47b33b28df59b0cea2bd685458743d024825b2f4c4d8a6a27e68c54cf
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5741623161CE8242EA70AF25E4546A9A361FB857A4F840235EA6F476D5EF3CD40C8F60

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _fread_nolock
                                                                                                                                                                                                                                    • String ID: Could not allocate buffer for TOC!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$fread$fseek$malloc
                                                                                                                                                                                                                                    • API String ID: 840049012-1384898525
                                                                                                                                                                                                                                    • Opcode ID: bd43d7dd0375f4be4b9488ade93112ef5bfac352b25b0a13d1b82bcccf50312e
                                                                                                                                                                                                                                    • Instruction ID: e155ed54cc69c1802a93364baac52df95341e480f4d6147c5000f044e72aa94b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bd43d7dd0375f4be4b9488ade93112ef5bfac352b25b0a13d1b82bcccf50312e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6E519671A0DE4285EB34EF14E4501B9B3A0EF48BA8B958135D90E47795EE7CE448CF64

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Process_invalid_parameter_noinfo$ByteCharCodeCommandConsoleCreateCtrlExitHandlerInfoLineMultiObjectSingleStartupWaitWide
                                                                                                                                                                                                                                    • String ID: CreateProcessW$Error creating child process!
                                                                                                                                                                                                                                    • API String ID: 2895956056-3524285272
                                                                                                                                                                                                                                    • Opcode ID: 09cdf26451e21f988e1d62598cc136331b4b0f50e0bb1119a682d216b8410746
                                                                                                                                                                                                                                    • Instruction ID: 005ed018f2685fe68e3037bc2be74477bda63ae9b57bc6ca5386e2974ff85b72
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 09cdf26451e21f988e1d62598cc136331b4b0f50e0bb1119a682d216b8410746
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17410331A0CF8585DA30AB24E4552AAE3A4FB94774F900339E6AE477D5EF7CD0488F10

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 627 7ff71dbd1050-7ff71dbd10ab call 7ff71dbda9b0 630 7ff71dbd10d3-7ff71dbd10eb call 7ff71dbe518c 627->630 631 7ff71dbd10ad-7ff71dbd10d2 call 7ff71dbd2010 627->631 636 7ff71dbd10ed-7ff71dbd1104 call 7ff71dbd1fd0 630->636 637 7ff71dbd1109-7ff71dbd1119 call 7ff71dbe518c 630->637 644 7ff71dbd126c-7ff71dbd1281 call 7ff71dbda690 call 7ff71dbe5178 * 2 636->644 642 7ff71dbd111b-7ff71dbd1132 call 7ff71dbd1fd0 637->642 643 7ff71dbd1137-7ff71dbd1147 637->643 642->644 646 7ff71dbd1150-7ff71dbd1175 call 7ff71dbdf99c 643->646 660 7ff71dbd1286-7ff71dbd12a0 644->660 653 7ff71dbd117b-7ff71dbd1185 call 7ff71dbdf710 646->653 654 7ff71dbd125e 646->654 653->654 661 7ff71dbd118b-7ff71dbd1197 653->661 656 7ff71dbd1264 654->656 656->644 662 7ff71dbd11a0-7ff71dbd11c8 call 7ff71dbd8e60 661->662 665 7ff71dbd1241-7ff71dbd125c call 7ff71dbd2010 662->665 666 7ff71dbd11ca-7ff71dbd11cd 662->666 665->656 667 7ff71dbd11cf-7ff71dbd11d9 666->667 668 7ff71dbd123c 666->668 670 7ff71dbd1203-7ff71dbd1206 667->670 671 7ff71dbd11db-7ff71dbd11e8 call 7ff71dbe00dc 667->671 668->665 674 7ff71dbd1208-7ff71dbd1216 call 7ff71dbdbef0 670->674 675 7ff71dbd1219-7ff71dbd121e 670->675 676 7ff71dbd11ed-7ff71dbd11f0 671->676 674->675 675->662 678 7ff71dbd1220-7ff71dbd1223 675->678 679 7ff71dbd11f2-7ff71dbd11fc call 7ff71dbdf710 676->679 680 7ff71dbd11fe-7ff71dbd1201 676->680 682 7ff71dbd1225-7ff71dbd1228 678->682 683 7ff71dbd1237-7ff71dbd123a 678->683 679->675 679->680 680->665 682->665 685 7ff71dbd122a-7ff71dbd1232 682->685 683->656 685->646
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID: 1.2.13$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
                                                                                                                                                                                                                                    • API String ID: 0-1655038675
                                                                                                                                                                                                                                    • Opcode ID: 796844992ad0ae0c37d0c4fbc41a8f7c79d8bd8a23177e062cabe6813e676bdd
                                                                                                                                                                                                                                    • Instruction ID: f547bc0b29b6799c90a9b4b09640eb92720f01df3ed458e973f2bff070a326e4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 796844992ad0ae0c37d0c4fbc41a8f7c79d8bd8a23177e062cabe6813e676bdd
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E0517522A0DE8245E670BB51A4603B9E291FB457E8F844235DD4F87799FE3CE549CB10

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • FreeLibrary.KERNEL32(?,?,?,00007FF71DBEF842,?,?,-00000018,00007FF71DBEB5D7,?,?,?,00007FF71DBEB4CE,?,?,?,00007FF71DBE66A2), ref: 00007FF71DBEF624
                                                                                                                                                                                                                                    • GetProcAddress.KERNEL32(?,?,?,00007FF71DBEF842,?,?,-00000018,00007FF71DBEB5D7,?,?,?,00007FF71DBEB4CE,?,?,?,00007FF71DBE66A2), ref: 00007FF71DBEF630
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressFreeLibraryProc
                                                                                                                                                                                                                                    • String ID: api-ms-$ext-ms-
                                                                                                                                                                                                                                    • API String ID: 3013587201-537541572
                                                                                                                                                                                                                                    • Opcode ID: ae5708f04b36c8c590ee3721b0de7d7d793178a269120fac9f1ca8338cf688ab
                                                                                                                                                                                                                                    • Instruction ID: 3e57f9f55d4f3a6b581851f5c48f45bc3da3be8817c7928d0343da67e30f98ea
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ae5708f04b36c8c590ee3721b0de7d7d793178a269120fac9f1ca8338cf688ab
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5941E122B1DE0285EA35AF16A8105B5A395BF4CBF0F888535DD0E67784FE3CE44D8B64

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 713 7ff71dbec2dc-7ff71dbec302 714 7ff71dbec304-7ff71dbec318 call 7ff71dbe7c28 call 7ff71dbe7c48 713->714 715 7ff71dbec31d-7ff71dbec321 713->715 733 7ff71dbec70e 714->733 717 7ff71dbec6f7-7ff71dbec703 call 7ff71dbe7c28 call 7ff71dbe7c48 715->717 718 7ff71dbec327-7ff71dbec32e 715->718 736 7ff71dbec709 call 7ff71dbeb164 717->736 718->717 719 7ff71dbec334-7ff71dbec362 718->719 719->717 722 7ff71dbec368-7ff71dbec36f 719->722 725 7ff71dbec371-7ff71dbec383 call 7ff71dbe7c28 call 7ff71dbe7c48 722->725 726 7ff71dbec388-7ff71dbec38b 722->726 725->736 731 7ff71dbec6f3-7ff71dbec6f5 726->731 732 7ff71dbec391-7ff71dbec397 726->732 734 7ff71dbec711-7ff71dbec728 731->734 732->731 737 7ff71dbec39d-7ff71dbec3a0 732->737 733->734 736->733 737->725 740 7ff71dbec3a2-7ff71dbec3c7 737->740 742 7ff71dbec3c9-7ff71dbec3cb 740->742 743 7ff71dbec3fa-7ff71dbec401 740->743 746 7ff71dbec3f2-7ff71dbec3f8 742->746 747 7ff71dbec3cd-7ff71dbec3d4 742->747 744 7ff71dbec3d6-7ff71dbec3ed call 7ff71dbe7c28 call 7ff71dbe7c48 call 7ff71dbeb164 743->744 745 7ff71dbec403-7ff71dbec42b call 7ff71dbede7c call 7ff71dbeb1cc * 2 743->745 776 7ff71dbec580 744->776 778 7ff71dbec42d-7ff71dbec443 call 7ff71dbe7c48 call 7ff71dbe7c28 745->778 779 7ff71dbec448-7ff71dbec473 call 7ff71dbecb04 745->779 748 7ff71dbec478-7ff71dbec48f 746->748 747->744 747->746 751 7ff71dbec491-7ff71dbec499 748->751 752 7ff71dbec50a-7ff71dbec514 call 7ff71dbf417c 748->752 751->752 757 7ff71dbec49b-7ff71dbec49d 751->757 763 7ff71dbec59e 752->763 764 7ff71dbec51a-7ff71dbec52f 752->764 757->752 761 7ff71dbec49f-7ff71dbec4b5 757->761 761->752 766 7ff71dbec4b7-7ff71dbec4c3 761->766 772 7ff71dbec5a3-7ff71dbec5c3 ReadFile 763->772 764->763 768 7ff71dbec531-7ff71dbec543 GetConsoleMode 764->768 766->752 770 7ff71dbec4c5-7ff71dbec4c7 766->770 768->763 775 7ff71dbec545-7ff71dbec54d 768->775 770->752 777 7ff71dbec4c9-7ff71dbec4e1 770->777 773 7ff71dbec6bd-7ff71dbec6c6 GetLastError 772->773 774 7ff71dbec5c9-7ff71dbec5d1 772->774 783 7ff71dbec6e3-7ff71dbec6e6 773->783 784 7ff71dbec6c8-7ff71dbec6de call 7ff71dbe7c48 call 7ff71dbe7c28 773->784 774->773 780 7ff71dbec5d7 774->780 775->772 782 7ff71dbec54f-7ff71dbec571 ReadConsoleW 775->782 785 7ff71dbec583-7ff71dbec58d call 7ff71dbeb1cc 776->785 777->752 786 7ff71dbec4e3-7ff71dbec4ef 777->786 778->776 779->748 788 7ff71dbec5de-7ff71dbec5f3 780->788 790 7ff71dbec573 GetLastError 782->790 791 7ff71dbec592-7ff71dbec59c 782->791 795 7ff71dbec6ec-7ff71dbec6ee 783->795 796 7ff71dbec579-7ff71dbec57b call 7ff71dbe7bbc 783->796 784->776 785->734 786->752 794 7ff71dbec4f1-7ff71dbec4f3 786->794 788->785 799 7ff71dbec5f5-7ff71dbec600 788->799 790->796 791->788 794->752 803 7ff71dbec4f5-7ff71dbec505 794->803 795->785 796->776 805 7ff71dbec602-7ff71dbec61b call 7ff71dbebef4 799->805 806 7ff71dbec627-7ff71dbec62f 799->806 803->752 813 7ff71dbec620-7ff71dbec622 805->813 809 7ff71dbec631-7ff71dbec643 806->809 810 7ff71dbec6ab-7ff71dbec6b8 call 7ff71dbebd34 806->810 814 7ff71dbec645 809->814 815 7ff71dbec69e-7ff71dbec6a6 809->815 810->813 813->785 817 7ff71dbec64a-7ff71dbec651 814->817 815->785 818 7ff71dbec653-7ff71dbec657 817->818 819 7ff71dbec68d-7ff71dbec698 817->819 820 7ff71dbec673 818->820 821 7ff71dbec659-7ff71dbec660 818->821 819->815 822 7ff71dbec679-7ff71dbec689 820->822 821->820 823 7ff71dbec662-7ff71dbec666 821->823 822->817 824 7ff71dbec68b 822->824 823->820 825 7ff71dbec668-7ff71dbec671 823->825 824->815 825->822
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3215553584-0
                                                                                                                                                                                                                                    • Opcode ID: 3aac8c1df359aa8ad0138161e1254d396fa891c01af46540a64807a88d95b6ef
                                                                                                                                                                                                                                    • Instruction ID: f0837815464e65b807acdf3d4c04891d98651c4f8d60bd092c3fd4a65bb71c59
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3aac8c1df359aa8ad0138161e1254d396fa891c01af46540a64807a88d95b6ef
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 76C10522A0CF8295EB706B1594012BEB790EB89BA0FD51131DA4F13391EE7CE84D8F20

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 936 7ff71dbed7e0-7ff71dbed805 937 7ff71dbedad3 936->937 938 7ff71dbed80b-7ff71dbed80e 936->938 941 7ff71dbedad5-7ff71dbedae5 937->941 939 7ff71dbed810-7ff71dbed842 call 7ff71dbeb098 938->939 940 7ff71dbed847-7ff71dbed873 938->940 939->941 943 7ff71dbed875-7ff71dbed87c 940->943 944 7ff71dbed87e-7ff71dbed884 940->944 943->939 943->944 946 7ff71dbed886-7ff71dbed88f call 7ff71dbecba0 944->946 947 7ff71dbed894-7ff71dbed8a9 call 7ff71dbf417c 944->947 946->947 951 7ff71dbed9c3-7ff71dbed9cc 947->951 952 7ff71dbed8af-7ff71dbed8b8 947->952 953 7ff71dbeda20-7ff71dbeda45 WriteFile 951->953 954 7ff71dbed9ce-7ff71dbed9d4 951->954 952->951 955 7ff71dbed8be-7ff71dbed8c2 952->955 956 7ff71dbeda50 953->956 957 7ff71dbeda47-7ff71dbeda4d GetLastError 953->957 958 7ff71dbed9d6-7ff71dbed9d9 954->958 959 7ff71dbeda0c-7ff71dbeda1e call 7ff71dbed298 954->959 960 7ff71dbed8d3-7ff71dbed8de 955->960 961 7ff71dbed8c4-7ff71dbed8cc call 7ff71dbe4870 955->961 965 7ff71dbeda53 956->965 957->956 966 7ff71dbed9db-7ff71dbed9de 958->966 967 7ff71dbed9f8-7ff71dbeda0a call 7ff71dbed4b8 958->967 980 7ff71dbed9b0-7ff71dbed9b7 959->980 962 7ff71dbed8ef-7ff71dbed904 GetConsoleMode 960->962 963 7ff71dbed8e0-7ff71dbed8e9 960->963 961->960 970 7ff71dbed9bc 962->970 971 7ff71dbed90a-7ff71dbed910 962->971 963->951 963->962 973 7ff71dbeda58 965->973 974 7ff71dbeda64-7ff71dbeda6e 966->974 975 7ff71dbed9e4-7ff71dbed9f6 call 7ff71dbed39c 966->975 967->980 970->951 978 7ff71dbed916-7ff71dbed919 971->978 979 7ff71dbed999-7ff71dbed9ab call 7ff71dbece20 971->979 981 7ff71dbeda5d 973->981 982 7ff71dbeda70-7ff71dbeda75 974->982 983 7ff71dbedacc-7ff71dbedad1 974->983 975->980 985 7ff71dbed924-7ff71dbed932 978->985 986 7ff71dbed91b-7ff71dbed91e 978->986 979->980 980->973 981->974 988 7ff71dbedaa3-7ff71dbedaad 982->988 989 7ff71dbeda77-7ff71dbeda7a 982->989 983->941 993 7ff71dbed934 985->993 994 7ff71dbed990-7ff71dbed994 985->994 986->981 986->985 991 7ff71dbedab4-7ff71dbedac3 988->991 992 7ff71dbedaaf-7ff71dbedab2 988->992 995 7ff71dbeda93-7ff71dbeda9e call 7ff71dbe7c04 989->995 996 7ff71dbeda7c-7ff71dbeda8b 989->996 991->983 992->937 992->991 998 7ff71dbed938-7ff71dbed94f call 7ff71dbf4248 993->998 994->965 995->988 996->995 1002 7ff71dbed951-7ff71dbed95d 998->1002 1003 7ff71dbed987-7ff71dbed98d GetLastError 998->1003 1004 7ff71dbed95f-7ff71dbed971 call 7ff71dbf4248 1002->1004 1005 7ff71dbed97c-7ff71dbed983 1002->1005 1003->994 1004->1003 1009 7ff71dbed973-7ff71dbed97a 1004->1009 1005->994 1006 7ff71dbed985 1005->1006 1006->998 1009->1005
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,?,00000000,00000000,00007FF71DBED7CB), ref: 00007FF71DBED8FC
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,00000000,?,?,00000000,00000000,00007FF71DBED7CB), ref: 00007FF71DBED987
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ConsoleErrorLastMode
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 953036326-0
                                                                                                                                                                                                                                    • Opcode ID: bc0851f0a6fd351bd2c279fe1f2b83c40d0216da9fe35e8edc63442de1074daf
                                                                                                                                                                                                                                    • Instruction ID: 5fb752d8c7465a01006b09e324f8a84db8391435d0a170b2a401a2e82f2187dd
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bc0851f0a6fd351bd2c279fe1f2b83c40d0216da9fe35e8edc63442de1074daf
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C5910822F0CA5185F770AF6D94403BDABA0BB487A8F945135DE0F67684EE7CD44ACB20

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 1010 7ff71dbefedc-7ff71dbeff18 1011 7ff71dbf00ce-7ff71dbf00d9 call 7ff71dbe7c48 1010->1011 1012 7ff71dbeff1e-7ff71dbeff27 1010->1012 1017 7ff71dbf00dd-7ff71dbf00f9 call 7ff71dbdb190 1011->1017 1012->1011 1014 7ff71dbeff2d-7ff71dbeff36 1012->1014 1014->1011 1016 7ff71dbeff3c-7ff71dbeff3f 1014->1016 1016->1011 1018 7ff71dbeff45-7ff71dbeff56 1016->1018 1020 7ff71dbeff80-7ff71dbeff84 1018->1020 1021 7ff71dbeff58-7ff71dbeff61 call 7ff71dbefe80 1018->1021 1020->1011 1024 7ff71dbeff8a-7ff71dbeff8e 1020->1024 1021->1011 1027 7ff71dbeff67-7ff71dbeff6a 1021->1027 1024->1011 1026 7ff71dbeff94-7ff71dbeff98 1024->1026 1026->1011 1028 7ff71dbeff9e-7ff71dbeffae call 7ff71dbefe80 1026->1028 1027->1011 1029 7ff71dbeff70-7ff71dbeff73 1027->1029 1033 7ff71dbeffb0-7ff71dbeffb3 1028->1033 1034 7ff71dbeffb7 call 7ff71dbf6af4 1028->1034 1029->1011 1031 7ff71dbeff79 1029->1031 1031->1020 1033->1034 1035 7ff71dbeffb5 1033->1035 1037 7ff71dbeffbc-7ff71dbeffd3 call 7ff71dbf5ef8 1034->1037 1035->1034 1040 7ff71dbeffd9-7ff71dbeffe4 call 7ff71dbf5f28 1037->1040 1041 7ff71dbf00fa-7ff71dbf010f call 7ff71dbeb184 1037->1041 1040->1041 1046 7ff71dbeffea-7ff71dbefff5 call 7ff71dbf5f58 1040->1046 1046->1041 1049 7ff71dbefffb-7ff71dbf008f 1046->1049 1050 7ff71dbf0091-7ff71dbf00ad 1049->1050 1051 7ff71dbf00c9-7ff71dbf00cc 1049->1051 1052 7ff71dbf00c4-7ff71dbf00c7 1050->1052 1053 7ff71dbf00af-7ff71dbf00b3 1050->1053 1051->1017 1052->1017 1053->1052 1054 7ff71dbf00b5-7ff71dbf00c0 call 7ff71dbf6b38 1053->1054 1054->1052
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _get_daylight$_isindst
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 4170891091-0
                                                                                                                                                                                                                                    • Opcode ID: 370ce9d4f2c7d76b293318dbc6090e4c5bee4dbd118fb82c4348fa72ec4c37d0
                                                                                                                                                                                                                                    • Instruction ID: a42d0e4d78e19cbbfc85e962caa1d5808c1c7399beca19723d1f9505a5b6bfc9
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 370ce9d4f2c7d76b293318dbc6090e4c5bee4dbd118fb82c4348fa72ec4c37d0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 20513B72F09A1546FB34EF3484417BCA751AB04378F904139DD1F53AE5EF38A44A8B10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2780335769-0
                                                                                                                                                                                                                                    • Opcode ID: 51a8a2fe9574b92c1b1a31e26e80e74b549c8e92adf517a132492e05c7b56290
                                                                                                                                                                                                                                    • Instruction ID: fc524d4be20a38e80012cc8330e76b65e76bc3f432a1aa16238d22f1baba2e6f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 51a8a2fe9574b92c1b1a31e26e80e74b549c8e92adf517a132492e05c7b56290
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3F518622E0CA4185FB34EF71D4503BDA7E1EB48768F508535DE0A67685FF38E4458B20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1279662727-0
                                                                                                                                                                                                                                    • Opcode ID: 22c7c8ea93c6e55cd6304c5d27c7b8c20ea285c7b5b8d17ce3e3754178751948
                                                                                                                                                                                                                                    • Instruction ID: 57bc394ebc67d1fe27818d97fc2fcce52c99c10af75ff3afe0636bb644c79728
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 22c7c8ea93c6e55cd6304c5d27c7b8c20ea285c7b5b8d17ce3e3754178751948
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5F41B622D1CB8143E770AB2195503B9A3A0FF98374F509335E65E13AD1FF6CA5A48B20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3058843127-0
                                                                                                                                                                                                                                    • Opcode ID: 7cbc3ccfbc8636d3bb4ea780b1106156ddb9104c1ea8e27ac65454a1d4f029ca
                                                                                                                                                                                                                                    • Instruction ID: 115f6fe6ea266c5be9a0b7c9e9deecb57efe22668f3013c2686a5966dcc99a15
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7cbc3ccfbc8636d3bb4ea780b1106156ddb9104c1ea8e27ac65454a1d4f029ca
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 94310E11A0CE4281EA34BB6595617BDE2A1AF45BA8FC44434E50F072D7FE2DE80D8E79
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Process$CurrentExitTerminate
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1703294689-0
                                                                                                                                                                                                                                    • Opcode ID: d42b1d15f89cff999c412ea6ed71aaaa637f6e35a99c016800735a1d81ea02f1
                                                                                                                                                                                                                                    • Instruction ID: 56df35ec8764a3b5ee284cbc97f848157549976ed082ddd60bd3cca677377db3
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d42b1d15f89cff999c412ea6ed71aaaa637f6e35a99c016800735a1d81ea02f1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DAD06710B5CA0642EA343B719C994B993155F49721B90143CC81B27393EE2DA84D4A24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3215553584-0
                                                                                                                                                                                                                                    • Opcode ID: 9984e4d9f7a55e09bc11c7d35f089592e1d844af62e83f1c9a7169eb0bd1663a
                                                                                                                                                                                                                                    • Instruction ID: a321447116d43cd968a2c5f9a7947900dec7dc1ee433361231cb8b4b65f77472
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9984e4d9f7a55e09bc11c7d35f089592e1d844af62e83f1c9a7169eb0bd1663a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2C51EC62E0DEC285F638AE25941067AE681BF4CBBCF984634DD6E477C5EF3CD4058A21
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: FileHandleType
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3000768030-0
                                                                                                                                                                                                                                    • Opcode ID: 89c3bb33dcc8d8fb84e538812bfc243b46b619b3f5bfaaaab49fc6713e7ed776
                                                                                                                                                                                                                                    • Instruction ID: 43d74480ca27234e469180f1a56477cd00fc17ef1ef8713a579f60829f141246
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 89c3bb33dcc8d8fb84e538812bfc243b46b619b3f5bfaaaab49fc6713e7ed776
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AD314821A1CF4181D7709B16858007CAA50FB4ABB0FA44339DB6F573E0EF39E895D710
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • FindCloseChangeNotification.KERNELBASE(?,?,?,00007FF71DBEB259,?,?,00000000,00007FF71DBEB30E), ref: 00007FF71DBEB44A
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(?,?,?,00007FF71DBEB259,?,?,00000000,00007FF71DBEB30E), ref: 00007FF71DBEB454
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ChangeCloseErrorFindLastNotification
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1687624791-0
                                                                                                                                                                                                                                    • Opcode ID: 9b2d7134de24883dfe1bed83b750e6d11ab913f1325c24bc3ad054c6785d1330
                                                                                                                                                                                                                                    • Instruction ID: 80e36f01d62e12629b3907cabbf6449f3db17ce87bc088df39f690531ba6927b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9b2d7134de24883dfe1bed83b750e6d11ab913f1325c24bc3ad054c6785d1330
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8321C621F0CE8241FEB4B725A59127D92919F88BB4F844335DA2F573C2EE6CA44D9B24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • SetFilePointerEx.KERNELBASE(?,?,?,?,?,00007FF71DBEC9A0,?,?,?,?,00007FF71DBD1023,00007FF71DBECAA9), ref: 00007FF71DBECA00
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(?,?,?,?,?,00007FF71DBEC9A0,?,?,?,?,00007FF71DBD1023,00007FF71DBECAA9), ref: 00007FF71DBECA0A
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorFileLastPointer
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2976181284-0
                                                                                                                                                                                                                                    • Opcode ID: 126ad919738aaa719abfbc17f8cc0c41deb71979501f9dc1ba73a397eb3649da
                                                                                                                                                                                                                                    • Instruction ID: 295fde23c61664d8ae5d78a24424e2790eafb6c4194ce5de9c3494ede16f0181
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 126ad919738aaa719abfbc17f8cc0c41deb71979501f9dc1ba73a397eb3649da
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3911C46170CF9181DA30AB25A404169E365BB48BF4F944331EEBE577D9EF3CD4598B00
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF71DBE5AD9), ref: 00007FF71DBE5BF7
                                                                                                                                                                                                                                    • SystemTimeToTzSpecificLocalTime.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF71DBE5AD9), ref: 00007FF71DBE5C0D
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Time$System$FileLocalSpecific
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1707611234-0
                                                                                                                                                                                                                                    • Opcode ID: 5b1745944c8e1f0208f906cdcb64eb36400219f32dfaba174e5aece3a08df2ec
                                                                                                                                                                                                                                    • Instruction ID: 448186566f9654b3c8155fe9802ae54ee78f4eccc622022fa4c92800c06a63ce
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5b1745944c8e1f0208f906cdcb64eb36400219f32dfaba174e5aece3a08df2ec
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5611983151CA5681EA746F10A41117EF7A0EB44771F900235F69E869D4FF6CE058DF20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • RtlRestoreThreadPreferredUILanguages.NTDLL(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1E2
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1EC
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorLanguagesLastPreferredRestoreThread
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 588628887-0
                                                                                                                                                                                                                                    • Opcode ID: 0e60ec9bcbeaef1bc6e8c9d3a4a5a79c6aef9ce5968bebdcadd0a596a0a29cab
                                                                                                                                                                                                                                    • Instruction ID: 72c2dc10bd5253c8c60c4bd52af761b4ce294b4538370e7aed247e68ef7bcc09
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0e60ec9bcbeaef1bc6e8c9d3a4a5a79c6aef9ce5968bebdcadd0a596a0a29cab
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E7E08C10F0CE0282FF38BFB2984507896904F98B60FC40234C92F67261FE2CA98E4B34
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DirectoryErrorLastRemove
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 377330604-0
                                                                                                                                                                                                                                    • Opcode ID: cf01615f97efe34a086462c80a9cc6781e111c0a2437e4ded728319ce65b2c78
                                                                                                                                                                                                                                    • Instruction ID: 7f6bb19d1faa936731bc4ee20d7434d95de4b62c3664c1237686fd6f678bfc4d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cf01615f97efe34a086462c80a9cc6781e111c0a2437e4ded728319ce65b2c78
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7DD0C914E1CD0281EA343B761C0607990906F9C770FD00634C42BD22D1FD6CA98D0A32
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DeleteErrorFileLast
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2018770650-0
                                                                                                                                                                                                                                    • Opcode ID: 67604593d98026fdc8848f919e48d1c3d34ef258b7d123369eb86f310e7cac90
                                                                                                                                                                                                                                    • Instruction ID: 464cba8c21adbb7ca1591fecb4938d6bd0763f0963042651b8be24b6d67389b8
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 67604593d98026fdc8848f919e48d1c3d34ef258b7d123369eb86f310e7cac90
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1DD01218F2CD0381EA743BB52C5517DD5902F98734FD41634C42B922D0FD5CA98D0E36
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ByteCharMultiWide_findclose
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2772937645-0
                                                                                                                                                                                                                                    • Opcode ID: af99be2f07f2496aa3316734a2c6b8900cd6e6c5e1a7ca73bb10cee4439b99b0
                                                                                                                                                                                                                                    • Instruction ID: ba2d7a28ac4387442a93798ada34a0c89acd953e995a8955112fe44f94145dea
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: af99be2f07f2496aa3316734a2c6b8900cd6e6c5e1a7ca73bb10cee4439b99b0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 74719D52E1CEC581EA219B2CC5152FDA360F7A8B5CF94E321DB9D12592FF28E2D9C700
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3215553584-0
                                                                                                                                                                                                                                    • Opcode ID: e6a1a6245d13ac9f392e831fc71363616ea603e6fd74d20c900946fba1b20a08
                                                                                                                                                                                                                                    • Instruction ID: 766cfa1a9a551db41649e3f91e83f9f637057e53b91a1d47b106e8b67f4728fb
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e6a1a6245d13ac9f392e831fc71363616ea603e6fd74d20c900946fba1b20a08
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AA41C93290CA4187EA34AB19A540279B7A4EB5D760F900135DB9FA37D1EF2CE807CF61
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _fread_nolock
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 840049012-0
                                                                                                                                                                                                                                    • Opcode ID: 7a6a9953cb27000a8e432e82601514793e8c9596b1829e06e9d3b57bb966bb43
                                                                                                                                                                                                                                    • Instruction ID: 1fec0fc674b9e346340cbfa170cce594109d8b1577252fda6ce70354460c9c77
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7a6a9953cb27000a8e432e82601514793e8c9596b1829e06e9d3b57bb966bb43
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 67213221B0DE9145EE34AA1269147F9E651BF45BECFC85431EE0F07786EE3CE04A8A21
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3215553584-0
                                                                                                                                                                                                                                    • Opcode ID: d50056e13121e088fd956b9fa59aa1edf025f204b261fbd69ab4f9f5d265a547
                                                                                                                                                                                                                                    • Instruction ID: b5cd93ce6e4e991f31d17e6bceb017fbcf5ce8a000c656940c76234eb2c39135
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d50056e13121e088fd956b9fa59aa1edf025f204b261fbd69ab4f9f5d265a547
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5A31B022A1CE5285F6357F95D84037CA790AB48B70FD50135E91E233D2EE7CE44A9B31
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: HandleModule$AddressFreeLibraryProc
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3947729631-0
                                                                                                                                                                                                                                    • Opcode ID: fd6f95c3572bf754f8497049759945b2e7c0237f0ec2a3ff2fce099309aa049a
                                                                                                                                                                                                                                    • Instruction ID: 97b5050a69e43369a14065442b8951b22165b3842c29b7484eac02d69a2c96f3
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fd6f95c3572bf754f8497049759945b2e7c0237f0ec2a3ff2fce099309aa049a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 55217132E08A4589EB34AFA4D4502FD73A4EB48728F841635D71E27AD5EF39D548CB60
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3215553584-0
                                                                                                                                                                                                                                    • Opcode ID: 230eb0b453f50547337b140c98883f6bc8fad4d25c6c65a93efb138b352d5fb0
                                                                                                                                                                                                                                    • Instruction ID: a1eb029a6149ab4b6ea4622d6857da6f15d1457392d8e92340f3d3987651112c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 230eb0b453f50547337b140c98883f6bc8fad4d25c6c65a93efb138b352d5fb0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 78116621A2CA4185EE71BF5194102BDE3A4BF99BA0FD44935EA4E67796FF3CD4048F20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3215553584-0
                                                                                                                                                                                                                                    • Opcode ID: 1765455d41bca3f2b959ba3621f16cf0597a8683876aeae35adaef8a4375950f
                                                                                                                                                                                                                                    • Instruction ID: 6bde545704bebe3a36ab631566ebca375024b8f1865162c8ec53305e024f6ef6
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1765455d41bca3f2b959ba3621f16cf0597a8683876aeae35adaef8a4375950f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 32214833A1CE4186DB71AF24D4403B9B6A0EB94B64F944234EA5E476D9EF3DD805CF10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3215553584-0
                                                                                                                                                                                                                                    • Opcode ID: cd44b4cff77b60623d985737580ed1813df099190acaa202378a92fd92a14a74
                                                                                                                                                                                                                                    • Instruction ID: 108d16d1e4f016ad2256c97f33b9ce9e94a14f09f9d83936989339b2dff281d2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cd44b4cff77b60623d985737580ed1813df099190acaa202378a92fd92a14a74
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B501A522A0CF8240E934AB526810169E6E5BF99FF4F888231DE5D63BD6EF3CE4054B10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • RtlAllocateHeap.NTDLL(?,?,00000000,00007FF71DBEBC66,?,?,?,00007FF71DBEAE27,?,?,00000000,00007FF71DBEB0C2), ref: 00007FF71DBEF485
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AllocateHeap
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1279760036-0
                                                                                                                                                                                                                                    • Opcode ID: 89b1110bf6de89d28fe3272bd006b9300fe142e42d1b683599a8f3a890580cc9
                                                                                                                                                                                                                                    • Instruction ID: 1b923a4fb5e042a8a642cbef8c599470072b60780db10f8e9c821c8ea172fb7b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 89b1110bf6de89d28fe3272bd006b9300fe142e42d1b683599a8f3a890580cc9
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B3F04F46B0DA0341FE74776194912B982A45F8DF70F884634C90F673D1FD1CE5894A30
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • RtlAllocateHeap.NTDLL(?,?,?,00007FF71DBE0224,?,?,?,00007FF71DBE1736,?,?,?,?,?,00007FF71DBE379D), ref: 00007FF71DBEDEBA
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AllocateHeap
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1279760036-0
                                                                                                                                                                                                                                    • Opcode ID: a59a3281ffe6c4ebb895ab54eba730b3e58e72ac8a9ed321292ae6a6c92afa7f
                                                                                                                                                                                                                                    • Instruction ID: 31b95c24e882504c7b601da07c76b69fa780a5319f91c49e61c5f6294c2bddb5
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a59a3281ffe6c4ebb895ab54eba730b3e58e72ac8a9ed321292ae6a6c92afa7f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 92F03A00B0DA4245FE747779584527992904FAC770FC80630982F672C1FE5CA4498A31
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DirectoryErrorLastRemove
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 377330604-0
                                                                                                                                                                                                                                    • Opcode ID: 11d6793fb54fd8debb9369a4c74f62d3d3ffc2ad23ee3de877a3213ac8242fd7
                                                                                                                                                                                                                                    • Instruction ID: 2a6f88cb96bca8fd40a352f81ff7049f66b942eeef90278b6c9ffcb347d2a06e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 11d6793fb54fd8debb9369a4c74f62d3d3ffc2ad23ee3de877a3213ac8242fd7
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 93419A16D1CEC641EA31AB2495112FC7360FBA5758F94A632DB8E52153FF28E5DCC720
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc
                                                                                                                                                                                                                                    • String ID: Failed to get address for Tcl_Alloc$Failed to get address for Tcl_ConditionFinalize$Failed to get address for Tcl_ConditionNotify$Failed to get address for Tcl_ConditionWait$Failed to get address for Tcl_CreateInterp$Failed to get address for Tcl_CreateObjCommand$Failed to get address for Tcl_CreateThread$Failed to get address for Tcl_DeleteInterp$Failed to get address for Tcl_DoOneEvent$Failed to get address for Tcl_EvalEx$Failed to get address for Tcl_EvalFile$Failed to get address for Tcl_EvalObjv$Failed to get address for Tcl_Finalize$Failed to get address for Tcl_FinalizeThread$Failed to get address for Tcl_FindExecutable$Failed to get address for Tcl_Free$Failed to get address for Tcl_GetCurrentThread$Failed to get address for Tcl_GetObjResult$Failed to get address for Tcl_GetString$Failed to get address for Tcl_GetVar2$Failed to get address for Tcl_Init$Failed to get address for Tcl_MutexLock$Failed to get address for Tcl_MutexUnlock$Failed to get address for Tcl_NewByteArrayObj$Failed to get address for Tcl_NewStringObj$Failed to get address for Tcl_SetVar2$Failed to get address for Tcl_SetVar2Ex$Failed to get address for Tcl_ThreadAlert$Failed to get address for Tcl_ThreadQueueEvent$Failed to get address for Tk_GetNumMainWindows$Failed to get address for Tk_Init$GetProcAddress$Tcl_Alloc$Tcl_ConditionFinalize$Tcl_ConditionNotify$Tcl_ConditionWait$Tcl_CreateInterp$Tcl_CreateObjCommand$Tcl_CreateThread$Tcl_DeleteInterp$Tcl_DoOneEvent$Tcl_EvalEx$Tcl_EvalFile$Tcl_EvalObjv$Tcl_Finalize$Tcl_FinalizeThread$Tcl_FindExecutable$Tcl_Free$Tcl_GetCurrentThread$Tcl_GetObjResult$Tcl_GetString$Tcl_GetVar2$Tcl_Init$Tcl_MutexLock$Tcl_MutexUnlock$Tcl_NewByteArrayObj$Tcl_NewStringObj$Tcl_SetVar2$Tcl_SetVar2Ex$Tcl_ThreadAlert$Tcl_ThreadQueueEvent$Tk_GetNumMainWindows$Tk_Init
                                                                                                                                                                                                                                    • API String ID: 190572456-2208601799
                                                                                                                                                                                                                                    • Opcode ID: b1a607239f8517a729b3d652d22cd5db79448a9b5e9ee3baec4123bb94c2d34d
                                                                                                                                                                                                                                    • Instruction ID: 3c8271c3be42e3a1fa4ae50341c4c31e68a8cd82fc2dabb471e2a251a34d4bf0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b1a607239f8517a729b3d652d22cd5db79448a9b5e9ee3baec4123bb94c2d34d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2BE1C664A4EF0790FA35AB18A8542B4A3A5AF087B5FC46535C82F06264FF7CF55CCB24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3140674995-0
                                                                                                                                                                                                                                    • Opcode ID: 5292a8a5a971cd825b96bdf4279ba62df65a4148ba3cf04c0a3a98a1218dcbbd
                                                                                                                                                                                                                                    • Instruction ID: 290491021b66106f2eff4df5c2d6964bb852d920b5787258b2dc1e8c68138bdf
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5292a8a5a971cd825b96bdf4279ba62df65a4148ba3cf04c0a3a98a1218dcbbd
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B3312172619E8189EB709F60E8907ED7365FB44758F844039DA4E47B98EF38D64CCB24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1239891234-0
                                                                                                                                                                                                                                    • Opcode ID: 7350904de150d1cb4172e17eeb8809c0d9adbb64f65e259fb5dcc6004eced91a
                                                                                                                                                                                                                                    • Instruction ID: 862a0a04bd0fa7ddc3639e3ca6c70dfe37f8ba29dab23fc15fa66fbafaceeaa2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7350904de150d1cb4172e17eeb8809c0d9adbb64f65e259fb5dcc6004eced91a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5F316236618F8185DB70DF25E8406AEB3A4FB88764F940135EA9E43B54EF3CD559CB10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: FileFindFirst_invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2227656907-0
                                                                                                                                                                                                                                    • Opcode ID: f5f139a55f972c05e0c5d89b196deaf72ef60d6fd941209caf0256bee93f9f9c
                                                                                                                                                                                                                                    • Instruction ID: 92b27bb75a6025f83e14e07eb289be0eaf6abb7d3b3894da752597762960dd3e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f5f139a55f972c05e0c5d89b196deaf72ef60d6fd941209caf0256bee93f9f9c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 00B1C462B1CE8641EA74AB2198406F9E351EB45BF4FC44131EE5F87BC5EE7CE4498B20
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: 1fb11526f0929feff4cc1f422dba12fb12f2c28f8ba1b321171814a7f24c0614
                                                                                                                                                                                                                                    • Instruction ID: 5e34343cb4c45207506eee30dfd94e160dc1af40069fd1449f030c62c5899d5b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1fb11526f0929feff4cc1f422dba12fb12f2c28f8ba1b321171814a7f24c0614
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 54F04471718A658EDBA49F29A442629B7D0E748390BC08579D58983F08D63C90558F14
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc
                                                                                                                                                                                                                                    • String ID: Failed to get address for PyConfig_Clear$Failed to get address for PyConfig_InitIsolatedConfig$Failed to get address for PyConfig_Read$Failed to get address for PyConfig_SetBytesString$Failed to get address for PyConfig_SetString$Failed to get address for PyConfig_SetWideStringList$Failed to get address for PyErr_Clear$Failed to get address for PyErr_Fetch$Failed to get address for PyErr_NormalizeException$Failed to get address for PyErr_Occurred$Failed to get address for PyErr_Print$Failed to get address for PyErr_Restore$Failed to get address for PyEval_EvalCode$Failed to get address for PyImport_AddModule$Failed to get address for PyImport_ExecCodeModule$Failed to get address for PyImport_ImportModule$Failed to get address for PyList_Append$Failed to get address for PyMarshal_ReadObjectFromString$Failed to get address for PyMem_RawFree$Failed to get address for PyModule_GetDict$Failed to get address for PyObject_CallFunction$Failed to get address for PyObject_CallFunctionObjArgs$Failed to get address for PyObject_GetAttrString$Failed to get address for PyObject_SetAttrString$Failed to get address for PyObject_Str$Failed to get address for PyPreConfig_InitIsolatedConfig$Failed to get address for PyRun_SimpleStringFlags$Failed to get address for PyStatus_Exception$Failed to get address for PySys_GetObject$Failed to get address for PySys_SetObject$Failed to get address for PyUnicode_AsUTF8$Failed to get address for PyUnicode_Decode$Failed to get address for PyUnicode_DecodeFSDefault$Failed to get address for PyUnicode_FromFormat$Failed to get address for PyUnicode_FromString$Failed to get address for PyUnicode_Join$Failed to get address for PyUnicode_Replace$Failed to get address for Py_DecRef$Failed to get address for Py_DecodeLocale$Failed to get address for Py_ExitStatusException$Failed to get address for Py_Finalize$Failed to get address for Py_InitializeFromConfig$Failed to get address for Py_IsInitialized$Failed to get address for Py_PreInitialize$GetProcAddress$PyConfig_Clear$PyConfig_InitIsolatedConfig$PyConfig_Read$PyConfig_SetBytesString$PyConfig_SetString$PyConfig_SetWideStringList$PyErr_Clear$PyErr_Fetch$PyErr_NormalizeException$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyEval_EvalCode$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ImportModule$PyList_Append$PyMarshal_ReadObjectFromString$PyMem_RawFree$PyModule_GetDict$PyObject_CallFunction$PyObject_CallFunctionObjArgs$PyObject_GetAttrString$PyObject_SetAttrString$PyObject_Str$PyPreConfig_InitIsolatedConfig$PyRun_SimpleStringFlags$PyStatus_Exception$PySys_GetObject$PySys_SetObject$PyUnicode_AsUTF8$PyUnicode_Decode$PyUnicode_DecodeFSDefault$PyUnicode_FromFormat$PyUnicode_FromString$PyUnicode_Join$PyUnicode_Replace$Py_DecRef$Py_DecodeLocale$Py_ExitStatusException$Py_Finalize$Py_InitializeFromConfig$Py_IsInitialized$Py_PreInitialize
                                                                                                                                                                                                                                    • API String ID: 190572456-4266016200
                                                                                                                                                                                                                                    • Opcode ID: 3cdbd3228bcaf959503b86dc7f57490f257e6b424ca5642a8cbbc9134cad9dd6
                                                                                                                                                                                                                                    • Instruction ID: 76616495c952f2e2eb2f0d4397de36777b8cd8b8fa03e3821cf30e56c5a8aad0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3cdbd3228bcaf959503b86dc7f57490f257e6b424ca5642a8cbbc9134cad9dd6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0A129165A4EF0390FA35AB18A8A45B4A3A5AF047B4FD45435C80F06264FF7CF59D8F24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • MultiByteToWideChar.KERNEL32 ref: 00007FF71DBD7E2C
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD2070: GetLastError.KERNEL32(?,?,00000000,00007FF71DBD7A52,?,?,?,?,?,?,?,?,?,?,?,00007FF71DBD1023), ref: 00007FF71DBD2097
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ByteCharErrorLastMultiWide
                                                                                                                                                                                                                                    • String ID: Failed to decode wchar_t from UTF-8$Failed to encode filename as ANSI.$Failed to get ANSI buffer size.$Failed to get wchar_t buffer size.$MultiByteToWideChar$Out of memory.$WideCharToMultiByte$win32_utils_from_utf8$win32_wcs_to_mbs
                                                                                                                                                                                                                                    • API String ID: 203985260-1562484376
                                                                                                                                                                                                                                    • Opcode ID: 5f038aab294c8fd19a923c01861dc675f16c94493efdf241cf7f408caab26175
                                                                                                                                                                                                                                    • Instruction ID: 45884f5662af7a164262168867ded7c152f8035d781c7159004ebfd146dc840a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5f038aab294c8fd19a923c01861dc675f16c94493efdf241cf7f408caab26175
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CA418621A0CF8341EB30BB26A8501BAE695AF447F4FC44535E95F47AA5FF3CE5098B60
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _fread_nolock
                                                                                                                                                                                                                                    • String ID: %s%c%s$Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$\$fread$fseek$malloc
                                                                                                                                                                                                                                    • API String ID: 840049012-2316137593
                                                                                                                                                                                                                                    • Opcode ID: 280050e0e3c7c8d26c2d51216203f91453f84d42608cb368c3e6801c631684fa
                                                                                                                                                                                                                                    • Instruction ID: 39433429dc5ab00fc64a4735d7cd4a6dbda50fb07ea8c121b247069c652cd803
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 280050e0e3c7c8d26c2d51216203f91453f84d42608cb368c3e6801c631684fa
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E3514261A0DE8355EA30BB11A8616FAA254EF447E8FC04131EA4F47B99FE7CE5498F10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(WideCharToMultiByte,00007FF71DBD20A4,?,?,00000000,00007FF71DBD7A52), ref: 00007FF71DBD77E7
                                                                                                                                                                                                                                    • FormatMessageW.KERNEL32 ref: 00007FF71DBD7816
                                                                                                                                                                                                                                    • WideCharToMultiByte.KERNEL32 ref: 00007FF71DBD786C
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD2070: GetLastError.KERNEL32(?,?,00000000,00007FF71DBD7A52,?,?,?,?,?,?,?,?,?,?,?,00007FF71DBD1023), ref: 00007FF71DBD2097
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorLast$ByteCharFormatMessageMultiWide
                                                                                                                                                                                                                                    • String ID: Failed to encode wchar_t as UTF-8.$FormatMessageW$No error messages generated.$PyInstaller: FormatMessageW failed.$PyInstaller: pyi_win32_utils_to_utf8 failed.$WideCharToMultiByte
                                                                                                                                                                                                                                    • API String ID: 2383786077-2573406579
                                                                                                                                                                                                                                    • Opcode ID: 7c57e2b6ebb6fcdc26cf68156021833fc54c556c30b231cb159875f8ec6ec51b
                                                                                                                                                                                                                                    • Instruction ID: 1dee6d2130b6ad1353040a74e13cec33defa16e1eda672f038eac12a1035de87
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7c57e2b6ebb6fcdc26cf68156021833fc54c556c30b231cb159875f8ec6ec51b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 43215C61A1CE8281EA70AF15E8603A5A3A5BB483A8FC04135E55F826A5FF3CD509CF24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: -$:$f$p$p
                                                                                                                                                                                                                                    • API String ID: 3215553584-2013873522
                                                                                                                                                                                                                                    • Opcode ID: 200fc6eded9d23d85e23f8288f3e7e64d2d75ea1ebf8e7eab3da15fbea06ec83
                                                                                                                                                                                                                                    • Instruction ID: 9197349b2efae24ab5ed81d50bdbc9a003242eaa807d4a45d0894942cc0f703d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 200fc6eded9d23d85e23f8288f3e7e64d2d75ea1ebf8e7eab3da15fbea06ec83
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 51129F61A0CA4386FB34BB15D1542BAB691EB48760FD48835D68B676C5FF3CE488DF20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: f$f$p$p$f
                                                                                                                                                                                                                                    • API String ID: 3215553584-1325933183
                                                                                                                                                                                                                                    • Opcode ID: 5150cc2f17f8123f8b3830771489176596fdb62c48b2c84a137625a88c910901
                                                                                                                                                                                                                                    • Instruction ID: 1d88a44ed5db6de75a49c39dd4a2685865dd67445d23d6d2521f502adce1b69f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5150cc2f17f8123f8b3830771489176596fdb62c48b2c84a137625a88c910901
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 90127022A0C96386FB306B15D05437AF661EB98760FC44035E69B676C4EF7CE888DF21
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                                                    • API String ID: 0-3659356012
                                                                                                                                                                                                                                    • Opcode ID: 384ff366afc6b9b5215a92974b01ff24ffb67964e8602296fcae0b8fe6846d6a
                                                                                                                                                                                                                                    • Instruction ID: 41fec4ee774858a6e8cabb0cf2af4a862e2e7d438b37a0fd76e8535e2f6ad9e2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 384ff366afc6b9b5215a92974b01ff24ffb67964e8602296fcae0b8fe6846d6a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F5315E21B0CE8246EA34BB52A4605BAE350EF447E8FD84131DE4F07A55FE3CE5498B20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                                                                                                                                                                                                                    • String ID: csm$csm$csm
                                                                                                                                                                                                                                    • API String ID: 849930591-393685449
                                                                                                                                                                                                                                    • Opcode ID: 1d9cba0ee705458a84b9eb7887f8bd16089d36748883092d9b0ee740c596672d
                                                                                                                                                                                                                                    • Instruction ID: 72e8b755f5bb0ea6ea20edc74098701bf070e8e50aa04f4fac9baeb28eb9959c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1d9cba0ee705458a84b9eb7887f8bd16089d36748883092d9b0ee740c596672d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1DE18132A0CF4186EB30AF6594512ADB7A0FB45BACF504135EE8E57755EF38E488CB50
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF71DBD1023), ref: 00007FF71DBD79A7
                                                                                                                                                                                                                                    • WideCharToMultiByte.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,00007FF71DBD1023), ref: 00007FF71DBD79FE
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ByteCharMultiWide
                                                                                                                                                                                                                                    • String ID: Failed to encode wchar_t as UTF-8.$Failed to get UTF-8 buffer size.$Out of memory.$WideCharToMultiByte$win32_utils_to_utf8
                                                                                                                                                                                                                                    • API String ID: 626452242-27947307
                                                                                                                                                                                                                                    • Opcode ID: b858524ce6855f304c8efe565ccb1bc8f57016cef4207499ca899fb6c0c33817
                                                                                                                                                                                                                                    • Instruction ID: 4c4c4d2fc791262ba53ee89fecf3568120b2172be4241647c154dbbd14d7a6f7
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b858524ce6855f304c8efe565ccb1bc8f57016cef4207499ca899fb6c0c33817
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5A417F3260CE8282DA30EF15A8501AAF7A5FB447A4F945135DA9F43B94FF3CD5598B10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • WideCharToMultiByte.KERNEL32(00000000,00007FF71DBD30F5), ref: 00007FF71DBD8101
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD2070: GetLastError.KERNEL32(?,?,00000000,00007FF71DBD7A52,?,?,?,?,?,?,?,?,?,?,?,00007FF71DBD1023), ref: 00007FF71DBD2097
                                                                                                                                                                                                                                    • WideCharToMultiByte.KERNEL32(00000000,00007FF71DBD30F5), ref: 00007FF71DBD8175
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ByteCharMultiWide$ErrorLast
                                                                                                                                                                                                                                    • String ID: Failed to encode wchar_t as UTF-8.$Failed to get UTF-8 buffer size.$Out of memory.$WideCharToMultiByte$win32_utils_to_utf8
                                                                                                                                                                                                                                    • API String ID: 1717984340-27947307
                                                                                                                                                                                                                                    • Opcode ID: 671ff269c8b490ce50744ff8f5587712a6cf4c5d2a9d3efd05795890c2378c30
                                                                                                                                                                                                                                    • Instruction ID: c7a5a288c5216e5facbed843ca3f38ad0277ef1ada5fbd08939a8faaef43f441
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 671ff269c8b490ce50744ff8f5587712a6cf4c5d2a9d3efd05795890c2378c30
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 70216265B0CF4285E630EF16A8502B9B762FB48BA4F944535DA5E43764FF3CE508CB10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo$_fread_nolock
                                                                                                                                                                                                                                    • String ID: %s%c%s$ERROR: file already exists but should not: %s$PYINSTALLER_STRICT_UNPACK_MODE$WARNING: file already exists but should not: %s$\
                                                                                                                                                                                                                                    • API String ID: 3231891352-3501660386
                                                                                                                                                                                                                                    • Opcode ID: 1bdb94ff4c3bcf12e5c576ede5f6fa54997d4bd2e51bac677fa57c109b0af2ab
                                                                                                                                                                                                                                    • Instruction ID: d5b48d2edb909fc859e54e0c92f4887a4e01e4e3905b69c2bf913ab67422981e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1bdb94ff4c3bcf12e5c576ede5f6fa54997d4bd2e51bac677fa57c109b0af2ab
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 83516E21A0DE8741FA34BB2599202B9D2919F897B8FC44131E94F877D6FE2CE50DCB20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD7FB0: MultiByteToWideChar.KERNEL32 ref: 00007FF71DBD7FEA
                                                                                                                                                                                                                                    • ExpandEnvironmentStringsW.KERNEL32(00000000,00007FF71DBD6BA1,00000000,00000000,00000000,00000000,?,00007FF71DBD154F), ref: 00007FF71DBD667F
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • LOADER: Failed to convert runtime-tmpdir to a wide string., xrefs: 00007FF71DBD6656
                                                                                                                                                                                                                                    • LOADER: Failed to obtain the absolute path of the runtime-tmpdir., xrefs: 00007FF71DBD66DA
                                                                                                                                                                                                                                    • LOADER: Failed to expand environment variables in the runtime-tmpdir., xrefs: 00007FF71DBD6693
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ByteCharEnvironmentExpandMultiStringsWide
                                                                                                                                                                                                                                    • String ID: LOADER: Failed to convert runtime-tmpdir to a wide string.$LOADER: Failed to expand environment variables in the runtime-tmpdir.$LOADER: Failed to obtain the absolute path of the runtime-tmpdir.
                                                                                                                                                                                                                                    • API String ID: 2001182103-3498232454
                                                                                                                                                                                                                                    • Opcode ID: 512057d8f16e869ec8b02829afa4c0683f2e94174ff51fe4728a8ab148420767
                                                                                                                                                                                                                                    • Instruction ID: f784cdbbf29e9d57481315128caf0b2a8d35c5220bb32c4543dd8802b5b5a658
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 512057d8f16e869ec8b02829afa4c0683f2e94174ff51fe4728a8ab148420767
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B3319E11B1CF8640FA34BB2198653FA9291AF987A4FC44035DA4F83796FE2CE50CCE24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • LoadLibraryExW.KERNEL32(?,?,?,00007FF71DBDD52A,?,?,?,00007FF71DBDD21C,?,?,00000001,00007FF71DBDCE39), ref: 00007FF71DBDD2FD
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(?,?,?,00007FF71DBDD52A,?,?,?,00007FF71DBDD21C,?,?,00000001,00007FF71DBDCE39), ref: 00007FF71DBDD30B
                                                                                                                                                                                                                                    • LoadLibraryExW.KERNEL32(?,?,?,00007FF71DBDD52A,?,?,?,00007FF71DBDD21C,?,?,00000001,00007FF71DBDCE39), ref: 00007FF71DBDD335
                                                                                                                                                                                                                                    • FreeLibrary.KERNEL32(?,?,?,00007FF71DBDD52A,?,?,?,00007FF71DBDD21C,?,?,00000001,00007FF71DBDCE39), ref: 00007FF71DBDD37B
                                                                                                                                                                                                                                    • GetProcAddress.KERNEL32(?,?,?,00007FF71DBDD52A,?,?,?,00007FF71DBDD21C,?,?,00000001,00007FF71DBDCE39), ref: 00007FF71DBDD387
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Library$Load$AddressErrorFreeLastProc
                                                                                                                                                                                                                                    • String ID: api-ms-
                                                                                                                                                                                                                                    • API String ID: 2559590344-2084034818
                                                                                                                                                                                                                                    • Opcode ID: 6bcac2c6d4744f46f93eb3f7cc5fd1049ae5631bf07c3cf9090e0e6883f90947
                                                                                                                                                                                                                                    • Instruction ID: 373459c4ffeb6c63821ef717e0dfb5b2e4f19e047c3fff9aa50ee21d22516ff2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6bcac2c6d4744f46f93eb3f7cc5fd1049ae5631bf07c3cf9090e0e6883f90947
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0D319221B1EF4295EE35BB1A94109A9A394BF44BB8F990534DD5E57380FE3CE4488B24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • MultiByteToWideChar.KERNEL32 ref: 00007FF71DBD7FEA
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD2070: GetLastError.KERNEL32(?,?,00000000,00007FF71DBD7A52,?,?,?,?,?,?,?,?,?,?,?,00007FF71DBD1023), ref: 00007FF71DBD2097
                                                                                                                                                                                                                                    • MultiByteToWideChar.KERNEL32 ref: 00007FF71DBD8070
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ByteCharMultiWide$ErrorLast
                                                                                                                                                                                                                                    • String ID: Failed to decode wchar_t from UTF-8$Failed to get wchar_t buffer size.$MultiByteToWideChar$Out of memory.$win32_utils_from_utf8
                                                                                                                                                                                                                                    • API String ID: 1717984340-876015163
                                                                                                                                                                                                                                    • Opcode ID: 61f1e1f65f2abf587f9c441370b1f9f094646be22c7fe0b557fd9129533f5ae1
                                                                                                                                                                                                                                    • Instruction ID: d56a56faec0b3e8362d8ab0238aff3f5423041f0fc44f9647481ac688e0d1e7e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 61f1e1f65f2abf587f9c441370b1f9f094646be22c7fe0b557fd9129533f5ae1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 16218725B0CE4241EB30EB2AF450165E761EF847E8F984135DB5D83B69FE2CD545CB10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Value$ErrorLast
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2506987500-0
                                                                                                                                                                                                                                    • Opcode ID: f2b34ce6245bf40951a90f27d1366218b7b91d15b1d25e2e49f5ff55d596edee
                                                                                                                                                                                                                                    • Instruction ID: 9d89e3794ada43adfb0f92b3182b88705e70351587bc92f6ddda2f5948340f55
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f2b34ce6245bf40951a90f27d1366218b7b91d15b1d25e2e49f5ff55d596edee
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B2218B21A4CE4281FA7877229551039E1564F4C7B0FD4A734D83F27AD6FE2CB8094E34
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                                                                                                                                                                                                    • String ID: CONOUT$
                                                                                                                                                                                                                                    • API String ID: 3230265001-3130406586
                                                                                                                                                                                                                                    • Opcode ID: 666c3d9e2718fc3e384982b01ad58156f77ff8708d305141843743c738123bff
                                                                                                                                                                                                                                    • Instruction ID: 7c3d4f9e48fbb54d6d260be02f69ed6454cac635f8a43316d052bd713dccb2ee
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 666c3d9e2718fc3e384982b01ad58156f77ff8708d305141843743c738123bff
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5C11E925B1CE5186E770AF46E854369E2A4FB48FF4F804634DA2E87794EF3CD9088B54
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • GetLastError.KERNEL32(?,?,?,00007FF71DBE7C51,?,?,?,?,00007FF71DBEF497,?,?,00000000,00007FF71DBEBC66,?,?,?), ref: 00007FF71DBEBB57
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBE7C51,?,?,?,?,00007FF71DBEF497,?,?,00000000,00007FF71DBEBC66,?,?,?), ref: 00007FF71DBEBB8D
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBE7C51,?,?,?,?,00007FF71DBEF497,?,?,00000000,00007FF71DBEBC66,?,?,?), ref: 00007FF71DBEBBBA
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBE7C51,?,?,?,?,00007FF71DBEF497,?,?,00000000,00007FF71DBEBC66,?,?,?), ref: 00007FF71DBEBBCB
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBE7C51,?,?,?,?,00007FF71DBEF497,?,?,00000000,00007FF71DBEBC66,?,?,?), ref: 00007FF71DBEBBDC
                                                                                                                                                                                                                                    • SetLastError.KERNEL32(?,?,?,00007FF71DBE7C51,?,?,?,?,00007FF71DBEF497,?,?,00000000,00007FF71DBEBC66,?,?,?), ref: 00007FF71DBEBBF7
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Value$ErrorLast
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2506987500-0
                                                                                                                                                                                                                                    • Opcode ID: 41c599df291fd3e631747b2aace2e23f0e8f3128d708c3cfb7bb859859b12653
                                                                                                                                                                                                                                    • Instruction ID: 78a51c6627067a35a027596e65e61a065a19d798eb9f866617da35d31601974a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 41c599df291fd3e631747b2aace2e23f0e8f3128d708c3cfb7bb859859b12653
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 87116325A4CE4241FA74B735554103AE1459F4D7B0FD44734D82F676DAFE2CE8094E34
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
                                                                                                                                                                                                                                    • String ID: csm$f
                                                                                                                                                                                                                                    • API String ID: 2395640692-629598281
                                                                                                                                                                                                                                    • Opcode ID: 6874ce62e9edfd12495692b318275d0e8d608d4f333f0d723dc3a41740f6e71d
                                                                                                                                                                                                                                    • Instruction ID: 75ea22c5bcec9c1f2020257a895b6b98ff618eb4d5fc4a0b370e89f3ed0cba37
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6874ce62e9edfd12495692b318275d0e8d608d4f333f0d723dc3a41740f6e71d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2251A732A1DE018AD774EF16D814A69BB55FB48BA8F908134DA4F43748EF38E849CB50
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                                                                                    • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                                                                    • API String ID: 4061214504-1276376045
                                                                                                                                                                                                                                    • Opcode ID: 2d8bae9984113d9ee1161ba42f49a1f9fa8607ff1cce463a2ed595953dbf4f55
                                                                                                                                                                                                                                    • Instruction ID: 52748427d5bb54e210cc6d09508fc6daec0db049e2ddcce3cb54c53d6d00d792
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2d8bae9984113d9ee1161ba42f49a1f9fa8607ff1cce463a2ed595953dbf4f55
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A4F06221A1CF0681EA30AB24E44477AD360EF497B1FD40639C57F462E4EF2CD44D8B24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _set_statfp
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1156100317-0
                                                                                                                                                                                                                                    • Opcode ID: a62d4fcbb0970871e45180a1f834c32a3c4d190302dd8db61346826940fa499d
                                                                                                                                                                                                                                    • Instruction ID: fba904883981a52d4e6f7aa2fe4f7f2ccf0605bb8111385e468c77cead3075aa
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a62d4fcbb0970871e45180a1f834c32a3c4d190302dd8db61346826940fa499d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B7114F72E1CE1341FA783564E4563FEA1406F583B4FC40635EA6F463D7EE2CAA8C4A25
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • FlsGetValue.KERNEL32(?,?,?,00007FF71DBEAE27,?,?,00000000,00007FF71DBEB0C2,?,?,?,?,?,00007FF71DBE2A80), ref: 00007FF71DBEBC2F
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBEAE27,?,?,00000000,00007FF71DBEB0C2,?,?,?,?,?,00007FF71DBE2A80), ref: 00007FF71DBEBC4E
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBEAE27,?,?,00000000,00007FF71DBEB0C2,?,?,?,?,?,00007FF71DBE2A80), ref: 00007FF71DBEBC76
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBEAE27,?,?,00000000,00007FF71DBEB0C2,?,?,?,?,?,00007FF71DBE2A80), ref: 00007FF71DBEBC87
                                                                                                                                                                                                                                    • FlsSetValue.KERNEL32(?,?,?,00007FF71DBEAE27,?,?,00000000,00007FF71DBEB0C2,?,?,?,?,?,00007FF71DBE2A80), ref: 00007FF71DBEBC98
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Value
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3702945584-0
                                                                                                                                                                                                                                    • Opcode ID: 4d9951ddb930028ea16999cbca66bd4ed784f1640a016819559599eea74df80b
                                                                                                                                                                                                                                    • Instruction ID: 9b119fea6d7136575846c331958bedbbc4958557f2f01e210cf7bb67718b88c3
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4d9951ddb930028ea16999cbca66bd4ed784f1640a016819559599eea74df80b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 80118C20E0CA0241FA78B7255541139D1455F4C3B0FC48734E82F277D6FE2CA84A9E34
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Value
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3702945584-0
                                                                                                                                                                                                                                    • Opcode ID: 2e04664127e5d8fea5349ed94c02016841b9f7de38eab6539d47ab1646b3bbb1
                                                                                                                                                                                                                                    • Instruction ID: 028f4ce320fa2d5ce6d972cab6d6ac8623076060e2d0051328cd83d76f1c227b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2e04664127e5d8fea5349ed94c02016841b9f7de38eab6539d47ab1646b3bbb1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AE11E020A4CA0785F978B732486117AE1458F4D370FD89B34D92F2B2D6FD2CB80A8E75
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: verbose
                                                                                                                                                                                                                                    • API String ID: 3215553584-579935070
                                                                                                                                                                                                                                    • Opcode ID: 1903bda87c4ff8796606e8a839c08c655b45d75bc3d73885c4b5b9d3096c4afd
                                                                                                                                                                                                                                    • Instruction ID: c64ea8cde99566aefe059434e056ac552265cfd843012c057d865bb851742834
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1903bda87c4ff8796606e8a839c08c655b45d75bc3d73885c4b5b9d3096c4afd
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: DC91CD22A0CE4681F735AB24D45037DB790AB48B64FC44936DA9F673D5EE3CE809CB21
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: UTF-16LEUNICODE$UTF-8$ccs
                                                                                                                                                                                                                                    • API String ID: 3215553584-1196891531
                                                                                                                                                                                                                                    • Opcode ID: a0eb1a53d3169c6808d927e78ed351066cc1cb27aa5cf4a039fc42470434503a
                                                                                                                                                                                                                                    • Instruction ID: 997df6f5c84004c02cbc9e523decd9136952bbc10f9286ee706e44f437d5e510
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a0eb1a53d3169c6808d927e78ed351066cc1cb27aa5cf4a039fc42470434503a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3C81A672E0CA2389F7746F2981143B8F6A0AB11B64FD5D035CA0F572A5FB2CE5099F21
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CallEncodePointerTranslator
                                                                                                                                                                                                                                    • String ID: MOC$RCC
                                                                                                                                                                                                                                    • API String ID: 3544855599-2084237596
                                                                                                                                                                                                                                    • Opcode ID: cd0f29946255e309e74fcb50d5115aded8192f9bf5440f1f1eb9698d31b1b80e
                                                                                                                                                                                                                                    • Instruction ID: 2492a582805d398bc105e2ca60ded611626d02704cff10900918f5a8da710f50
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cd0f29946255e309e74fcb50d5115aded8192f9bf5440f1f1eb9698d31b1b80e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CD613B32A08F458AE7309F65D4503ADBBA0FB44B9CF544225EE8E17B95EF38E159CB10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                                                                                                                                                                                                                                    • String ID: csm$csm
                                                                                                                                                                                                                                    • API String ID: 3896166516-3733052814
                                                                                                                                                                                                                                    • Opcode ID: 46c1d6a381f338ebb670c5d7ab3bc16210c8d1d1246f20c28ff8771ada5ef693
                                                                                                                                                                                                                                    • Instruction ID: 314d293e423cab87233dae3bb1aec752b205347e209aa09f192da32c64278e20
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 46c1d6a381f338ebb670c5d7ab3bc16210c8d1d1246f20c28ff8771ada5ef693
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F551A33290CE8286DB74AF159054368B6A0FB44BACF944135DADE47AD5EF3CE459CB10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • GetModuleFileNameW.KERNEL32(?,00007FF71DBD2B0F), ref: 00007FF71DBD30C1
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBD2070: GetLastError.KERNEL32(?,?,00000000,00007FF71DBD7A52,?,?,?,?,?,?,?,?,?,?,?,00007FF71DBD1023), ref: 00007FF71DBD2097
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorFileLastModuleName
                                                                                                                                                                                                                                    • String ID: Failed to convert executable path to UTF-8.$Failed to get executable path.$GetModuleFileNameW
                                                                                                                                                                                                                                    • API String ID: 2776309574-1977442011
                                                                                                                                                                                                                                    • Opcode ID: ffccb051d3bc93b8d7d7749af726f94290e388cae2a19a91baddb17076418f5f
                                                                                                                                                                                                                                    • Instruction ID: 60efdc3fc301d4fd3a7e6eca57adcd1a9aa28a555fb14c20cff42e10f7747100
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ffccb051d3bc93b8d7d7749af726f94290e388cae2a19a91baddb17076418f5f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A8018421B2DE4381FA71B720D8663B59251AF487A8FC04436D84F86392FE1CE54CCF24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: FileWrite$ConsoleErrorLastOutput
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2718003287-0
                                                                                                                                                                                                                                    • Opcode ID: 56014f98c4375db7cd9cd138184bf14cd97057d405c5f2c5078312aa4a460ab3
                                                                                                                                                                                                                                    • Instruction ID: 07f67dc0dd94cbc663db57f0d1df2377b2729bb998e7634468a83570800bf980
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 56014f98c4375db7cd9cd138184bf14cd97057d405c5f2c5078312aa4a460ab3
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E6D1D432B1CE4189E731DF69D4402ACB771FB497A8B844235CE5EA7B95EE38D40AC710
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2933794660-0
                                                                                                                                                                                                                                    • Opcode ID: 9d2e1f26a6c13150d8e348e866a4e60fab7d691edde13c5122d0fb5ddf5e2557
                                                                                                                                                                                                                                    • Instruction ID: 45a4b5a13a6e90aa9eea8c8956015b406db658e95bf50eff8d4b23c247f71335
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9d2e1f26a6c13150d8e348e866a4e60fab7d691edde13c5122d0fb5ddf5e2557
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3311A326B18F0189EB10DF70E8542B873A4FB08728F800E31DA2E477A4EF3CD1998750
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Window$Process$ConsoleCurrentShowThread
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 242035731-0
                                                                                                                                                                                                                                    • Opcode ID: 93267d1080b3e3cbd8d0a9e25e3b2f5895aa4e347dfed7a264085a69707fb08f
                                                                                                                                                                                                                                    • Instruction ID: 9779fbad11545fa309366bb79833cb4d70de3e7c9d8fae89a96c920127bfb38e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 93267d1080b3e3cbd8d0a9e25e3b2f5895aa4e347dfed7a264085a69707fb08f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E0F03721A1DF4781EE746B666454479D251FF887A4F481034E95F43254FE3CE4498A24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Window$Process$ConsoleCurrentShowThread
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 242035731-0
                                                                                                                                                                                                                                    • Opcode ID: 75a1641a8899898a335428a09803ee58f148ff016589288d2c12425f69f9b710
                                                                                                                                                                                                                                    • Instruction ID: 2d657a38a7e327f63cc5151b9168f868687a0bb2529b17632fd32a40504e0bcf
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 75a1641a8899898a335428a09803ee58f148ff016589288d2c12425f69f9b710
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7FF01221A1CF8782EE746B21A454A79A351EF487A8F582034D95F07654FE3CF4498B24
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _get_daylight$_invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: ?
                                                                                                                                                                                                                                    • API String ID: 1286766494-1684325040
                                                                                                                                                                                                                                    • Opcode ID: 0a3d9a2c6523c86c030df9a5c19ce2b4966c9e361a44fc0c5c5f14ca4f8216fa
                                                                                                                                                                                                                                    • Instruction ID: 2658caa01835047136bbe9a7f38d66cd78e19fc3dccdd45ec32a4fc0456c88a2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0a3d9a2c6523c86c030df9a5c19ce2b4966c9e361a44fc0c5c5f14ca4f8216fa
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8641F922A1CA8646FB74AB25D4113BA9690EB80BB4F944235EE5E07AD9FE3CD445CF10
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • _invalid_parameter_noinfo.LIBCMT ref: 00007FF71DBE989A
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB1CC: RtlRestoreThreadPreferredUILanguages.NTDLL(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1E2
                                                                                                                                                                                                                                      • Part of subcall function 00007FF71DBEB1CC: GetLastError.KERNEL32(?,?,?,00007FF71DBF3582,?,?,?,00007FF71DBF35BF,?,?,00000000,00007FF71DBF3A85,?,?,00000000,00007FF71DBF39B7), ref: 00007FF71DBEB1EC
                                                                                                                                                                                                                                    • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF71DBDB4B5), ref: 00007FF71DBE98B8
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorFileLanguagesLastModuleNamePreferredRestoreThread_invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: C:\explorerwin\explorer.exe
                                                                                                                                                                                                                                    • API String ID: 2553983749-952608369
                                                                                                                                                                                                                                    • Opcode ID: ed4c4ddc6ba55ec2504098fa00b89c4721ab4e83171ef93bd49a65225d9fc6d6
                                                                                                                                                                                                                                    • Instruction ID: b873836af5fc5202702084b367b9876b76f35e1c21d0de6ffa609fc882839063
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ed4c4ddc6ba55ec2504098fa00b89c4721ab4e83171ef93bd49a65225d9fc6d6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AB414035A0CF1289EB75EF2594410BCA794EF49BA4F944036ED4F53B55EE3CD4898B20
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ErrorFileLastWrite
                                                                                                                                                                                                                                    • String ID: U
                                                                                                                                                                                                                                    • API String ID: 442123175-4171548499
                                                                                                                                                                                                                                    • Opcode ID: dc51142747858649a960dd086b9af45c31a5bc692d4dd8b190574bce523d8d27
                                                                                                                                                                                                                                    • Instruction ID: bb2312e01f411688a06078a35f55aacc32baaba6a78ba8225758289a775444aa
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dc51142747858649a960dd086b9af45c31a5bc692d4dd8b190574bce523d8d27
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8641A76272CE4185DB30EF29E4443A9A7A0F7987A4F904035EE4E87794EF7CD445CB50
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CurrentDirectory
                                                                                                                                                                                                                                    • String ID: :
                                                                                                                                                                                                                                    • API String ID: 1611563598-336475711
                                                                                                                                                                                                                                    • Opcode ID: 709e7ec7808cc89d8e8b1f9978ddc0a4e57477efcaec04eb86f4091237b7047a
                                                                                                                                                                                                                                    • Instruction ID: 7689a2bee4de02a29a66aa4f5f9b13c0413f2dd1375e4b825b10f32452e623a6
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 709e7ec7808cc89d8e8b1f9978ddc0a4e57477efcaec04eb86f4091237b7047a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7621D563A0CA8181EB34AB25D05426EB3B1FB8CB54FD58135DB4E53284EF7CD9498F61
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExceptionFileHeaderRaise
                                                                                                                                                                                                                                    • String ID: csm
                                                                                                                                                                                                                                    • API String ID: 2573137834-1018135373
                                                                                                                                                                                                                                    • Opcode ID: 9abbc046261961642e0ae191188f43d439b3f0fbc2742ea280541fdcad3ae0f6
                                                                                                                                                                                                                                    • Instruction ID: d1bb703f73af00d6dc4b2b180b6693fc4b66bc4c4d20b07de5dcb8f3715ffbf6
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9abbc046261961642e0ae191188f43d439b3f0fbc2742ea280541fdcad3ae0f6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6B11493261CF8182EB309F15E410269B7E4FB88BA8F994230DA8D07758EF3CD9558B04
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000B.00000002.2186197772.00007FF71DBD1000.00000020.00000001.01000000.00000009.sdmp, Offset: 00007FF71DBD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186161561.00007FF71DBD0000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186248659.00007FF71DBFB000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC0E000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186286401.00007FF71DC10000.00000004.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000B.00000002.2186359260.00007FF71DC12000.00000002.00000001.01000000.00000009.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_11_2_7ff71dbd0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DriveType_invalid_parameter_noinfo
                                                                                                                                                                                                                                    • String ID: :
                                                                                                                                                                                                                                    • API String ID: 2595371189-336475711
                                                                                                                                                                                                                                    • Opcode ID: 5fcfa487bc11bb0757f654d2247ae3b306383d0dd0d50167c3aa74d7c7a9fa00
                                                                                                                                                                                                                                    • Instruction ID: d4467e9428e75ebba35613ec7e0a9169de13471c2744808a5131fa3b984064e0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5fcfa487bc11bb0757f654d2247ae3b306383d0dd0d50167c3aa74d7c7a9fa00
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C001842591CA1285FB70BF6094623BEA3A0EF88724FC41439D54E866A1FE3CD5489F34

                                                                                                                                                                                                                                    Execution Graph

                                                                                                                                                                                                                                    Execution Coverage:0.6%
                                                                                                                                                                                                                                    Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                    Signature Coverage:0.3%
                                                                                                                                                                                                                                    Total number of Nodes:1668
                                                                                                                                                                                                                                    Total number of Limit Nodes:24
                                                                                                                                                                                                                                    execution_graph 130260 70a0e6f0 130261 70a0e89b 130260->130261 130262 70a0e745 130260->130262 130262->130261 130263 70a0e805 strlen strncmp 130262->130263 130265 70a0e82b 130263->130265 130265->130261 130266 70a0dc10 130265->130266 130293 70a96500 130266->130293 130268 70a0dc26 strlen strncmp 130269 70a0dc92 130268->130269 130289 70a0dc56 130268->130289 130272 70a0e550 130269->130272 130282 70a0dca0 130269->130282 130270 70a0dcbe 130295 70a0a420 malloc 130270->130295 130337 70a96730 14 API calls 130272->130337 130277 70a05300 35 API calls 130277->130289 130278 70a0a420 55 API calls 130278->130289 130279 70a0dce4 130333 70a04590 35 API calls 130279->130333 130282->130270 130282->130289 130291 70a0df5a 130282->130291 130292 70a0dc7b 130282->130292 130284 70a0df7d 130284->130289 130340 70a96730 14 API calls 130284->130340 130287 70a0dcef free 130287->130289 130288 70a0ddb6 free 130288->130289 130289->130277 130289->130278 130289->130284 130289->130292 130334 70a05300 35 API calls 130289->130334 130336 70a26c50 __iob_func abort 130289->130336 130338 70a265b0 __iob_func abort 130289->130338 130339 70a27110 __iob_func abort 130289->130339 130335 70a04590 35 API calls 130291->130335 130292->130261 130294 70a9650f 130293->130294 130294->130268 130294->130294 130296 70a0a4c4 130295->130296 130297 70a0a44a 130295->130297 130298 70a0a5c0 130296->130298 130299 70a0a4db 130296->130299 130341 70a2df40 __iob_func abort 130297->130341 130345 70a04230 7 API calls 130298->130345 130304 70a0a6c0 _errno strerror 130299->130304 130305 70a0a4ea _errno 130299->130305 130301 70a0a455 130308 70a0a490 free 130301->130308 130309 70a0a470 130301->130309 130303 70a0a5d3 130306 70a0a730 fprintf 130303->130306 130307 70a0a5df _errno 130303->130307 130317 70a0a6e6 fprintf 130304->130317 130310 70a0a47a 130305->130310 130320 70a0a767 _errno strerror fprintf 130306->130320 130311 70a0a787 _errno strerror fprintf 130307->130311 130312 70a0a5eb 8 API calls 130307->130312 130315 70a0a4f4 130308->130315 130316 70a0a4a9 130308->130316 130342 70a03760 14 API calls 130309->130342 130310->130279 130310->130292 130318 70a0a660 fprintf 130312->130318 130343 70a04230 7 API calls 130315->130343 130324 70a0a4b8 _errno 130316->130324 130330 70a0a690 130316->130330 130317->130306 130323 70a0a675 fputc 130318->130323 130320->130311 130321 70a0a507 130321->130317 130322 70a0a513 _errno 130321->130322 130322->130320 130325 70a0a51f fprintf 130322->130325 130323->130330 130324->130310 130344 70a2df20 130325->130344 130328 70a0a54a fprintf fputc fclose 130329 70a0a57f 130328->130329 130331 70a0a590 fprintf 130329->130331 130330->130304 130332 70a0a5a5 fputc 130331->130332 130332->130298 130333->130287 130334->130288 130335->130284 130336->130289 130338->130289 130339->130289 130341->130301 130342->130310 130343->130321 130344->130328 130345->130303 130346 7ffde402c4b0 130352 7ffde402c4d0 130346->130352 130348 7ffde3ffa600 106 API calls 130348->130352 130350 7ffde402c545 130352->130348 130352->130350 130353 7ffde402cde0 41 API calls 130352->130353 130354 7ffde402cb70 25 API calls 130352->130354 130355 7ffde402c6a0 106 API calls 130352->130355 130353->130352 130354->130352 130356 70a199f0 130357 70a1a6d0 130356->130357 130409 70a19a11 130356->130409 130358 70a1a6e7 _errno 130357->130358 131078 70a19afb 130357->131078 130358->130409 130359 70a1a704 130360 70a1a903 _errno 130361 70a1a911 fprintf fprintf fputc fclose 130360->130361 130362 70a1aff3 _errno strerror fprintf 130360->130362 130368 70a1a96e fprintf 130361->130368 130362->131078 130363 70a1a73f _errno 130365 70a1b493 _errno strerror fprintf 130363->130365 130366 70a1a74b fprintf fputc fclose 130363->130366 130364 70a1b33e fprintf 130364->130409 130365->130409 130375 70a1a788 fputc 130366->130375 130367 70a1a8be fprintf 130367->131078 130374 70a1a980 fputc 130368->130374 130370 70a1a7c0 _errno 130370->130359 130370->131078 130372 70a19c7e GetProcAddress 130377 70a19cab GetProcAddress 130372->130377 130372->131078 130373 70a1b021 fprintf 130373->130409 130382 70a1a992 GetProcAddress 130374->130382 130375->130359 130380 70a19cc0 GetProcAddress 130377->130380 130377->131078 130378 70a1b4c8 _errno 130378->130409 130385 70a19cd5 GetProcAddress 130380->130385 130380->131078 130381 70a1ae06 _errno 130387 70a1c753 _errno strerror fprintf 130381->130387 130388 70a1ae14 fprintf fprintf fputc fclose 130381->130388 130384 70a19cf1 GetProcAddress 130382->130384 130382->131078 130391 70a19d0d GetProcAddress 130384->130391 130384->130409 130385->130382 130385->130384 130386 70a1a7fc _errno 130392 70a1c1f3 _errno strerror fprintf 130386->130392 130393 70a1a808 fprintf fputc fclose 130386->130393 130387->131078 130399 70a1ae78 fprintf 130388->130399 130389 70a1bb50 _errno 130396 70a1c801 _errno strerror fprintf 130389->130396 130389->131078 130390 70a1bf77 fprintf 130390->131078 130398 70a19d29 GetProcAddress 130391->130398 130391->130409 130392->131078 130408 70a1a85a fputc 130393->130408 130395 70a1aa9f _errno 130401 70a1bc80 _errno strerror fprintf 130395->130401 130402 70a1aaad fprintf fprintf fputc fclose 130395->130402 130396->130409 130397 70a1bd30 free 130397->130409 130397->131078 130406 70a19d3e GetProcAddress 130398->130406 130398->131078 130410 70a1ae91 fputc 130399->130410 130400 70a1b76f _errno 130400->130409 130414 70a1c333 _errno strerror fprintf 130400->130414 130434 70a1bca0 fprintf 130401->130434 130429 70a1ab11 fprintf 130402->130429 130403 70a1c1aa fprintf 130422 70a1c1d3 _errno strerror fprintf 130403->130422 130404 70a04a00 48 API calls 130416 70a1b3cc free 130404->130416 130405 70a1b087 _errno 130405->130359 130454 70a1b0a4 130405->130454 130406->130409 130417 70a19d5a GetProcAddress 130406->130417 130407 70a1ac44 _errno 130418 70a1ac50 fprintf fprintf fputc fclose 130407->130418 130419 70a1bf0b _errno strerror fprintf 130407->130419 130408->130409 130409->130359 130409->130370 130409->130378 130409->130397 130409->130400 130409->130404 130409->130405 130423 70a1bd71 _errno 130409->130423 130460 70a1cf97 _errno 130409->130460 130492 70a1b417 _time64 130409->130492 130527 70a1b82f _errno 130409->130527 130665 70a1d91b GetProcAddress 130409->130665 130743 70a1a569 _time64 srand 130409->130743 130778 70a2d860 2 API calls 130409->130778 130846 70a2d470 10 API calls 130409->130846 130954 70a05fd0 107 API calls 130409->130954 130977 70a1b7f0 free 130409->130977 130991 70a1b238 free 130409->130991 131023 70a1b277 _errno 130409->131023 131032 70a0a420 55 API calls 130409->131032 131046 70a1b216 memcpy free 130409->131046 130409->131078 131097 70a2dcd0 130409->131097 131111 70a2da40 130409->131111 131125 70a2d5c0 130409->131125 131139 70a2d710 130409->131139 131153 70a70be0 130409->131153 131162 70a04a00 130409->131162 131287 70a04230 7 API calls 130409->131287 130410->130370 130411 70a1aeb1 fprintf 130411->131078 130412 70a1a9e2 _errno 130427 70a1cf6a _errno strerror fprintf 130412->130427 130428 70a1a9ee fprintf fprintf fputc fclose 130412->130428 130413 70a1c781 fprintf 130439 70a1c7aa _errno strerror fprintf 130413->130439 130414->131078 130415 70a1bb71 _errno strerror fprintf 130415->130409 131264 70a0da10 130416->131264 130417->130409 130433 70a19d6f GetProcAddress GetProcAddress 130417->130433 130443 70a1acb4 fprintf 130418->130443 130419->131078 130420 70a1ad14 _errno 130421 70a1ad20 fprintf fprintf fputc fclose 130420->130421 130420->130422 130446 70a1ad84 fprintf 130421->130446 130422->130392 130423->131078 130424 70a1c221 fprintf 130424->131078 130425 70a1ba8f fprintf 130425->130409 130426 70a1aeee fprintf 130426->130409 130427->130409 130449 70a1aa52 fprintf 130428->130449 130450 70a1ab2a fputc 130429->130450 130430 70a1bfae fprintf 130430->131078 130432 70a1ab74 _errno 130440 70a1ab80 fprintf fprintf fputc fclose 130432->130440 130441 70a1c4b7 _errno strerror fprintf 130432->130441 130433->130409 130442 70a19d98 GetProcAddress GetProcAddress 130433->130442 130434->130375 130436 70a1c0f8 _errno 130444 70a1c100 _errno strerror fprintf 130436->130444 130436->131078 130437 70a1c5d8 _errno 130447 70a1c5e2 _errno strerror fprintf 130437->130447 130437->131078 130438 70a1b98e fprintf 130438->130409 130439->131078 130465 70a1abe4 fprintf 130440->130465 130441->131078 130452 70a19dc1 GetProcAddress GetProcAddress 130442->130452 130442->131078 130469 70a1accd fputc 130443->130469 130444->131078 130445 70a1c98c fprintf 130445->130409 130470 70a1ad9d fputc 130446->130470 130447->131078 130448 70a1b627 _errno 130461 70a1b631 _errno strerror fprintf 130448->130461 130462 70a1b64c fprintf fprintf fputc fclose 130448->130462 130473 70a1aa6b fputc 130449->130473 130450->130409 130451 70a1ccfd fprintf 130478 70a1cd26 _errno strerror fprintf 130451->130478 130466 70a19df1 GetProcAddress 130452->130466 130452->131078 130455 70a1b0c3 _errno 130454->130455 130482 70a1b4fe fprintf 130454->130482 131284 70a04230 7 API calls 130454->131284 130455->130415 130467 70a1b0d1 fprintf fputc fclose 130455->130467 130456 70a1bce1 fprintf 130456->130409 130457 70a1c129 fprintf fprintf fputc fclose 130457->131078 130458 70a1b1cd fprintf 130483 70a1b1df fputc 130458->130483 130459 70a1cab3 fprintf 130459->131078 130460->130359 130518 70a1cfdd 130460->130518 130461->130462 130485 70a1b6b0 fprintf 130462->130485 130463 70a1c361 fprintf 130463->131078 130464 70a1c855 _errno 130476 70a1c877 fprintf fprintf fputc fclose 130464->130476 130477 70a1c85c _errno strerror fprintf 130464->130477 130493 70a1abfd fputc 130465->130493 130479 70a19e0d GetProcAddress 130466->130479 130466->131078 130497 70a1b11d fputc 130467->130497 130468 70a1b884 _errno 130480 70a1b890 fprintf fprintf fputc fclose 130468->130480 130481 70a1cadc _errno strerror fprintf 130468->130481 130469->130370 130470->130370 130471 70a1bd9e fprintf 130471->130409 130472 70a1c30a fprintf 130472->130414 130473->130370 130474 70a1af56 _errno 130486 70a1cc91 _errno strerror fprintf 130474->130486 130487 70a1af64 fprintf fprintf fputc fclose 130474->130487 130475 70a1bf4a _errno 130488 70a1cb33 _errno strerror fprintf 130475->130488 130475->131078 130509 70a1c8db fprintf 130476->130509 130477->130476 130478->130409 130496 70a19e29 GetProcAddress 130479->130496 130479->131078 130514 70a1b8f4 fprintf 130480->130514 130481->131078 130482->130409 130483->130409 130484 70a1c26f _errno 130484->130478 130500 70a1c27b fprintf fprintf fputc fclose 130484->130500 130519 70a1b6c9 fputc 130485->130519 130486->131078 130523 70a1afc8 fprintf 130487->130523 130488->131078 130489 70a1c7d8 fprintf 130489->130396 130490 70a1b7c6 _errno 130506 70a1ca85 _errno strerror fprintf 130490->130506 130490->131078 130491 70a1bbc7 _errno 130507 70a1bbd1 _errno strerror fprintf 130491->130507 130508 70a1bbec fprintf fprintf fputc fclose 130491->130508 131286 70a098a0 19 API calls 130492->131286 130493->130370 130494 70a1d181 fprintf 130494->130409 130495 70a1c4e5 fprintf 130495->131078 130496->130409 130512 70a19e3e GetProcAddress 130496->130512 130497->130359 130498 70a1c178 fprintf 130515 70a1c18a fputc 130498->130515 130499 70a1b5cd fprintf 130535 70a1b5df fputc 130499->130535 130537 70a1c2d8 fprintf 130500->130537 130502 70a1be70 _errno 130520 70a1d13a _errno strerror fprintf 130502->130520 130521 70a1be7c fprintf fprintf fputc fclose 130502->130521 130503 70a1c72a fprintf 130503->130387 130504 70a1baf4 _errno 130522 70a1bb03 _errno strerror fprintf 130504->130522 130504->131078 130505 70a1ba0e fprintf fprintf fputc fclose 130505->131078 130506->131078 130507->130508 130540 70a1bc50 fprintf 130508->130540 130543 70a1c8f4 fputc 130509->130543 130511 70a1c51c fprintf 130511->131078 130512->130409 130529 70a19e53 GetProcAddress 130512->130529 130513 70a1d1e2 _errno 130530 70a21921 _errno strerror fprintf 130513->130530 130531 70a1d1f4 fprintf fprintf fputc fclose 130513->130531 130546 70a1b90d fputc 130514->130546 130515->130409 130516 70a1c9eb _errno 130532 70a1c9f6 fprintf fprintf fputc fclose 130516->130532 130533 70a1d83b _errno strerror fprintf 130516->130533 130517 70a1b9f4 _errno 130534 70a1ce25 _errno strerror fprintf 130517->130534 130517->131078 131288 70a04230 7 API calls 130518->131288 130519->130370 130520->131078 130553 70a1bee0 fprintf 130521->130553 130522->131078 130554 70a1afe1 fputc 130523->130554 130524 70a1c398 fprintf 130524->131078 130525 70a1b17e fprintf fprintf fputc fclose 130525->131078 130526 70a1c00b _errno 130541 70a1c035 fprintf fprintf fputc fclose 130526->130541 130542 70a1c01a _errno strerror fprintf 130526->130542 130527->130409 130528 70a1c955 fprintf 130528->131078 130544 70a19e6f GetProcAddress 130529->130544 130529->131078 130549 70a21941 _errno strerror fprintf 130530->130549 130560 70a1d251 fprintf 130531->130560 130562 70a1ca5a fprintf 130532->130562 130533->131078 130534->130409 130535->130378 130536 70a1cb0a fprintf 130536->130488 130567 70a1c2ea fputc 130537->130567 130539 70a1c3f5 _errno 130555 70a1d375 _errno strerror fprintf 130539->130555 130556 70a1c408 fprintf fprintf fputc fclose 130539->130556 130570 70a1bc69 fputc 130540->130570 130571 70a1c099 fprintf 130541->130571 130542->130541 130543->130370 130544->130409 130559 70a19e84 GetProcAddress 130544->130559 130545 70a1d684 fprintf 130545->131078 130546->130370 130547 70a1c644 _errno 130563 70a1d4fa _errno strerror fprintf 130547->130563 130564 70a1c64f fprintf fprintf fputc fclose 130547->130564 130548 70a1ba5d fprintf 130578 70a1ba6f fputc 130548->130578 130549->131078 130550 70a1d3a3 fprintf 130550->131078 130551 70a1cb61 fprintf 130551->131078 130552 70a1cff0 130568 70a1cffc _errno 130552->130568 130569 70a1d07f fprintf 130552->130569 130581 70a1bef9 fputc 130553->130581 130554->130370 130555->131078 130583 70a1c46c fprintf 130556->130583 130557 70a1ccbf fprintf 130557->131078 130558 70a1c6fa fprintf 130558->131078 130574 70a19ea0 GetProcAddress 130559->130574 130559->131078 130587 70a1d263 fputc 130560->130587 130561 70a1b562 _errno 130575 70a1c906 _errno strerror fprintf 130561->130575 130561->131078 130589 70a1ca73 fputc 130562->130589 130597 70a1d51a _errno strerror fprintf 130563->130597 130592 70a1c6b3 fprintf 130564->130592 130565 70a1cf3a fprintf 130565->130427 130566 70a1be04 _errno 130577 70a1be0e _errno strerror fprintf 130566->130577 130566->131078 130567->131078 130579 70a1d021 fprintf fputc fclose 130568->130579 130580 70a1d006 _errno strerror fprintf 130568->130580 130593 70a1d061 fputc 130569->130593 130570->130370 130598 70a1c0b2 fputc 130571->130598 130572 70a1b44e 130572->130359 130573 70a1cd73 _errno 130584 70a1cd81 _errno strerror fprintf 130573->130584 130585 70a1cd9c fprintf fprintf fputc fclose 130573->130585 130586 70a19eb5 GetProcAddress 130574->130586 130574->131078 130575->131078 130576 70a1d75c _errno 130590 70a1e017 _errno strerror fprintf 130576->130590 130591 70a1d76e fprintf fprintf fputc fclose 130576->130591 130577->131078 130578->130409 130579->130593 130580->130579 130581->130370 130582 70a1d111 fprintf 130582->130520 130609 70a1c485 fputc 130583->130609 130584->130585 130610 70a1cdfc fprintf 130585->130610 130586->130409 130599 70a19ed1 GetProcAddress 130586->130599 130587->131078 130588 70a1b57e fprintf fprintf fputc fclose 130588->131078 130589->130370 130590->131078 130615 70a1d7d2 fprintf 130591->130615 130616 70a1c6cc fputc 130592->130616 130593->130359 130594 70a1cbc0 _errno 130607 70a1cbe2 fprintf fprintf fputc fclose 130594->130607 130608 70a1cbc7 _errno strerror fprintf 130594->130608 130596 70a1d4d1 fprintf 130596->130563 130597->131078 130598->130370 130611 70a19eed GetProcAddress 130599->130611 130599->131078 130600 70a1d6c2 fprintf 130600->130409 130601 70a1ce7b _errno 130612 70a1ce82 _errno strerror fprintf 130601->130612 130613 70a1ce9d fprintf fprintf fputc fclose 130601->130613 130602 70a1e045 fprintf 130624 70a1e075 GetProcAddress 130602->130624 130603 70a2196f fprintf 130603->131078 130604 70a1d3da fprintf 130604->131078 130605 70a1d87a _errno 130617 70a1db74 _errno strerror fprintf 130605->130617 130618 70a1d88c fprintf fprintf fputc fclose 130605->130618 130606 70a1d422 _errno 130606->130549 130619 70a1d434 fprintf fprintf fputc fclose 130606->130619 130627 70a1cc46 fprintf 130607->130627 130608->130607 130609->130370 130629 70a1ce13 fputc 130610->130629 130611->130409 130621 70a19f02 GetProcAddress 130611->130621 130612->130613 130633 70a1cf01 fprintf 130613->130633 130614 70a1d2bb _errno 130625 70a1dd26 _errno strerror fprintf 130614->130625 130626 70a1d2cd fprintf fprintf fputc fclose 130614->130626 130634 70a1d7eb fputc 130615->130634 130616->130370 130617->131078 130636 70a1d8f0 fprintf 130618->130636 130637 70a1d498 fprintf 130619->130637 130622 70a19f1e GetProcAddress 130621->130622 130621->131078 130630 70a19f3a GetProcAddress 130622->130630 130622->131078 130623 70a1dba2 fprintf 130623->130409 130631 70a1e091 GetProcAddress 130624->130631 130632 70a1a4b9 GetProcAddress 130624->130632 130640 70a1dd46 GetProcAddress 130625->130640 130639 70a1d331 fprintf 130626->130639 130641 70a1cc5f fputc 130627->130641 130628 70a1d548 fprintf 130628->130409 130629->130359 130630->130409 130638 70a19f56 GetProcAddress 130630->130638 130631->130632 130631->131078 130642 70a1dd71 GetProcAddress 130632->130642 130643 70a1a4d5 GetProcAddress 130632->130643 130645 70a1cf1a fputc 130633->130645 130634->130370 130635 70a1d80b fprintf 130635->130533 130649 70a1d909 fputc 130636->130649 130650 70a1d4b1 fputc 130637->130650 130644 70a19f72 GetProcAddress 130638->130644 130638->131078 130653 70a1d34a fputc 130639->130653 130640->131078 130641->130370 130642->130643 130648 70a1dd8d GetProcAddress 130642->130648 130643->130409 130643->130640 130652 70a19f8e GetProcAddress 130644->130652 130644->131078 130645->130370 130646 70a1dc33 _errno 130654 70a1dc41 _errno strerror fprintf 130646->130654 130655 70a1dc5c fprintf fprintf fputc fclose 130646->130655 130647 70a219be _errno 130656 70a219e7 fprintf fprintf fputc fclose 130647->130656 130657 70a219cc _errno strerror fprintf 130647->130657 130648->130643 130658 70a1dda9 GetProcAddress 130648->130658 130649->130370 130650->130370 130651 70a1d5be _errno 130659 70a1d5e7 fprintf fprintf fputc fclose 130651->130659 130660 70a1d5cc _errno strerror fprintf 130651->130660 130661 70a19faa GetProcAddress 130652->130661 130652->131078 130653->130370 130654->130655 130655->131078 130656->131078 130657->130656 130658->130643 130658->131078 130670 70a1d64b fprintf 130659->130670 130660->130659 130666 70a19fc6 GetProcAddress 130661->130666 130661->131078 130662 70a21d3b _errno 130667 70a21d64 fprintf fprintf fputc fclose 130662->130667 130668 70a21d49 _errno strerror fprintf 130662->130668 130663 70a1dcf9 fprintf 130663->131078 130664 70a21a84 fprintf 130664->131078 130665->130409 130665->131078 130671 70a19fdb GetProcAddress 130666->130671 130666->131078 130667->131078 130668->130667 130669 70a1e132 _errno 130673 70a1e140 _errno strerror fprintf 130669->130673 130674 70a1e15b fprintf fprintf fputc fclose 130669->130674 130686 70a1d664 fputc 130670->130686 130679 70a19ff7 GetProcAddress 130671->130679 130671->131078 130672 70a1dcc0 fprintf 130689 70a1dcd9 fputc 130672->130689 130673->130674 130674->131078 130675 70a21e01 fprintf 130675->131078 130676 70a21a4b fprintf 130692 70a21a64 fputc 130676->130692 130677 70a1d96f _errno 130682 70a1d998 fprintf fprintf fputc fclose 130677->130682 130683 70a1d97d _errno strerror fprintf 130677->130683 130678 70a1df24 _errno 130684 70a1df32 _errno strerror fprintf 130678->130684 130685 70a1df4d fprintf fprintf fputc fclose 130678->130685 130687 70a1a00c GetProcAddress 130679->130687 130679->131078 130680 70a21e4d _errno 130690 70a21e76 fprintf fprintf fputc fclose 130680->130690 130691 70a21e5b _errno strerror fprintf 130680->130691 130681 70a1e1f8 fprintf 130681->131078 130682->131078 130683->130682 130684->130685 130685->131078 130686->130370 130697 70a1a021 GetProcAddress 130687->130697 130687->131078 130688 70a21dc8 fprintf 130709 70a21de1 fputc 130688->130709 130689->130370 130690->131078 130691->130690 130692->130370 130693 70a1de12 _errno 130700 70a1de20 _errno strerror fprintf 130693->130700 130701 70a1de3b fprintf fprintf fputc fclose 130693->130701 130694 70a1da35 fprintf 130694->131078 130695 70a21c10 _errno 130704 70a21c39 fprintf fprintf fputc fclose 130695->130704 130705 70a21c1e _errno strerror fprintf 130695->130705 130696 70a1dfea fprintf 130696->131078 130708 70a1a03d GetProcAddress 130697->130708 130697->131078 130698 70a1e1bf fprintf 130720 70a1e1d8 fputc 130698->130720 130699 70a21f13 fprintf 130699->131078 130700->130701 130701->131078 130702 70a21afe _errno 130711 70a21b27 fprintf fprintf fputc fclose 130702->130711 130712 70a21b0c _errno strerror fprintf 130702->130712 130703 70a1da81 _errno 130714 70a1daaa fprintf fprintf fputc fclose 130703->130714 130715 70a1da8f _errno strerror fprintf 130703->130715 130704->131078 130705->130704 130706 70a2182e _errno 130717 70a21857 fprintf fprintf fputc fclose 130706->130717 130718 70a2183c _errno strerror fprintf 130706->130718 130707 70a21cd6 fprintf 130707->131078 130719 70a1a059 GetProcAddress 130708->130719 130708->131078 130709->130370 130710 70a1d9fc fprintf 130729 70a1da15 fputc 130710->130729 130711->131078 130712->130711 130713 70a1ded8 fprintf 130713->131078 130714->131078 130715->130714 130716 70a1dfb1 fprintf 130732 70a1dfca fputc 130716->130732 130717->131078 130718->130717 130726 70a1a075 GetProcAddress 130719->130726 130719->131078 130720->130370 130721 70a21eda fprintf 130736 70a21ef3 fputc 130721->130736 130722 70a21bc4 fprintf 130722->131078 130723 70a2171c _errno 130730 70a21745 fprintf fprintf fputc fclose 130723->130730 130731 70a2172a _errno strerror fprintf 130723->130731 130724 70a1db47 fprintf 130724->131078 130725 70a218f4 fprintf 130725->131078 130734 70a1a091 GetProcAddress 130726->130734 130726->131078 130727 70a215dc _errno 130737 70a21605 fprintf fprintf fputc fclose 130727->130737 130738 70a215ea _errno strerror fprintf 130727->130738 130728 70a1de9f fprintf 130749 70a1deb8 fputc 130728->130749 130729->130370 130730->131078 130731->130730 130732->130370 130733 70a21c9d fprintf 130750 70a21cb6 fputc 130733->130750 130745 70a1a0ad GetProcAddress 130734->130745 130734->131078 130735 70a214ca _errno 130746 70a214f3 fprintf fprintf fputc fclose 130735->130746 130747 70a214d8 _errno strerror fprintf 130735->130747 130736->130370 130737->131078 130738->130737 130739 70a21b8b fprintf 130756 70a21ba4 fputc 130739->130756 130740 70a1db0e fprintf 130759 70a1db27 fputc 130740->130759 130741 70a217e2 fprintf 130741->131078 130742 70a2138a _errno 130751 70a213b3 fprintf fprintf fputc fclose 130742->130751 130752 70a21398 _errno strerror fprintf 130742->130752 131092 70a2d860 130743->131092 130744 70a218bb fprintf 130760 70a218d4 fputc 130744->130760 130754 70a1a0c9 GetProcAddress 130745->130754 130745->131078 130746->131078 130747->130746 130748 70a216a2 fprintf 130748->131078 130749->130370 130750->130370 130751->131078 130752->130751 130762 70a1a0e5 GetProcAddress 130754->130762 130754->131078 130755 70a21590 fprintf 130755->131078 130756->130370 130757 70a21278 _errno 130766 70a212a1 fprintf fprintf fputc fclose 130757->130766 130767 70a21286 _errno strerror fprintf 130757->130767 130758 70a217a9 fprintf 130774 70a217c2 fputc 130758->130774 130759->130370 130760->130370 130761 70a21450 fprintf 130761->131078 130768 70a1a101 GetProcAddress 130762->130768 130762->131078 130763 70a1b716 _errno 130771 70a1b71e _errno strerror fprintf 130763->130771 130763->131078 130764 70a21138 _errno 130772 70a21161 fprintf fprintf fputc fclose 130764->130772 130773 70a21146 _errno strerror fprintf 130764->130773 130765 70a21669 fprintf 130782 70a21682 fputc 130765->130782 130766->131078 130767->130766 130779 70a1a116 GetProcAddress 130768->130779 130768->131078 130769 70a21026 _errno 130780 70a21034 _errno strerror fprintf 130769->130780 130781 70a2104f fprintf fprintf fputc fclose 130769->130781 130770 70a21557 fprintf 130787 70a21570 fputc 130770->130787 130771->131078 130772->131078 130773->130772 130774->130370 130775 70a2133e fprintf 130775->131078 130776 70a20ee6 _errno 130784 70a20ef4 _errno strerror fprintf 130776->130784 130785 70a20f0f fprintf fprintf fputc fclose 130776->130785 130777 70a21417 fprintf 130791 70a21430 fputc 130777->130791 130778->130409 130786 70a1a132 GetProcAddress 130779->130786 130779->131078 130780->130781 130781->131078 130782->130370 130783 70a211fe fprintf 130783->131078 130784->130785 130785->131078 130793 70a1a14e GetProcAddress 130786->130793 130786->131078 130787->130370 130788 70a210ec fprintf 130788->131078 130789 70a20dd4 _errno 130796 70a20de2 _errno strerror fprintf 130789->130796 130797 70a20dfd fprintf fprintf fputc fclose 130789->130797 130790 70a21305 fprintf 130804 70a2131e fputc 130790->130804 130791->130370 130792 70a20fac fprintf 130792->131078 130800 70a1a16a GetProcAddress 130793->130800 130793->131078 130794 70a20c94 _errno 130802 70a20ca2 _errno strerror fprintf 130794->130802 130803 70a20cbd fprintf fprintf fputc fclose 130794->130803 130795 70a211c5 fprintf 130811 70a211de fputc 130795->130811 130796->130797 130797->131078 130799 70a20b82 _errno 130808 70a20b90 _errno strerror fprintf 130799->130808 130809 70a20bab fprintf fprintf fputc fclose 130799->130809 130810 70a1a186 GetProcAddress 130800->130810 130800->131078 130801 70a210b3 fprintf 130816 70a210cc fputc 130801->130816 130802->130803 130803->131078 130804->130370 130805 70a20e9a fprintf 130805->131078 130806 70a20a42 _errno 130813 70a20a50 _errno strerror fprintf 130806->130813 130814 70a20a6b fprintf fprintf fputc fclose 130806->130814 130807 70a20f73 fprintf 130820 70a20f8c fputc 130807->130820 130808->130809 130809->131078 130815 70a1a1a2 GetProcAddress 130810->130815 130810->131078 130811->130370 130812 70a20d5a fprintf 130812->131078 130813->130814 130814->131078 130823 70a1a1be GetProcAddress 130815->130823 130815->131078 130816->130370 130817 70a20c48 fprintf 130817->131078 130818 70a20930 _errno 130826 70a20959 fprintf fprintf fputc fclose 130818->130826 130827 70a2093e _errno strerror fprintf 130818->130827 130819 70a20e61 fprintf 130834 70a20e7a fputc 130819->130834 130820->130370 130821 70a20b08 fprintf 130821->131078 130831 70a1a1d3 GetProcAddress 130823->130831 130823->131078 130824 70a207f0 _errno 130832 70a20819 fprintf fprintf fputc fclose 130824->130832 130833 70a207fe _errno strerror fprintf 130824->130833 130825 70a20d21 fprintf 130842 70a20d3a fputc 130825->130842 130826->131078 130827->130826 130828 70a1b164 _errno 130835 70a1c545 _errno strerror fprintf 130828->130835 130828->131078 130829 70a206de _errno 130839 70a20707 fprintf fprintf fputc fclose 130829->130839 130840 70a206ec _errno strerror fprintf 130829->130840 130830 70a20c0f fprintf 130848 70a20c28 fputc 130830->130848 130841 70a1a1e8 GetProcAddress 130831->130841 130831->131078 130832->131078 130833->130832 130834->130370 130835->130409 130836 70a209f6 fprintf 130836->131078 130837 70a2059e _errno 130844 70a205c7 fprintf fprintf fputc fclose 130837->130844 130845 70a205ac _errno strerror fprintf 130837->130845 130838 70a20acf fprintf 130853 70a20ae8 fputc 130838->130853 130839->131078 130840->130839 130849 70a1a204 GetProcAddress 130841->130849 130841->131078 130842->130370 130843 70a208b6 fprintf 130843->131078 130844->131078 130845->130844 130846->130409 130847 70a1b309 _errno 130847->130439 130847->131078 130848->130370 130855 70a1a220 GetProcAddress 130849->130855 130849->131078 130850 70a207a4 fprintf 130850->131078 130851 70a2048c _errno 130858 70a204b5 fprintf fprintf fputc fclose 130851->130858 130859 70a2049a _errno strerror fprintf 130851->130859 130852 70a209bd fprintf 130865 70a209d6 fputc 130852->130865 130853->130370 130854 70a20664 fprintf 130854->131078 130862 70a1a23c GetProcAddress 130855->130862 130855->131078 130856 70a2034c _errno 130863 70a20375 fprintf fprintf fputc fclose 130856->130863 130864 70a2035a _errno strerror fprintf 130856->130864 130857 70a2087d fprintf 130872 70a20896 fputc 130857->130872 130858->131078 130859->130858 130860 70a2023a _errno 130869 70a20263 fprintf fprintf fputc fclose 130860->130869 130870 70a20248 _errno strerror fprintf 130860->130870 130861 70a2076b fprintf 130876 70a20784 fputc 130861->130876 130871 70a1a258 GetProcAddress 130862->130871 130862->131078 130863->131078 130864->130863 130865->130370 130866 70a20552 fprintf 130866->131078 130867 70a200fa _errno 130874 70a20123 fprintf fprintf fputc fclose 130867->130874 130875 70a20108 _errno strerror fprintf 130867->130875 130868 70a2062b fprintf 130882 70a20644 fputc 130868->130882 130869->131078 130870->130869 130878 70a1a26d GetProcAddress 130871->130878 130871->131078 130872->130370 130873 70a20412 fprintf 130873->131078 130874->131078 130875->130874 130876->130370 130877 70a20300 fprintf 130877->131078 130884 70a1a289 GetProcAddress 130878->130884 130878->131078 130879 70a1ffe8 _errno 130887 70a20011 fprintf fprintf fputc fclose 130879->130887 130888 70a1fff6 _errno strerror fprintf 130879->130888 130880 70a20519 fprintf 130897 70a20532 fputc 130880->130897 130881 70a1c59b _errno 130881->130597 130881->131078 130882->130370 130883 70a201c0 fprintf 130883->131078 130893 70a1a2a5 GetProcAddress 130884->130893 130884->131078 130885 70a1fea8 _errno 130894 70a1fed1 fprintf fprintf fputc fclose 130885->130894 130895 70a1feb6 _errno strerror fprintf 130885->130895 130886 70a203d9 fprintf 130905 70a203f2 fputc 130886->130905 130887->131078 130888->130887 130889 70a1b956 _errno 130899 70a1cc71 _errno strerror fprintf 130889->130899 130889->131078 130890 70a1fd96 _errno 130902 70a1fda4 _errno strerror fprintf 130890->130902 130903 70a1fdbf fprintf fprintf fputc fclose 130890->130903 130892 70a202c7 fprintf 130909 70a202e0 fputc 130892->130909 130904 70a1a2ba GetProcAddress 130893->130904 130893->131078 130894->131078 130895->130894 130896 70a1d0c1 fprintf 130896->131078 130897->130370 130898 70a200ae fprintf 130898->131078 130899->130486 130900 70a1fc56 _errno 130907 70a1fc64 _errno strerror fprintf 130900->130907 130908 70a1fc7f fprintf fprintf fputc fclose 130900->130908 130901 70a20187 fprintf 130914 70a201a0 fputc 130901->130914 130902->130903 130903->131078 130911 70a1a2d6 GetProcAddress 130904->130911 130904->131078 130905->130370 130906 70a1ff6e fprintf 130906->131078 130907->130908 130908->131078 130909->130370 130910 70a1fe5c fprintf 130910->131078 130918 70a1a2f2 GetProcAddress 130911->130918 130911->131078 130912 70a1fb44 _errno 130920 70a1fb52 _errno strerror fprintf 130912->130920 130921 70a1fb6d fprintf fprintf fputc fclose 130912->130921 130913 70a20075 fprintf 130927 70a2008e fputc 130913->130927 130914->130370 130915 70a1fd1c fprintf 130915->131078 130917 70a1fa04 _errno 130924 70a1fa12 _errno strerror fprintf 130917->130924 130925 70a1fa2d fprintf fprintf fputc fclose 130917->130925 130926 70a1a30e GetProcAddress 130918->130926 130918->131078 130919 70a1ff35 fprintf 130934 70a1ff4e fputc 130919->130934 130920->130921 130921->131078 130922 70a1f8f2 _errno 130931 70a1f900 _errno strerror fprintf 130922->130931 130932 70a1f91b fprintf fprintf fputc fclose 130922->130932 130923 70a1fe23 fprintf 130938 70a1fe3c fputc 130923->130938 130924->130925 130925->131078 130933 70a1a32a GetProcAddress 130926->130933 130926->131078 130927->130370 130928 70a1fc0a fprintf 130928->131078 130929 70a1f7b2 _errno 130936 70a1f7c0 _errno strerror fprintf 130929->130936 130937 70a1f7db fprintf fprintf fputc fclose 130929->130937 130930 70a1fce3 fprintf 130945 70a1fcfc fputc 130930->130945 130931->130932 130932->131078 130941 70a1a33f GetProcAddress 130933->130941 130933->131078 130934->130370 130935 70a1faca fprintf 130935->131078 130936->130937 130937->131078 130938->130370 130939 70a1f9b8 fprintf 130939->131078 130949 70a1a35b GetProcAddress 130941->130949 130941->131078 130942 70a1f6a0 _errno 130950 70a1f6c9 fprintf fprintf fputc fclose 130942->130950 130951 70a1f6ae _errno strerror fprintf 130942->130951 130943 70a1fbd1 fprintf 130958 70a1fbea fputc 130943->130958 130944 70a04230 7 API calls 130944->131078 130945->130370 130946 70a1f878 fprintf 130946->131078 130947 70a1f560 _errno 130955 70a1f589 fprintf fprintf fputc fclose 130947->130955 130956 70a1f56e _errno strerror fprintf 130947->130956 130948 70a1fa91 fprintf 130964 70a1faaa fputc 130948->130964 130957 70a1a377 GetProcAddress 130949->130957 130949->131078 130950->131078 130951->130950 130952 70a1f44e _errno 130962 70a1f477 fprintf fprintf fputc fclose 130952->130962 130963 70a1f45c _errno strerror fprintf 130952->130963 130953 70a1f97f fprintf 130969 70a1f998 fputc 130953->130969 130954->130409 130955->131078 130956->130955 130965 70a1a38c GetProcAddress 130957->130965 130957->131078 130958->130370 130959 70a1f766 fprintf 130959->131078 130960 70a1f30e _errno 130967 70a1f337 fprintf fprintf fputc fclose 130960->130967 130968 70a1f31c _errno strerror fprintf 130960->130968 130961 70a1f83f fprintf 130974 70a1f858 fputc 130961->130974 130962->131078 130963->130962 130964->130370 130971 70a1a3a8 GetProcAddress 130965->130971 130965->131078 130966 70a1f626 fprintf 130966->131078 130967->131078 130968->130967 130969->130370 130970 70a1f514 fprintf 130970->131078 130979 70a1a3c4 GetProcAddress 130971->130979 130971->131078 130972 70a1f1fc _errno 130980 70a1f225 fprintf fprintf fputc fclose 130972->130980 130981 70a1f20a _errno strerror fprintf 130972->130981 130973 70a1f72d fprintf 130987 70a1f746 fputc 130973->130987 130974->130370 130975 70a1f3d4 fprintf 130975->131078 130976 70a1f0bc _errno 130984 70a1f0e5 fprintf fprintf fputc fclose 130976->130984 130985 70a1f0ca _errno strerror fprintf 130976->130985 130977->130409 130977->131078 130978 70a1f5ed fprintf 130994 70a1f606 fputc 130978->130994 130986 70a1a3e0 GetProcAddress 130979->130986 130979->131078 130980->131078 130981->130980 130982 70a1efaa _errno 130992 70a1efd3 fprintf fprintf fputc fclose 130982->130992 130993 70a1efb8 _errno strerror fprintf 130982->130993 130983 70a1f4db fprintf 130999 70a1f4f4 fputc 130983->130999 130984->131078 130985->130984 130996 70a1a3f5 GetProcAddress 130986->130996 130986->131078 130987->130370 130988 70a1f2c2 fprintf 130988->131078 130989 70a1ee6a _errno 130997 70a1ee93 fprintf fprintf fputc fclose 130989->130997 130998 70a1ee78 _errno strerror fprintf 130989->130998 130990 70a1f39b fprintf 131005 70a1f3b4 fputc 130990->131005 130991->130409 130991->131078 130992->131078 130993->130992 130994->130370 130995 70a1f182 fprintf 130995->131078 131001 70a1a411 GetProcAddress 130996->131001 131002 70a1e84b GetProcAddress 130996->131002 130997->131078 130998->130997 130999->130370 131000 70a1f070 fprintf 131000->131078 131009 70a1e5f2 GetProcAddress 131001->131009 131010 70a1a42d GetProcAddress 131001->131010 131002->131001 131002->131078 131003 70a1ed58 _errno 131011 70a1ed81 fprintf fprintf fputc fclose 131003->131011 131012 70a1ed66 _errno strerror fprintf 131003->131012 131004 70a1f289 fprintf 131019 70a1f2a2 fputc 131004->131019 131005->130370 131006 70a1ef30 fprintf 131006->131078 131007 70a1ec18 _errno 131015 70a1ec41 fprintf fprintf fputc fclose 131007->131015 131016 70a1ec26 _errno strerror fprintf 131007->131016 131008 70a1f149 fprintf 131026 70a1f162 fputc 131008->131026 131009->131010 131009->131078 131017 70a1e5c1 GetProcAddress 131010->131017 131018 70a1a449 GetProcAddress 131010->131018 131011->131078 131012->131011 131013 70a1eb06 _errno 131024 70a1eb14 _errno strerror fprintf 131013->131024 131025 70a1eb2f fprintf fprintf fputc fclose 131013->131025 131014 70a1f037 fprintf 131034 70a1f050 fputc 131014->131034 131015->131078 131016->131015 131017->131018 131017->131078 131028 70a1a465 GetProcAddress 131018->131028 131029 70a1e368 GetProcAddress 131018->131029 131019->130370 131020 70a1ee1e fprintf 131020->131078 131021 70a1e9c6 _errno 131030 70a1e9d4 _errno strerror fprintf 131021->131030 131031 70a1e9ef fprintf fprintf fputc fclose 131021->131031 131022 70a1eef7 fprintf 131039 70a1ef10 fputc 131022->131039 131023->130359 131033 70a1b299 131023->131033 131024->131025 131025->131078 131026->130370 131027 70a1ecde fprintf 131027->131078 131036 70a1a481 GetProcAddress 131028->131036 131037 70a1e337 GetProcAddress 131028->131037 131029->131028 131029->131078 131030->131031 131031->131078 131032->130409 131033->130434 131055 70a1b2b8 _errno 131033->131055 131285 70a04230 7 API calls 131033->131285 131034->130370 131035 70a1ebcc fprintf 131035->131078 131044 70a1e0c2 GetProcAddress 131036->131044 131045 70a1a49d GetProcAddress 131036->131045 131037->131036 131037->131078 131038 70a1ede5 fprintf 131052 70a1edfe fputc 131038->131052 131039->130370 131040 70a1ea8c fprintf 131040->131078 131042 70a1eca5 fprintf 131058 70a1ecbe fputc 131042->131058 131043 70a1e8b4 _errno 131050 70a1e8c2 _errno strerror fprintf 131043->131050 131051 70a1e8dd fprintf fprintf fputc fclose 131043->131051 131044->131045 131047 70a1e0de GetProcAddress 131044->131047 131045->130624 131045->130632 131046->130409 131047->131045 131047->131078 131048 70a1eb93 fprintf 131063 70a1ebac fputc 131048->131063 131049 70a1e758 _errno 131056 70a1e781 fprintf fprintf fputc fclose 131049->131056 131057 70a1e766 _errno strerror fprintf 131049->131057 131050->131051 131051->131078 131052->130370 131053 70a1ea53 fprintf 131068 70a1ea6c fputc 131053->131068 131054 70a1e646 _errno 131060 70a1e654 _errno strerror fprintf 131054->131060 131061 70a1e66f fprintf fprintf fputc fclose 131054->131061 131055->130366 131062 70a1c497 _errno strerror fprintf 131055->131062 131056->131078 131057->131056 131058->130370 131059 70a1e97a fprintf 131059->131078 131060->131061 131061->131078 131062->130441 131063->130370 131064 70a1e81e fprintf 131064->131078 131065 70a1e4ce _errno 131066 70a1e4f7 fprintf fprintf fputc fclose 131065->131066 131067 70a1e4dc _errno strerror fprintf 131065->131067 131066->131078 131067->131066 131068->130370 131069 70a1e70c fprintf 131069->131078 131070 70a1e3bc _errno 131074 70a1e3e5 fprintf fprintf fputc fclose 131070->131074 131075 70a1e3ca _errno strerror fprintf 131070->131075 131071 70a1e941 fprintf 131080 70a1e95a fputc 131071->131080 131072 70a1e594 fprintf 131072->131078 131073 70a1e7e5 fprintf 131084 70a1e7fe fputc 131073->131084 131074->131078 131075->131074 131076 70a1e6d3 fprintf 131085 70a1e6ec fputc 131076->131085 131077 70a1e244 _errno 131082 70a1e252 _errno strerror fprintf 131077->131082 131083 70a1e26d fprintf fprintf fputc fclose 131077->131083 131078->130360 131078->130363 131078->130364 131078->130367 131078->130370 131078->130372 131078->130373 131078->130381 131078->130386 131078->130389 131078->130390 131078->130395 131078->130397 131078->130403 131078->130407 131078->130409 131078->130411 131078->130412 131078->130413 131078->130415 131078->130420 131078->130423 131078->130424 131078->130425 131078->130426 131078->130430 131078->130432 131078->130436 131078->130437 131078->130438 131078->130445 131078->130448 131078->130451 131078->130456 131078->130457 131078->130458 131078->130459 131078->130463 131078->130464 131078->130468 131078->130471 131078->130472 131078->130474 131078->130475 131078->130484 131078->130489 131078->130490 131078->130491 131078->130494 131078->130495 131078->130498 131078->130499 131078->130502 131078->130503 131078->130504 131078->130505 131078->130511 131078->130513 131078->130516 131078->130517 131078->130524 131078->130525 131078->130526 131078->130528 131078->130536 131078->130539 131078->130545 131078->130547 131078->130548 131078->130550 131078->130551 131078->130557 131078->130558 131078->130561 131078->130565 131078->130566 131078->130572 131078->130573 131078->130576 131078->130582 131078->130588 131078->130594 131078->130596 131078->130600 131078->130601 131078->130602 131078->130603 131078->130604 131078->130605 131078->130606 131078->130614 131078->130623 131078->130628 131078->130635 131078->130642 131078->130646 131078->130647 131078->130651 131078->130662 131078->130663 131078->130664 131078->130669 131078->130672 131078->130675 131078->130676 131078->130677 131078->130678 131078->130680 131078->130681 131078->130688 131078->130693 131078->130694 131078->130695 131078->130696 131078->130698 131078->130699 131078->130702 131078->130703 131078->130706 131078->130707 131078->130710 131078->130713 131078->130716 131078->130721 131078->130722 131078->130723 131078->130724 131078->130725 131078->130727 131078->130728 131078->130733 131078->130735 131078->130739 131078->130740 131078->130741 131078->130742 131078->130744 131078->130748 131078->130755 131078->130757 131078->130758 131078->130761 131078->130763 131078->130764 131078->130765 131078->130769 131078->130770 131078->130775 131078->130776 131078->130777 131078->130783 131078->130788 131078->130789 131078->130790 131078->130792 131078->130794 131078->130795 131078->130799 131078->130801 131078->130805 131078->130806 131078->130807 131078->130812 131078->130817 131078->130818 131078->130819 131078->130821 131078->130824 131078->130825 131078->130828 131078->130829 131078->130830 131078->130836 131078->130837 131078->130838 131078->130843 131078->130847 131078->130850 131078->130851 131078->130852 131078->130854 131078->130856 131078->130857 131078->130860 131078->130861 131078->130866 131078->130867 131078->130868 131078->130873 131078->130877 131078->130879 131078->130880 131078->130881 131078->130883 131078->130885 131078->130886 131078->130889 131078->130890 131078->130892 131078->130896 131078->130898 131078->130900 131078->130901 131078->130906 131078->130910 131078->130912 131078->130913 131078->130915 131078->130917 131078->130919 131078->130922 131078->130923 131078->130928 131078->130929 131078->130930 131078->130935 131078->130939 131078->130942 131078->130943 131078->130944 131078->130946 131078->130947 131078->130948 131078->130952 131078->130953 131078->130959 131078->130960 131078->130961 131078->130966 131078->130970 131078->130972 131078->130973 131078->130975 131078->130976 131078->130978 131078->130982 131078->130983 131078->130988 131078->130989 131078->130990 131078->130995 131078->131000 131078->131003 131078->131004 131078->131006 131078->131007 131078->131008 131078->131013 131078->131014 131078->131020 131078->131021 131078->131022 131078->131027 131078->131035 131078->131038 131078->131040 131078->131042 131078->131043 131078->131048 131078->131049 131078->131053 131078->131054 131078->131059 131078->131064 131078->131065 131078->131069 131078->131070 131078->131071 131078->131072 131078->131073 131078->131076 131078->131077 131079 70a1e482 fprintf 131078->131079 131081 70a1e55b fprintf 131078->131081 131086 70a1e30a fprintf 131078->131086 131087 70a1e449 fprintf 131078->131087 131089 70a1e2d1 fprintf 131078->131089 131079->131078 131080->130370 131088 70a1e574 fputc 131081->131088 131082->131083 131083->131078 131084->130370 131085->130370 131086->131078 131090 70a1e462 fputc 131087->131090 131088->130370 131091 70a1e2ea fputc 131089->131091 131090->130370 131091->130370 131093 70a2da25 131092->131093 131096 70a2d872 131092->131096 131289 70a2d400 __iob_func abort 131093->131289 131096->130409 131098 70a2deff 131097->131098 131110 70a2dce8 131097->131110 131290 70a2d400 __iob_func abort 131098->131290 131100 70a2dcf7 memcmp 131101 70a2dd10 memcmp 131100->131101 131102 70a2de02 131100->131102 131101->131102 131104 70a2dd2f memcmp 131101->131104 131102->130409 131104->131102 131105 70a2dd4f memcmp 131104->131105 131105->131102 131106 70a2dd6f memcmp 131105->131106 131106->131102 131107 70a2dd8f memcmp 131106->131107 131107->131102 131108 70a2ddaf memcmp 131107->131108 131108->131102 131109 70a2ddcf memcmp 131108->131109 131109->131102 131109->131110 131110->131100 131110->131102 131112 70a2dca7 131111->131112 131113 70a2da58 131111->131113 131291 70a2d400 __iob_func abort 131112->131291 131115 70a2da67 memcmp 131113->131115 131124 70a2db75 131113->131124 131117 70a2da80 memcmp 131115->131117 131115->131124 131118 70a2daa2 memcmp 131117->131118 131117->131124 131119 70a2dac2 memcmp 131118->131119 131118->131124 131120 70a2dae2 memcmp 131119->131120 131119->131124 131121 70a2db02 memcmp 131120->131121 131120->131124 131122 70a2db22 memcmp 131121->131122 131121->131124 131123 70a2db42 memcmp 131122->131123 131122->131124 131123->131113 131123->131124 131124->130409 131126 70a2d6f1 131125->131126 131134 70a2d5d6 131125->131134 131292 70a2d400 __iob_func abort 131126->131292 131128 70a2d5e8 strcmp 131130 70a2d6df 131128->131130 131128->131134 131130->130409 131131 70a2d612 strcmp 131131->131130 131131->131134 131132 70a2d631 strcmp 131132->131130 131132->131134 131133 70a2d650 strcmp 131133->131130 131133->131134 131134->131128 131134->131130 131134->131131 131134->131132 131134->131133 131135 70a2d66f strcmp 131134->131135 131136 70a2d68a strcmp 131134->131136 131137 70a2d6a5 strcmp 131134->131137 131138 70a2d6c0 strcmp 131134->131138 131135->131130 131135->131134 131136->131130 131136->131134 131137->131130 131137->131134 131138->131130 131138->131134 131140 70a2d838 131139->131140 131144 70a2d726 131139->131144 131293 70a2d400 __iob_func abort 131140->131293 131143 70a2d738 strcmp 131143->131144 131152 70a2d826 131143->131152 131144->131143 131145 70a2d75c strcmp 131144->131145 131146 70a2d778 strcmp 131144->131146 131147 70a2d797 strcmp 131144->131147 131148 70a2d7b6 strcmp 131144->131148 131149 70a2d7d1 strcmp 131144->131149 131150 70a2d7ec strcmp 131144->131150 131151 70a2d807 strcmp 131144->131151 131144->131152 131145->131144 131145->131152 131146->131144 131146->131152 131147->131144 131147->131152 131148->131144 131148->131152 131149->131144 131149->131152 131150->131144 131150->131152 131151->131144 131151->131152 131152->130409 131154 70a70bee 131153->131154 131294 70a70db9 131154->131294 131156 70a70c23 exit 131157 70a70c3e 131156->131157 131157->130409 131158 70a70bf3 131158->131156 131297 70a70de0 GetCurrentThread GetThreadContext 131158->131297 131160 70a70c05 131160->131156 131161 70a70c09 131160->131161 131161->130409 131304 70a6ffb0 131162->131304 131164 70a04a15 131165 70a04a25 free 131164->131165 131166 70a04a63 131164->131166 131178 70a05fd0 131165->131178 131319 70a04230 7 API calls 131166->131319 131168 70a04a76 131169 70a04b20 fprintf 131168->131169 131170 70a04a82 _errno 131168->131170 131174 70a04ae8 fprintf 131169->131174 131171 70a04b54 _errno strerror fprintf 131170->131171 131172 70a04a96 131170->131172 131171->131172 131175 70a04aba fprintf fputc fclose 131172->131175 131177 70a04b0b fputc 131174->131177 131175->131174 131177->131165 131179 70a05ff2 131178->131179 131206 70a0609d 131178->131206 131181 70a06110 malloc 131179->131181 131182 70a06010 131179->131182 131180 70a024c0 strlen strlen malloc _strdup 131180->131206 131185 70a0612a memcpy 131181->131185 131183 70a061b1 malloc 131182->131183 131184 70a0602e 131182->131184 131183->131185 131186 70a060fa 131184->131186 131188 70a06150 malloc 131184->131188 131189 70a0605f getenv 131184->131189 131185->130409 131186->130409 131188->131185 131213 70a06074 131189->131213 131191 70a060e8 free 131191->131186 131192 70a0631c _errno 131192->131213 131193 70a0617c free 131198 70a06184 131193->131198 131194 70a064e1 _errno 131199 70a066b3 _errno strerror fprintf 131194->131199 131200 70a064ef fprintf fprintf fputc fclose 131194->131200 131195 70a06340 free 131195->131206 131196 70a061f1 free 131196->131198 131197 70a06420 _access 131197->131206 131197->131213 131202 70a061f8 131198->131202 131208 70a06195 131198->131208 131199->131213 131200->131206 131201 70a06617 fprintf 131201->131206 131214 70a06217 _errno 131202->131214 131229 70a0668a fprintf 131202->131229 131407 70a04230 7 API calls 131202->131407 131204 70a06585 getenv 131204->131213 131205 70a0635d strlen strlen malloc 131205->131206 131215 70a065c6 131205->131215 131206->131180 131206->131191 131206->131192 131206->131193 131206->131194 131206->131195 131206->131196 131206->131201 131206->131204 131206->131205 131209 70a0654f fprintf 131206->131209 131206->131213 131216 70a0644e 131206->131216 131406 70a04900 15 API calls 131206->131406 131408 70a05f60 6 API calls 131206->131408 131409 70a04900 15 API calls 131206->131409 131411 70a04230 7 API calls 131206->131411 131207 70a067fe 131413 70a04230 7 API calls 131207->131413 131210 70a061a4 _errno 131208->131210 131211 70a0664e _errno strerror 131208->131211 131217 70a06564 fputc 131209->131217 131210->131186 131228 70a065db 131211->131228 131213->131192 131213->131197 131213->131204 131213->131205 131213->131206 131213->131207 131219 70a065ae getenv 131213->131219 131220 70a0623a 8 API calls 131214->131220 131221 70a0621f _errno strerror fprintf 131214->131221 131222 70a06719 131215->131222 131215->131228 131410 70a04900 15 API calls 131216->131410 131217->131213 131218 70a06811 131226 70a0689c 131218->131226 131227 70a0681d _errno 131218->131227 131219->131205 131219->131215 131235 70a062b2 fprintf 131220->131235 131221->131220 131412 70a04230 7 API calls 131222->131412 131225 70a06459 free 131225->131186 131231 70a0646d 131225->131231 131236 70a068e3 fprintf 131226->131236 131248 70a068aa fprintf 131226->131248 131233 70a06846 fprintf fprintf fputc fclose 131227->131233 131234 70a0682b _errno strerror fprintf 131227->131234 131228->131210 131229->131199 131239 70a06930 131231->131239 131240 70a0647a 131231->131240 131232 70a0672c 131237 70a06738 _errno 131232->131237 131238 70a06795 131232->131238 131233->131226 131234->131233 131244 70a062ca fputc 131235->131244 131236->131226 131242 70a06910 _errno strerror fprintf 131237->131242 131243 70a06743 fprintf fprintf fputc fclose 131237->131243 131247 70a067d8 fprintf 131238->131247 131256 70a067a3 fprintf 131238->131256 131414 70a04230 7 API calls 131239->131414 131240->131210 131249 70a06490 _errno strerror 131240->131249 131242->131239 131243->131238 131244->131206 131246 70a06943 131251 70a06a0b fprintf 131246->131251 131252 70a0694f _errno 131246->131252 131247->131238 131257 70a068c3 fputc 131248->131257 131259 70a064bd 131249->131259 131250 70a063f8 free 131250->131198 131253 70a0640c 131250->131253 131260 70a069c3 _errno strerror 131251->131260 131254 70a06961 6 API calls 131252->131254 131255 70a06a49 _errno strerror fprintf 131252->131255 131253->131186 131254->131260 131261 70a067b8 fputc 131256->131261 131257->131226 131259->131210 131262 70a069dd fprintf 131260->131262 131261->131238 131263 70a069f9 fputc 131262->131263 131263->131251 131265 70a05fd0 107 API calls 131264->131265 131266 70a0da2a 131265->131266 131267 70a0da80 131266->131267 131268 70a0da32 131266->131268 131270 70a0daa0 131267->131270 131271 70a0da91 _errno 131267->131271 131415 70a0a7b0 131268->131415 131832 70a04230 7 API calls 131270->131832 131273 70a0da74 131271->131273 131273->130409 131275 70a0dab3 131276 70a0db4c fprintf 131275->131276 131277 70a0dabf _errno 131275->131277 131280 70a0db1a fprintf 131276->131280 131278 70a0db80 _errno strerror fprintf 131277->131278 131279 70a0dacb fprintf fprintf fputc fclose 131277->131279 131278->131279 131279->131280 131283 70a0db3a fputc 131280->131283 131283->131271 131284->130454 131285->131033 131286->131078 131287->130409 131288->130552 131300 70a70c90 131294->131300 131298 70a70e1e GetCurrentThread SetThreadContext 131297->131298 131298->131160 131301 70a70ca4 131300->131301 131302 70a70cf2 131301->131302 131303 70a70cd7 RtlWow64SetThreadContext 131301->131303 131302->131158 131303->131302 131320 70a70f40 131304->131320 131306 70a70002 malloc 131307 70a70023 memcpy 131306->131307 131308 70a700de 131306->131308 131307->131308 131318 70a70045 131307->131318 131308->131164 131309 70a77660 abort 131309->131318 131312 70a7bf10 fwrite abort 131312->131318 131318->131308 131318->131309 131318->131312 131321 70a94120 131318->131321 131349 70a75cf0 131318->131349 131372 70a76e80 131318->131372 131376 70a7c3e0 fwrite abort 131318->131376 131377 70a75ec0 free UnmapViewOfFile GetLastError _errno 131318->131377 131378 70a76e80 abort 131318->131378 131379 70a775c0 abort 131318->131379 131319->131168 131320->131306 131322 70a9413c 131321->131322 131342 70a942f9 131321->131342 131324 70a942e0 131322->131324 131325 70a942b9 131322->131325 131326 70a9415a 131322->131326 131327 70a94ed0 9 API calls 131324->131327 131324->131342 131384 70a94ed0 131325->131384 131397 70a82d40 fwrite abort abort memset abort 131326->131397 131327->131342 131331 70a943b9 memset 131331->131342 131332 70a70fe0 free 131332->131342 131333 70a94245 131335 70a94257 131333->131335 131333->131342 131334 70a9425d 131380 70a96550 131334->131380 131335->131334 131337 70a94283 131335->131337 131400 70a70fe0 131337->131400 131338 70a94185 131338->131333 131340 70a9427a 131338->131340 131347 70a941d8 131338->131347 131339 70a94270 131339->131340 131343 70a96550 VirtualProtect 131339->131343 131340->131318 131342->131331 131342->131332 131342->131334 131403 70a7ac80 11 API calls 131342->131403 131404 70a949c0 memcpy free 131342->131404 131345 70a942ac 131343->131345 131345->131318 131346 70a94ed0 9 API calls 131346->131347 131347->131333 131347->131338 131347->131346 131398 70a950a0 UnmapViewOfFile GetLastError _errno 131347->131398 131399 70a82d40 fwrite abort abort memset abort 131347->131399 131350 70a70fe0 free 131349->131350 131351 70a75d1e 131350->131351 131352 70a70fe0 free 131351->131352 131353 70a75d2b 131352->131353 131354 70a70fe0 free 131353->131354 131355 70a75d48 131354->131355 131356 70a70fe0 free 131355->131356 131357 70a75d58 131356->131357 131358 70a70fe0 free 131357->131358 131359 70a75d68 131358->131359 131360 70a70fe0 free 131359->131360 131361 70a75d78 131360->131361 131362 70a70fe0 free 131361->131362 131363 70a75d88 131362->131363 131364 70a75ddf 131363->131364 131366 70a70fe0 free 131363->131366 131365 70a70fe0 free 131364->131365 131367 70a75deb 131365->131367 131366->131363 131368 70a75e41 131367->131368 131370 70a70fe0 free 131367->131370 131369 70a70fe0 free 131368->131369 131371 70a75e4d 131369->131371 131370->131367 131373 70a76e9d 131372->131373 131375 70a76ea5 131372->131375 131373->131375 131405 70a76840 abort 131373->131405 131375->131318 131376->131318 131377->131318 131378->131318 131379->131318 131382 70a9655a 131380->131382 131381 70a96586 VirtualProtect 131383 70a9659e 131381->131383 131382->131381 131382->131383 131383->131339 131388 70a94eea 131384->131388 131385 70a94f27 _errno 131386 70a94f3f 131385->131386 131387 70a94ff0 _errno 131385->131387 131386->131387 131391 70a94f52 131386->131391 131389 70a94fff 131387->131389 131388->131385 131390 70a95088 131388->131390 131389->131324 131392 70a94f63 CreateFileMappingA 131391->131392 131393 70a95054 _get_osfhandle 131391->131393 131394 70a94fc8 GetLastError _errno 131392->131394 131395 70a94f93 MapViewOfFile CloseHandle 131392->131395 131393->131392 131396 70a9506e _errno 131393->131396 131394->131324 131395->131389 131395->131394 131396->131389 131397->131338 131398->131347 131399->131347 131401 70a70ff0 free 131400->131401 131402 70a70ffd 131400->131402 131401->131402 131402->131339 131403->131342 131404->131342 131405->131375 131406->131206 131407->131202 131408->131206 131409->131250 131410->131225 131411->131206 131412->131232 131413->131218 131414->131246 131416 70a0a7c6 131415->131416 131417 70a05fd0 107 API calls 131416->131417 131418 70a0a7f7 131417->131418 131419 70a0afd0 131418->131419 131420 70a0a803 131418->131420 131421 70a0acd4 _errno 131419->131421 131422 70a0afe7 131419->131422 131833 70a2bd40 131420->131833 131508 70a0ad43 free 131421->131508 131994 70a04230 7 API calls 131422->131994 131426 70a0affa 131428 70a0c7f0 fprintf 131426->131428 131429 70a0b006 _errno 131426->131429 131427 70a0bea1 free 131746 70a0acc5 131427->131746 131769 70a0c6e8 131427->131769 131452 70a0c850 131428->131452 131432 70a0b014 fprintf fputc fclose 131429->131432 131433 70a0ce6e _errno strerror fprintf 131429->131433 131430 70a0ac80 131439 70a0aca0 free free 131430->131439 131431 70a0a83a strncmp 131435 70a0a8b0 131431->131435 131436 70a0a89a strchr 131431->131436 131444 70a0b05b fputc 131432->131444 131447 70a0ce8e fprintf 131433->131447 131437 70a0a420 55 API calls 131435->131437 131436->131435 131440 70a0c2e1 131436->131440 131442 70a0a8ef 131437->131442 131548 70a0acb0 131439->131548 131443 70a0c2f8 131440->131443 131440->131746 131441 70a0c715 131445 70a0c721 _errno 131441->131445 131446 70a0ccc6 fprintf 131441->131446 131450 70a0ad62 free 131442->131450 131451 70a0a8fb 131442->131451 132014 70a04230 7 API calls 131443->132014 131444->131421 131448 70a0d201 _errno strerror fprintf 131445->131448 131449 70a0c72d fprintf 131445->131449 131468 70a0ccfd 131446->131468 131462 70a0b531 fprintf 131447->131462 131651 70a0b840 131448->131651 132018 70a2df20 131449->132018 131450->131548 131863 70a30380 131451->131863 131459 70a0c867 131452->131459 131460 70a0bc2a 131452->131460 131457 70a04230 7 API calls 131457->131651 132020 70a04230 7 API calls 131459->132020 131474 70a0bc4c _errno 131460->131474 131461 70a0c30b 131466 70a0c317 _errno 131461->131466 131515 70a0d105 131461->131515 131492 70a0b551 fputc 131462->131492 131463 70a0c758 fprintf fputc fclose 131467 70a0c78d 131463->131467 131471 70a0c321 _errno strerror fprintf 131466->131471 131472 70a0c33c fprintf fprintf fputc fclose 131466->131472 131489 70a0c79e fprintf 131467->131489 132023 70a04230 7 API calls 131468->132023 131469 70a0b85f _errno 131476 70a0b882 fprintf 131469->131476 131477 70a0b867 _errno strerror fprintf 131469->131477 131470 70a0c87a 131480 70a0d415 fprintf 131470->131480 131481 70a0c886 _errno 131470->131481 131471->131472 131488 70a0c399 fprintf 131472->131488 131474->131508 131475 70a0d14a fprintf 131475->131515 131507 70a0b8e2 131476->131507 131477->131476 131509 70a0d44c _errno strerror fprintf 131480->131509 131485 70a0c894 fprintf fprintf fputc fclose 131481->131485 131486 70a0d74d _errno strerror fprintf 131481->131486 131482 70a0c923 fprintf 131498 70a0c950 memcpy 131482->131498 131483 70a0cd10 131490 70a0cd1c _errno 131483->131490 131483->131515 131503 70a0c8f1 fprintf 131485->131503 131486->131548 131487 70a0d240 _errno 131495 70a0d251 _errno strerror fprintf 131487->131495 131487->131651 131496 70a0c3ab fputc 131488->131496 131504 70a0c7b3 fputc 131489->131504 131499 70a0cd41 fprintf 131490->131499 131500 70a0cd26 _errno strerror fprintf 131490->131500 131491 70a0b8ad fprintf fputc fclose 131491->131507 131492->131746 131495->131651 131496->131746 131497 70a0d27a fprintf fprintf fputc fclose 131497->131651 131498->131548 131540 70a0cd8b 131499->131540 131500->131499 131501 70a0d599 fprintf 131501->131651 131502 70a0a974 131502->131439 131519 70a0a97c 131502->131519 131511 70a0c903 fputc 131503->131511 131514 70a0c7c5 131504->131514 131505 70a0d113 fprintf 131505->131515 131506 70a0d181 fprintf 131506->131515 131507->131491 131516 70a0b8f3 fprintf 131507->131516 131508->131273 131512 70a0d46c 131509->131512 131510 70a0a98d free free 131517 70a0a9ac 131510->131517 131510->131548 131511->131460 132026 70a04230 7 API calls 131512->132026 131513 70a0d2c9 fprintf 131528 70a0d2db fputc 131513->131528 132019 70a04230 7 API calls 131514->132019 131515->131475 131515->131505 131515->131506 131531 70a0d1b8 fprintf 131515->131531 131532 70a0b908 fputc 131516->131532 131524 70a0a9b5 strncmp 131517->131524 131517->131548 131519->131510 131529 70a04a00 48 API calls 131519->131529 131522 70a0d5d7 fprintf 131541 70a0d600 _errno strerror fprintf 131522->131541 131523 70a0bd19 strncmp 131523->131508 131523->131548 131525 70a0a9dd strncmp 131524->131525 131555 70a0aeb0 131524->131555 131533 70a0ad74 atof _time64 131525->131533 131534 70a0a9fa 131525->131534 131526 70a0d47f 131536 70a0d48b _errno 131526->131536 131772 70a0d70c fprintf 131526->131772 131527 70a0b7b9 strncmp 131527->131548 131784 70a0bf57 131527->131784 131545 70a0d2ed free 131528->131545 131537 70a0ae67 131529->131537 131530 70a0c7d8 131538 70a0c7e4 _errno 131530->131538 131539 70a0cc8f fprintf 131530->131539 131547 70a0d1e1 _errno strerror fprintf 131531->131547 131532->131548 131559 70a0b563 131533->131559 131560 70a0add6 131533->131560 131542 70a0aa06 strncmp 131534->131542 131534->131548 131543 70a0d9b8 _errno strerror fprintf 131536->131543 131742 70a0c12a fprintf fprintf fputc fclose 131536->131742 131537->131510 131538->131428 131538->131547 131539->131446 132024 70a04230 7 API calls 131540->132024 131562 70a0d620 _errno strerror fprintf 131541->131562 131550 70a0aa29 131542->131550 131564 70a0aa4a 131542->131564 131569 70a0d9d8 _errno strerror fprintf 131543->131569 131544 70a0bf9a 131551 70a0bfa6 _errno 131544->131551 131552 70a0ce37 fprintf 131544->131552 131545->131460 131554 70a0d640 131545->131554 131547->131448 131548->131508 131548->131523 131548->131527 131558 70a0b708 _errno 131548->131558 131548->131651 131548->131746 131548->131772 131548->131784 131563 70a0be80 _time64 131550->131563 131550->131564 131571 70a0bfb0 _errno strerror fprintf 131551->131571 131572 70a0bfcb 131551->131572 131552->131433 131595 70a0d8a5 fprintf 131554->131595 131596 70a0d65f _errno 131554->131596 132028 70a04230 7 API calls 131554->132028 131566 70a0aee1 131555->131566 131568 70a0b2e9 131555->131568 131587 70a0b28a sprintf strstr 131555->131587 131556 70a0cd9e 131556->131515 131567 70a0cdaa _errno 131556->131567 131558->131508 131574 70a0b571 131559->131574 131575 70a0ba62 131559->131575 131560->131548 131582 70a0bb50 131560->131582 131560->131746 131562->131554 131563->131427 131564->131508 131564->131548 131565 70a0aa84 strncmp 131564->131565 131576 70a0af30 131565->131576 131577 70a0aaa9 strncmp 131565->131577 131578 70a0b962 131566->131578 131566->131746 131567->131562 131579 70a0cdb6 fprintf fprintf fputc fclose 131567->131579 131568->131514 131568->131548 131568->131746 131569->131548 131571->131572 131609 70a0bff7 131572->131609 131572->131746 131573 70a0c179 fprintf 131615 70a0c199 fputc 131573->131615 131574->131421 131613 70a0b587 _errno strerror 131574->131613 132003 70a04230 7 API calls 131575->132003 131589 70a0b740 131576->131589 131590 70a0af4e 131576->131590 131585 70a0b070 131577->131585 131586 70a0aac9 131577->131586 132002 70a04230 7 API calls 131578->132002 131602 70a0ce13 fprintf 131579->131602 132004 70a04230 7 API calls 131582->132004 131610 70a0b091 131585->131610 131761 70a0c442 131585->131761 131586->131548 131599 70a0aad2 strncmp 131586->131599 131680 70a0c5a9 131586->131680 131699 70a0c3c0 131586->131699 131726 70a0c080 131586->131726 131744 70a0bddb strncmp 131586->131744 131790 70a0be15 131586->131790 131806 70a0b200 131586->131806 132005 70a230c0 24 API calls 131586->132005 131600 70a0b2c3 strcmp 131587->131600 131601 70a0d054 strstr 131587->131601 131588 70a0ba75 131603 70a0ba81 _errno 131588->131603 131777 70a0ca09 fprintf 131588->131777 132001 70a230c0 24 API calls 131589->132001 131623 70a0c1b0 131590->131623 131639 70a0af67 131590->131639 131592 70a0cfa8 fprintf 131663 70a0cfdf fprintf 131592->131663 131593 70a0caad _errno 131605 70a0cad2 fprintf fprintf fputc fclose 131593->131605 131606 70a0cab7 _errno strerror fprintf 131593->131606 131655 70a0d8dc fprintf 131595->131655 131596->131569 131608 70a0d66a fprintf fprintf fputc fclose 131596->131608 131597 70a0bc7f _errno 131611 70a0d0e5 _errno strerror fprintf 131597->131611 131612 70a0bc8b fprintf fprintf fputc fclose 131597->131612 131598 70a0b975 131616 70a0b981 _errno 131598->131616 131617 70a0c968 fprintf 131598->131617 131618 70a0b3c0 131599->131618 131619 70a0aaf8 strncmp 131599->131619 131600->131566 131600->131568 131601->131600 131631 70a0d071 strstr 131601->131631 131638 70a0ce25 fputc 131602->131638 131621 70a0ba90 _errno strerror fprintf 131603->131621 131622 70a0baab 8 API calls 131603->131622 131641 70a0cb2f fprintf 131605->131641 131606->131605 131607 70a0bb63 131624 70a0ca57 fprintf 131607->131624 131625 70a0bb6f _errno 131607->131625 131644 70a0d6c7 fprintf 131608->131644 132009 70a04230 7 API calls 131609->132009 131628 70a0b09c 131610->131628 131665 70a0b100 131610->131665 131611->131515 131648 70a0bce8 fprintf 131612->131648 131613->131746 131614 70a0d7d1 _errno 131630 70a0d7d8 _errno strerror fprintf 131614->131630 131614->131651 131615->131746 131633 70a0cf51 _errno strerror fprintf 131616->131633 131634 70a0b98d fprintf fprintf fputc fclose 131616->131634 131687 70a0c99f 131617->131687 131997 70a230c0 24 API calls 131618->131997 131635 70a0b5b2 131619->131635 131636 70a0ab18 strncmp 131619->131636 131621->131622 131658 70a0bb20 fprintf 131622->131658 131632 70a0c1c7 131623->131632 131623->131746 131624->131651 131642 70a0bb94 fprintf fprintf fputc fclose 131625->131642 131643 70a0bb79 _errno strerror fprintf 131625->131643 131626 70a0cb61 fprintf 131659 70a0cb8a 131626->131659 131995 70a230c0 24 API calls 131628->131995 131630->131651 131631->131600 131649 70a0d08e strstr 131631->131649 132012 70a04230 7 API calls 131632->132012 131676 70a0cf71 fprintf 131633->131676 131669 70a0b9f1 fprintf 131634->131669 131999 70a230c0 24 API calls 131635->131999 131636->131586 131654 70a0ab35 strncmp 131636->131654 131638->131552 131993 70a22f50 60 API calls 131639->131993 131640 70a0d98f fprintf 131640->131543 131672 70a0cb41 fputc 131641->131672 131673 70a0bbf1 fprintf 131642->131673 131643->131642 131674 70a0d6d9 fputc 131644->131674 131646 70a0c00a 131646->131447 131661 70a0c016 _errno 131646->131661 131681 70a0bcfa fputc 131648->131681 131649->131600 131651->131457 131651->131469 131651->131482 131651->131487 131651->131497 131651->131501 131651->131513 131651->131522 131651->131592 131651->131593 131651->131597 131651->131614 131651->131626 131651->131640 131686 70a0d814 fprintf 131651->131686 131722 70a0d351 _errno 131651->131722 131654->131548 131670 70a0ab52 strchr 131654->131670 131655->131462 131693 70a0bb35 fputc 131658->131693 131659->131460 131659->131651 131660 70a0b755 131660->131548 131660->131746 132015 70a04230 7 API calls 131660->132015 131677 70a0b258 fprintf fprintf fputc fclose 131661->131677 131678 70a0c01e _errno strerror fprintf 131661->131678 131662 70a0da02 131724 70a0d016 fprintf 131663->131724 131664 70a0c0d3 131682 70a0c0e8 131664->131682 131664->131746 131665->131664 131666 70a0b113 131665->131666 131666->131687 131762 70a0b0b4 131666->131762 131667 70a0b5dc 131684 70a0ba20 131667->131684 131685 70a0b5e7 131667->131685 131668 70a0c1da 131668->131663 131688 70a0c1e6 _errno 131668->131688 131703 70a0ba0a fputc 131669->131703 131689 70a0bc15 131670->131689 131690 70a0ab6d 131670->131690 131671 70a0af88 131671->131498 131692 70a0af90 131671->131692 131672->131651 131708 70a0bc03 fputc 131673->131708 131674->131548 131676->131592 131677->131462 131678->131677 131679 70a0b0bc 131679->131512 131679->131746 131680->131746 132016 70a04230 7 API calls 131680->132016 131681->131548 132011 70a04230 7 API calls 131682->132011 131705 70a0cbca 131684->131705 131684->131746 131685->131572 131685->131685 131729 70a0b63e strncmp 131685->131729 131686->131651 131704 70a0c9b4 131687->131704 131687->131746 131701 70a0d4e0 _errno strerror fprintf 131688->131701 131702 70a0c1f4 fprintf fprintf fputc fclose 131688->131702 131689->131460 131689->131468 131706 70a0ab7a strchr 131690->131706 131768 70a0c670 strchr 131690->131768 131707 70a0cec5 131692->131707 131692->131746 131693->131582 131694 70a0c428 131694->131515 131711 70a0c434 _errno 131694->131711 131696 70a0c4e2 isxdigit 131696->131680 131696->131761 131699->131540 131699->131746 131730 70a0ac3b 131701->131730 131731 70a0c243 fprintf 131702->131731 131703->131684 132021 70a04230 7 API calls 131704->132021 132022 70a04230 7 API calls 131705->132022 131706->131452 131718 70a0ab97 131706->131718 132025 70a04230 7 API calls 131707->132025 131708->131689 131709 70a0bf00 131709->131746 132007 70a04230 7 API calls 131709->132007 131710 70a0b3ea 131710->131548 131710->131709 131720 70a0b44c strncmp 131710->131720 131711->131541 131711->131761 131713 70a0c0fb 131713->131676 131725 70a0c107 _errno 131713->131725 131714 70a0c275 131733 70a0c28a 131714->131733 131714->131746 131715 70a0c5d8 131727 70a0d554 fprintf 131715->131727 131728 70a0c5e4 _errno 131715->131728 131991 70a024c0 strlen strlen malloc _strdup 131718->131991 131720->131709 131738 70a0b464 131720->131738 131740 70a0d885 _errno strerror fprintf 131722->131740 131741 70a0d35d fprintf fprintf fputc fclose 131722->131741 131723 70a0c4ff isxdigit 131723->131680 131723->131761 131724->131462 131725->131742 131743 70a0c10f _errno strerror fprintf 131725->131743 131726->131746 131760 70a0c095 131726->131760 131727->131651 131728->131746 131747 70a0c5ec _errno strerror fprintf 131728->131747 131729->131572 131745 70a0b656 131729->131745 131831 70a0ac52 131730->131831 132027 70a04230 7 API calls 131730->132027 131793 70a0c263 fputc 131731->131793 131732 70a0c9c7 131748 70a0c9d3 _errno 131732->131748 131749 70a0d4a9 fprintf 131732->131749 132013 70a04230 7 API calls 131733->132013 131737 70a0ced8 131756 70a0cee4 _errno 131737->131756 131757 70a0d3de fprintf 131737->131757 131738->131548 131738->131746 131786 70a0b49e 131738->131786 131739 70a0cbdd 131758 70a0cbe9 _errno 131739->131758 131759 70a0d0ae fprintf 131739->131759 131740->131595 131776 70a0d3ba fprintf 131741->131776 131742->131573 131743->131742 131744->131586 131744->131726 131745->131548 131780 70a0b679 131745->131780 131746->131421 131747->131746 131748->131742 131765 70a0c9db _errno strerror fprintf 131748->131765 131749->131573 131752 70a0aba2 131752->131659 131992 70a04900 15 API calls 131752->131992 131753 70a0c6d3 atof 131753->131548 131753->131769 131754 70a0c6b5 atof 131754->131548 131754->131768 131755 70a0bf28 131755->131499 131770 70a0bf34 _errno 131755->131770 131756->131702 131771 70a0ceec _errno strerror fprintf 131756->131771 131757->131731 131774 70a0cbf3 _errno strerror fprintf 131758->131774 131775 70a0cc0e fprintf fprintf fputc fclose 131758->131775 131759->131611 132010 70a04230 7 API calls 131760->132010 131761->131428 131761->131586 131761->131662 131761->131680 131761->131696 131761->131723 131761->131777 131805 70a0c577 memcmp 131761->131805 131762->131586 131762->131679 131762->131714 131763 70a0d513 131763->131651 131781 70a0d51f _errno 131763->131781 131765->131742 131767 70a0c29d 131767->131724 131782 70a0c2a9 _errno 131767->131782 131768->131753 131768->131754 131769->131651 132017 70a04230 7 API calls 131769->132017 131770->131784 131785 70a0bf3c _errno strerror fprintf 131770->131785 131771->131702 131772->131573 131774->131775 131799 70a0cc6b fprintf 131775->131799 131800 70a0d3cc fputc 131776->131800 131777->131624 131780->131746 131791 70a0b68e 131780->131791 131781->131651 131792 70a0d526 _errno strerror fprintf 131781->131792 131782->131677 131794 70a0c2b3 _errno strerror fprintf 131782->131794 131784->131746 132008 70a04230 7 API calls 131784->132008 131785->131784 131998 70a04230 7 API calls 131786->131998 131787 70a0c0a8 131797 70a0c0b4 _errno 131787->131797 131798 70a0cf1a fprintf 131787->131798 131790->131746 131801 70a0be2a 131790->131801 132000 70a04230 7 API calls 131791->132000 131792->131651 131793->131746 131794->131677 131795 70a0abbb 131795->131545 131803 70a0abca free 131795->131803 131797->131509 131797->131677 131798->131462 131813 70a0cc7d fputc 131799->131813 131800->131757 132006 70a04230 7 API calls 131801->132006 131803->131724 131809 70a0abde 131803->131809 131804 70a0b4b1 131811 70a0d94a fprintf 131804->131811 131812 70a0b4bd _errno 131804->131812 131805->131761 131806->131746 131814 70a0b217 131806->131814 131808 70a0b6a1 131816 70a0d913 fprintf 131808->131816 131817 70a0b6ad _errno 131808->131817 131809->131724 131826 70a0ac0b free atof 131809->131826 131811->131651 131812->131677 131818 70a0b4c4 _errno strerror fprintf 131812->131818 131813->131539 131996 70a04230 7 API calls 131814->131996 131815 70a0be3d 131815->131655 131820 70a0be49 _errno 131815->131820 131816->131462 131817->131677 131821 70a0b6b4 _errno strerror fprintf 131817->131821 131818->131677 131820->131677 131824 70a0be50 _errno strerror fprintf 131820->131824 131821->131677 131823 70a0b22a 131827 70a0b236 _errno 131823->131827 131828 70a0d77b fprintf 131823->131828 131824->131677 131826->131548 131826->131730 131827->131677 131829 70a0b23d _errno strerror fprintf 131827->131829 131828->131462 131829->131677 131831->131474 131832->131275 131834 70a2bd51 131833->131834 131835 70a2c16a 131833->131835 131837 70a2c151 131834->131837 131847 70a0a820 131834->131847 132029 70a2d400 __iob_func abort 131834->132029 132031 70a2d400 __iob_func abort 131835->132031 132030 70a2d400 __iob_func abort 131837->132030 131847->131427 131847->131430 131847->131431 131864 70a303a0 131863->131864 131865 70a307fc 131863->131865 131866 70a307e3 131864->131866 131868 70a303bb 131864->131868 131869 70a307ca 131864->131869 132039 70a2d400 __iob_func abort 131865->132039 131866->131865 132038 70a2d400 __iob_func abort 131866->132038 131878 70a0a916 131868->131878 131879 70a30415 calloc 131868->131879 132037 70a2d400 __iob_func abort 131869->132037 131878->131439 131906 70a30fc0 131878->131906 131882 70a30434 131879->131882 131887 70a30518 131879->131887 132032 70a334c0 6 API calls 131882->132032 131884 70a3046a 131885 70a304e0 131884->131885 131886 70a3046e 131884->131886 132034 70a33350 __iob_func abort calloc free 131885->132034 132033 70a33350 __iob_func abort calloc free 131886->132033 131890 70a305d3 131887->131890 131891 70a30740 131887->131891 131898 70a304c4 131887->131898 131890->131898 132035 70a33350 __iob_func abort calloc free 131890->132035 131891->131898 132036 70a33350 __iob_func abort calloc free 131891->132036 131892 70a304ce free 131892->131878 131898->131892 131907 70a3125b 131906->131907 131908 70a30fff 131906->131908 132044 70a2d400 __iob_func abort 131907->132044 131910 70a31242 131908->131910 131913 70a31229 131908->131913 131916 70a31210 131908->131916 131922 70a3101a 131908->131922 132043 70a2d400 __iob_func abort 131910->132043 131912 70a31274 memcmp 131914 70a3128a 131912->131914 131915 70a3117e free 131912->131915 132042 70a2d400 __iob_func abort 131913->132042 131914->131915 131918 70a31186 free 131915->131918 132041 70a2d400 __iob_func abort 131916->132041 131921 70a31195 131918->131921 131920 70a0a968 131945 70a30310 131920->131945 131921->131918 131923 70a36f00 22 API calls 131921->131923 131922->131920 131924 70a31094 malloc 131922->131924 131923->131921 131924->131920 131925 70a310ab 131924->131925 131925->131918 131926 70a310ea free 131925->131926 131927 70a310fe 131925->131927 131926->131920 131927->131921 131928 70a31107 malloc 131927->131928 131928->131918 131929 70a31139 131928->131929 132040 70a37b90 memcpy 131929->132040 131931 70a31168 131931->131915 131932 70a31173 131931->131932 131933 70a311e1 131931->131933 131932->131912 131932->131915 131933->131921 132045 70a328a0 __iob_func abort 131933->132045 131935 70a31391 131936 70a313db 131935->131936 132046 70a328a0 __iob_func abort 131935->132046 131941 70a3147d free 131936->131941 132047 70a33ba0 __iob_func abort 131936->132047 131939 70a313f8 131940 70a313ff 131939->131940 131939->131941 131940->131915 131942 70a3142d memcmp 131940->131942 131942->131915 131943 70a3144f 131942->131943 131943->131915 131944 70a3145d memcmp 131943->131944 131944->131914 131944->131915 131946 70a30364 131945->131946 131947 70a3031c 131945->131947 132048 70a2d400 __iob_func abort 131946->132048 131947->131502 131991->131752 131992->131795 131993->131671 131994->131426 131995->131762 131996->131823 131997->131710 131998->131804 131999->131667 132000->131808 132001->131660 132002->131598 132003->131588 132004->131607 132005->131586 132006->131815 132007->131755 132008->131544 132009->131646 132010->131787 132011->131713 132012->131668 132013->131767 132014->131461 132015->131694 132016->131715 132017->131441 132018->131463 132019->131530 132020->131470 132021->131732 132022->131739 132023->131483 132024->131556 132025->131737 132026->131526 132027->131763 132028->131554 132032->131884 132033->131898 132034->131887 132035->131898 132036->131898 132040->131931 132045->131935 132046->131936 132047->131939 132049 7ffde402a1a0 132083 7ffde402a1c2 132049->132083 132050 7ffde402a878 132060 7ffde402a8f0 132050->132060 132067 7ffde402a915 132050->132067 132071 7ffde402aa85 132050->132071 132130 7ffde4023620 29 API calls 132050->132130 132052 7ffde402a860 132128 7ffde40463c0 24 API calls 132052->132128 132054 7ffde402a7e9 132054->132050 132054->132052 132057 7ffde402a83f 132054->132057 132127 7ffde4045f00 TlsGetValue 132054->132127 132056 7ffde402a7eb 132056->132054 132126 7ffde403c5f0 memmove memmove TlsGetValue TlsGetValue 132056->132126 132129 7ffde4023620 29 API calls 132057->132129 132058 7ffde402aa08 132131 7ffde403c5f0 memmove memmove TlsGetValue TlsGetValue 132060->132131 132065 7ffde402a95c 132065->132058 132132 7ffde4046220 132065->132132 132066 7ffde402aa0a 132066->132071 132148 7ffde3ff6e00 TlsGetValue 132066->132148 132117 7ffde3ff7980 132067->132117 132070 7ffde403bbf0 29 API calls 132070->132083 132072 7ffde403c5f0 memmove memmove TlsGetValue TlsGetValue 132072->132083 132073 7ffde402a96a 132073->132071 132146 7ffde4037950 25 API calls 132073->132146 132075 7ffde402a9da 132147 7ffde4038170 79 API calls 132075->132147 132078 7ffde402a44a _errno 132078->132083 132079 7ffde403c200 30 API calls 132079->132083 132080 7ffde4023620 29 API calls 132080->132083 132082 7ffde4045f00 TlsGetValue 132082->132083 132083->132054 132083->132056 132083->132070 132083->132071 132083->132072 132083->132078 132083->132079 132083->132080 132083->132082 132085 7ffde40463c0 24 API calls 132083->132085 132086 7ffde3ffa600 132083->132086 132124 7ffde402ab10 106 API calls 132083->132124 132125 7ffde403c810 191 API calls 132083->132125 132085->132083 132087 7ffde3ffa615 132086->132087 132088 7ffde3ffa734 132086->132088 132087->132088 132089 7ffde3ffa61d 132087->132089 132105 7ffde402c545 132088->132105 132108 7ffde3ffa600 106 API calls 132088->132108 132176 7ffde402cde0 41 API calls 132088->132176 132177 7ffde402cb70 25 API calls 132088->132177 132178 7ffde402c6a0 106 API calls 132088->132178 132149 7ffde3ff6a80 TlsGetValue 132089->132149 132094 7ffde3ffa6db 132172 7ffde3ff6d70 TlsGetValue 132094->132172 132095 7ffde3ffa67c 132095->132094 132098 7ffde3ffa697 132095->132098 132099 7ffde3ffa6a1 132095->132099 132096 7ffde3ffa639 132096->132095 132096->132099 132100 7ffde3ffa66a 132096->132100 132168 7ffde402cde0 41 API calls 132096->132168 132171 7ffde3ff6d70 TlsGetValue 132098->132171 132099->132094 132110 7ffde3ffa6f8 132099->132110 132169 7ffde402cb70 25 API calls 132100->132169 132101 7ffde3ffa69c 132101->132083 132105->132083 132108->132088 132109 7ffde3ffa672 132170 7ffde402c6a0 106 API calls 132109->132170 132112 7ffde3ffa711 132110->132112 132173 7ffde402c6a0 106 API calls 132110->132173 132115 7ffde3ffa726 132112->132115 132174 7ffde3ff6e00 TlsGetValue 132112->132174 132175 7ffde3ff6d70 TlsGetValue 132115->132175 132118 7ffde3ff6a80 21 API calls 132117->132118 132119 7ffde3ff79a8 132118->132119 132120 7ffde3ff6ce0 TlsGetValue 132119->132120 132122 7ffde3ff79b0 132120->132122 132183 7ffde3ff6d70 TlsGetValue 132122->132183 132123 7ffde3ff7a1e 132123->132058 132123->132065 132123->132066 132125->132083 132126->132054 132127->132052 132128->132057 132129->132050 132130->132060 132131->132067 132133 7ffde404624c TlsGetValue 132132->132133 132134 7ffde404622d TlsAlloc 132132->132134 132136 7ffde4046277 132133->132136 132137 7ffde4046269 GetLastError 132133->132137 132134->132133 132138 7ffde404627c 132136->132138 132144 7ffde4046284 132136->132144 132137->132136 132184 7ffde4045bb0 22 API calls 132138->132184 132139 7ffde404636a 132139->132073 132141 7ffde4046281 132141->132144 132142 7ffde40462f1 LeaveCriticalSection 132142->132139 132143 7ffde4046308 GetProcessHeap HeapAlloc 132142->132143 132145 7ffde404632a 132143->132145 132144->132139 132144->132142 132144->132144 132145->132139 132145->132145 132146->132075 132147->132058 132148->132058 132152 7ffde3ff6aa9 132149->132152 132150 7ffde3ff6b13 132151 7ffde3ff6b34 TlsGetValue 132150->132151 132164 7ffde3ff6c8c 132150->132164 132156 7ffde3ff6b52 132151->132156 132152->132150 132153 7ffde3ff6ae7 132152->132153 132154 7ffde3ff6cb3 132152->132154 132179 7ffde4046bc0 18 API calls 132153->132179 132156->132154 132157 7ffde3ff6ba7 132156->132157 132158 7ffde3ff6b7b 132156->132158 132157->132154 132160 7ffde3ff6c39 LeaveCriticalSection 132157->132160 132180 7ffde4046bc0 18 API calls 132158->132180 132161 7ffde3ff6c78 132160->132161 132165 7ffde3ff6c5a 132160->132165 132161->132164 132182 7ffde3fc6ab0 18 API calls 132161->132182 132166 7ffde3ff6ce0 TlsGetValue 132164->132166 132165->132161 132181 7ffde4045f00 TlsGetValue 132165->132181 132167 7ffde3ff6d13 132166->132167 132167->132096 132168->132100 132169->132109 132171->132101 132172->132101 132174->132115 132175->132101 132176->132088 132177->132088 132179->132150 132180->132157 132181->132165 132182->132164 132183->132123 132184->132141 132185 7ffde4072b10 GetFileType 132186 7ffde4072b39 132185->132186 132187 7ffde4072b47 GetConsoleMode 132185->132187 132188 7ffde4072b59 132186->132188 132189 7ffde4072b3d GetLastError 132186->132189 132187->132188 132190 7ffde4072b60 GetCommState 132187->132190 132193 7ffde4086240 8 API calls 2 library calls 132188->132193 132189->132187 132189->132188 132190->132188 132192 7ffde4072b8f 132193->132192 132194 7ffde4053220 132199 7ffde40530d0 132194->132199 132196 7ffde4053425 132220 7ffde4086240 8 API calls 2 library calls 132196->132220 132198 7ffde4053439 132199->132194 132199->132196 132202 7ffde40533e6 132199->132202 132205 7ffde40533f5 132199->132205 132207 7ffde4053193 memmove 132199->132207 132214 7ffde4045f00 TlsGetValue 132199->132214 132217 7ffde4052f30 49 API calls 132199->132217 132201 7ffde4053401 LeaveCriticalSection 132201->132196 132218 7ffde3fc69b0 LeaveCriticalSection LeaveCriticalSection TlsGetValue 132202->132218 132219 7ffde403bbf0 29 API calls 132205->132219 132208 7ffde40531b3 132207->132208 132209 7ffde40531ae 132207->132209 132216 7ffde4052f30 49 API calls 132208->132216 132215 7ffde3fbb4e0 LeaveCriticalSection TlsGetValue 132209->132215 132212 7ffde40531c2 132213 7ffde40531db LeaveCriticalSection 132212->132213 132214->132199 132216->132212 132217->132199 132219->132201 132220->132198 132221 7ffde3fea8c0 132222 7ffde3fea927 132221->132222 132223 7ffde3fea92c 132221->132223 132249 7ffde3fea620 TlsGetValue 132222->132249 132225 7ffde3fea94b memchr 132223->132225 132246 7ffde3fea960 132223->132246 132225->132246 132226 7ffde3fead40 132253 7ffde4086240 8 API calls 2 library calls 132226->132253 132228 7ffde3fea9dd memmove 132228->132246 132229 7ffde3fead9a 132230 7ffde4046220 28 API calls 132233 7ffde3feadfa 132230->132233 132231 7ffde3feadad 132231->132230 132232 7ffde3fead0d 132235 7ffde3fead1a 132232->132235 132251 7ffde4045f00 TlsGetValue 132232->132251 132239 7ffde3feae45 132233->132239 132254 7ffde4051b00 TlsGetValue memmove memmove 132233->132254 132234 7ffde3feac58 memmove 132234->132246 132235->132226 132237 7ffde3fead22 _errno 132235->132237 132237->132226 132240 7ffde3feae92 132239->132240 132241 7ffde3feae61 132239->132241 132255 7ffde4045f00 TlsGetValue 132239->132255 132256 7ffde40463c0 24 API calls 132240->132256 132245 7ffde3fead33 132245->132226 132252 7ffde4045f00 TlsGetValue 132245->132252 132246->132226 132246->132228 132246->132231 132246->132232 132246->132234 132246->132245 132247 7ffde3feac00 memchr 132246->132247 132250 7ffde4045f00 TlsGetValue 132246->132250 132247->132246 132249->132223 132250->132246 132251->132235 132252->132226 132253->132229 132254->132239 132255->132240 132256->132241
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: strncmp$free$_errnofprintf$fputc$strchr$atoffclose$_time64getenvstrerror
                                                                                                                                                                                                                                    • String ID: %s$%s,%d,0x%x,$*$*CODE:$*DOMAIN:$*FIXKEY:$*FLAGS:$*HARDDISK:$*IFIPV4:$*IFIPV6:$*IFMAC:$*TIME:$*VERSION:$Pyarmor$_vax_%s$clickbank$license.c$pyarmor-test-0001$pytransform.log$regnow$shareit
                                                                                                                                                                                                                                    • API String ID: 1877277240-1732257083
                                                                                                                                                                                                                                    • Opcode ID: 0ab194c1bf24722a606870c51134e8615c4c9e8748de1bb9da5860feec46e328
                                                                                                                                                                                                                                    • Instruction ID: 9e1d1b8ada2dcebee2fe6bcc057d11c69bf52c235d1179b5613465b19a765894
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0ab194c1bf24722a606870c51134e8615c4c9e8748de1bb9da5860feec46e328
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 42338B7171874ADAEB159B21FA1079D23A5FB88BC4F44422AD94E5B36CEF3CE509C312

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2169 70a0e6f0-70a0e73f 2170 70a0e9e2-70a0e9e4 2169->2170 2171 70a0e745-70a0e74d 2169->2171 2172 70a0e92e-70a0e93d 2170->2172 2173 70a0e940-70a0e947 2171->2173 2174 70a0e753-70a0e75b 2171->2174 2175 70a0e917-70a0e91e 2173->2175 2174->2173 2176 70a0e761-70a0e791 2174->2176 2177 70a0e927-70a0e929 call 70a01c70 2175->2177 2180 70a0e910 2176->2180 2181 70a0e797-70a0e79f 2176->2181 2177->2172 2180->2175 2182 70a0ea74-70a0ea90 call 70a01c70 2181->2182 2183 70a0e7a5-70a0e7b1 2181->2183 2182->2172 2187 70a0e980-70a0e989 2183->2187 2188 70a0e7b7-70a0e7bc 2183->2188 2190 70a0ea30-70a0ea37 2187->2190 2191 70a0e98f-70a0e996 2187->2191 2192 70a0e7c4-70a0e7e3 2188->2192 2190->2191 2193 70a0ea3d-70a0ea49 2190->2193 2194 70a0e999-70a0e9a0 2191->2194 2192->2175 2198 70a0e7e9-70a0e7ff 2192->2198 2193->2194 2194->2192 2195 70a0e9a6-70a0e9b8 2194->2195 2195->2192 2197 70a0e9be-70a0e9cb 2195->2197 2199 70a0e9d1-70a0e9dd 2197->2199 2200 70a0ea95-70a0ea98 2197->2200 2206 70a0e9f0-70a0ea0c call 70a01c70 2198->2206 2207 70a0e805-70a0e829 strlen strncmp 2198->2207 2199->2192 2201 70a0ea9a-70a0eaa1 2200->2201 2202 70a0eaaf-70a0eab6 2200->2202 2203 70a0eaa4-70a0eaaa 2201->2203 2202->2201 2205 70a0eab8-70a0eac4 2202->2205 2203->2199 2205->2203 2206->2172 2208 70a0e881-70a0e896 call 70a0dc10 2207->2208 2209 70a0e82b-70a0e830 2207->2209 2214 70a0e89b-70a0e8a2 2208->2214 2209->2208 2212 70a0e832-70a0e843 2209->2212 2215 70a0e858-70a0e864 2212->2215 2216 70a0e950-70a0e954 2214->2216 2217 70a0e8a8-70a0e8b8 2214->2217 2219 70a0e845-70a0e852 2215->2219 2220 70a0e866-70a0e86d 2215->2220 2221 70a0ea50-70a0ea54 2216->2221 2222 70a0e95a-70a0e973 2216->2222 2225 70a0e8c1-70a0e8c4 2217->2225 2219->2215 2223 70a0eaea 2219->2223 2220->2219 2224 70a0e86f-70a0e877 2220->2224 2226 70a0eac6-70a0eaca 2221->2226 2227 70a0ea56-70a0ea6f 2221->2227 2222->2225 2232 70a0eaf4-70a0eaf8 2223->2232 2224->2208 2228 70a0e879-70a0e87e 2224->2228 2229 70a0e8f4-70a0e8fd 2225->2229 2230 70a0e8c6-70a0e8c9 2225->2230 2226->2232 2233 70a0eacc-70a0eae5 2226->2233 2227->2225 2228->2208 2229->2177 2248 70a0e8ff-70a0e90e 2229->2248 2230->2229 2234 70a0e8cb-70a0e8d2 2230->2234 2236 70a0eb18-70a0eb1c 2232->2236 2237 70a0eafa-70a0eb13 2232->2237 2233->2225 2239 70a0ea11-70a0ea18 2234->2239 2240 70a0e8d8-70a0e8df 2234->2240 2236->2237 2238 70a0eb1e-70a0eb22 2236->2238 2237->2236 2244 70a0eb42-70a0eb46 2238->2244 2245 70a0eb24-70a0eb3d 2238->2245 2239->2240 2246 70a0ea1e-70a0ea2a 2239->2246 2247 70a0e8e2-70a0e8ef 2240->2247 2249 70a0eb66-70a0eb6a 2244->2249 2250 70a0eb48-70a0eb61 2244->2250 2245->2225 2246->2247 2247->2229 2249->2237 2252 70a0eb6c-70a0eb70 2249->2252 2250->2225 2254 70a0eb90-70a0eb94 2252->2254 2255 70a0eb72-70a0eb8b 2252->2255 2256 70a0ebb4-70a0ebb8 2254->2256 2257 70a0eb96-70a0ebaf 2254->2257 2255->2225 2258 70a0ebd8-70a0ebdc 2256->2258 2259 70a0ebba-70a0ebd3 2256->2259 2257->2225 2258->2225 2262 70a0ebe2-70a0ebfb 2258->2262 2259->2225 2262->2225
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • The python version in runtime is different from the build time, xrefs: 70A0E8B1
                                                                                                                                                                                                                                    • The runtime library doesn't support Super Mode, xrefs: 70A0E961
                                                                                                                                                                                                                                    • The runtime library doesn't support Advanced Mode, xrefs: 70A0EA5D
                                                                                                                                                                                                                                    • ssO|i, xrefs: 70A0E770
                                                                                                                                                                                                                                    • This obfuscated script is obfuscated by old PyArmor, xrefs: 70A0EB4F
                                                                                                                                                                                                                                    • NULL code object, xrefs: 70A0EA7B
                                                                                                                                                                                                                                    • Marshal loads failed, xrefs: 70A0EB79
                                                                                                                                                                                                                                    • Loaded module __main__ not found in sys.modules, xrefs: 70A0EB9D
                                                                                                                                                                                                                                    • Incompatible core library, xrefs: 70A0EBE9
                                                                                                                                                                                                                                    • <frozen pyarmor>, xrefs: 70A0E6FC
                                                                                                                                                                                                                                    • Got string from code object failed, xrefs: 70A0E7DC, 70A0E9F7
                                                                                                                                                                                                                                    • Invalid parameter, xrefs: 70A0E910
                                                                                                                                                                                                                                    • Check restrict mode of module failed, xrefs: 70A0EAD3
                                                                                                                                                                                                                                    • Enable restrict mode failed, xrefs: 70A0EBC1
                                                                                                                                                                                                                                    • Restore module failed, xrefs: 70A0EB01
                                                                                                                                                                                                                                    • Check the restrict mode of module failed, xrefs: 70A0EB2B
                                                                                                                                                                                                                                    • Python interpreter is debug version, xrefs: 70A0E940
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: strlenstrncmp
                                                                                                                                                                                                                                    • String ID: <frozen pyarmor>$Check restrict mode of module failed$Check the restrict mode of module failed$Enable restrict mode failed$Got string from code object failed$Incompatible core library$Invalid parameter$Loaded module __main__ not found in sys.modules$Marshal loads failed$NULL code object$Python interpreter is debug version$Restore module failed$The python version in runtime is different from the build time$The runtime library doesn't support Advanced Mode$The runtime library doesn't support Super Mode$This obfuscated script is obfuscated by old PyArmor$ssO|i
                                                                                                                                                                                                                                    • API String ID: 1310274236-189690365
                                                                                                                                                                                                                                    • Opcode ID: c76b4630db5dba8b94918e888814963c6e56fdf8d1109c16338af8bbd98566b7
                                                                                                                                                                                                                                    • Instruction ID: e8202e0a391df97a66eca3d7aa74d733dc9f664c9cb6af039623d3c9ba643694
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c76b4630db5dba8b94918e888814963c6e56fdf8d1109c16338af8bbd98566b7
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 20D14E72B09B09D5EB15CF15F88035963B5F799B88F844226D90E87728EF7CE688E341
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2178175784.00007FFDE3F41000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFDE3F40000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178149093.00007FFDE3F40000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178285367.00007FFDE4088000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178332844.00007FFDE40CF000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178375766.00007FFDE40D2000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3f40000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _errno
                                                                                                                                                                                                                                    • String ID: PATH$TCL$UpdateStringProc for type '%s' failed to create a valid string rep$UpdateStringProc should not be invoked for type %s$VALUE$WTF$ntation$unable to alloc %u bytes
                                                                                                                                                                                                                                    • API String ID: 2918714741-3483878451
                                                                                                                                                                                                                                    • Opcode ID: 9d498abfc2765ea8c37c9f8485d8f0e0786074b00d434953e022ca2e09b5be3e
                                                                                                                                                                                                                                    • Instruction ID: 7e504f7b071434dc8a2d97d637f07cba5e4ec0caba291f91150449808a978f78
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9d498abfc2765ea8c37c9f8485d8f0e0786074b00d434953e022ca2e09b5be3e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2B52E229F0864386FA6D9B2581F437967A1AF57B85F088035CA4D07EC3DF2CE445AB0A

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2811 7ffde3fea8c0-7ffde3fea925 2812 7ffde3fea927-7ffde3fea92c call 7ffde3fea620 2811->2812 2813 7ffde3fea92f-7ffde3fea943 2811->2813 2812->2813 2815 7ffde3fea94b-7ffde3fea95b memchr 2813->2815 2816 7ffde3fea945-7ffde3fea949 2813->2816 2818 7ffde3fea960-7ffde3fea96e 2815->2818 2816->2815 2816->2818 2819 7ffde3fea974-7ffde3fea97a 2818->2819 2820 7ffde3fead80 2818->2820 2821 7ffde3fea97c-7ffde3fea97e 2819->2821 2822 7ffde3fea980-7ffde3fea987 2819->2822 2823 7ffde3fead82-7ffde3feadac call 7ffde4086240 2820->2823 2821->2822 2824 7ffde3fea989-7ffde3fea9a2 call 7ffde4045db0 2822->2824 2825 7ffde3fea9d8-7ffde3fea9db 2822->2825 2835 7ffde3fea9a4-7ffde3fea9a7 2824->2835 2836 7ffde3fea9ad-7ffde3fea9d4 2824->2836 2828 7ffde3fea9ff-7ffde3feaa03 2825->2828 2829 7ffde3fea9dd-7ffde3fea9fc memmove 2825->2829 2832 7ffde3feaa09-7ffde3feaa48 2828->2832 2833 7ffde3feadca-7ffde3feae19 call 7ffde4027370 call 7ffde4046220 call 7ffde3feaec0 2828->2833 2829->2828 2837 7ffde3feaa4a-7ffde3feaa4c 2832->2837 2838 7ffde3feaa4e-7ffde3feaa50 2832->2838 2856 7ffde3feae1e-7ffde3feae22 2833->2856 2835->2836 2840 7ffde3feadad-7ffde3feadbc call 7ffde4027370 2835->2840 2836->2825 2841 7ffde3feaa69-7ffde3feaad4 2837->2841 2838->2841 2842 7ffde3feaa52-7ffde3feaa59 2838->2842 2852 7ffde3feadbd-7ffde3feadc9 call 7ffde4027370 2840->2852 2849 7ffde3feaad6-7ffde3feaadb 2841->2849 2850 7ffde3feaae1-7ffde3feaaf5 2841->2850 2845 7ffde3feaa60-7ffde3feaa67 2842->2845 2845->2841 2845->2845 2849->2850 2854 7ffde3feaaf7-7ffde3feaafd 2850->2854 2855 7ffde3feab03-7ffde3feab2f 2850->2855 2852->2833 2854->2855 2858 7ffde3fead0d-7ffde3fead10 2854->2858 2859 7ffde3feab35-7ffde3feab38 2855->2859 2860 7ffde3feac4f-7ffde3feac56 2855->2860 2861 7ffde3feae45-7ffde3feae4f 2856->2861 2862 7ffde3feae24-7ffde3feae2b 2856->2862 2867 7ffde3fead1a-7ffde3fead20 2858->2867 2868 7ffde3fead12-7ffde3fead15 call 7ffde4045f00 2858->2868 2859->2860 2869 7ffde3feab3e-7ffde3feab44 2859->2869 2865 7ffde3feac7b-7ffde3feac87 2860->2865 2866 7ffde3feac58-7ffde3feac78 memmove 2860->2866 2863 7ffde3feaea1-7ffde3feaeb2 2861->2863 2864 7ffde3feae51-7ffde3feae58 2861->2864 2870 7ffde3feae39-7ffde3feae40 call 7ffde4051b00 2862->2870 2871 7ffde3feae2d-7ffde3feae35 call 7ffde4023710 2862->2871 2872 7ffde3feae7b-7ffde3feae82 2864->2872 2873 7ffde3feae5a-7ffde3feae5f 2864->2873 2874 7ffde3feac9c-7ffde3feac9f 2865->2874 2875 7ffde3feac89-7ffde3feac97 2865->2875 2866->2865 2879 7ffde3fead4b-7ffde3fead4f 2867->2879 2880 7ffde3fead22-7ffde3fead31 _errno 2867->2880 2868->2867 2877 7ffde3feab69 2869->2877 2878 7ffde3feab46-7ffde3feab49 2869->2878 2870->2861 2871->2870 2885 7ffde3feae84-7ffde3feae8b 2872->2885 2886 7ffde3feae92-7ffde3feae9c call 7ffde40463c0 2872->2886 2873->2872 2884 7ffde3feae61-7ffde3feae7a call 7ffde4023420 2873->2884 2887 7ffde3feace3 2874->2887 2888 7ffde3feaca1-7ffde3feacb5 call 7ffde3fe8e70 2874->2888 2875->2874 2892 7ffde3feab6f 2877->2892 2889 7ffde3feab4b-7ffde3feab4e 2878->2889 2890 7ffde3feab5a-7ffde3feab67 2878->2890 2879->2820 2883 7ffde3fead51-7ffde3fead56 2879->2883 2880->2823 2894 7ffde3fead58-7ffde3fead5d 2883->2894 2895 7ffde3fead63-7ffde3fead77 call 7ffde3fe8e70 2883->2895 2885->2886 2897 7ffde3feae8d call 7ffde4045f00 2885->2897 2886->2863 2893 7ffde3feace6-7ffde3feace9 2887->2893 2914 7ffde3feacb7-7ffde3feaccc 2888->2914 2915 7ffde3fead33-7ffde3fead36 2888->2915 2889->2852 2900 7ffde3feab54-7ffde3feab58 2889->2900 2901 7ffde3feab76-7ffde3feabf3 2890->2901 2892->2901 2902 7ffde3feaceb-7ffde3feacee call 7ffde4045f00 2893->2902 2903 7ffde3feacf3-7ffde3fead01 2893->2903 2894->2820 2904 7ffde3fead5f-7ffde3fead61 2894->2904 2895->2820 2918 7ffde3fead79-7ffde3fead7e 2895->2918 2897->2886 2900->2892 2916 7ffde3feabf5-7ffde3feabfa 2901->2916 2917 7ffde3feac00-7ffde3feac47 memchr 2901->2917 2902->2903 2911 7ffde3fead47 2903->2911 2912 7ffde3fead03-7ffde3fead08 2903->2912 2904->2820 2904->2895 2911->2879 2912->2819 2914->2887 2920 7ffde3feacce-7ffde3feacd1 2914->2920 2915->2918 2919 7ffde3fead38-7ffde3fead45 call 7ffde4045f00 2915->2919 2916->2917 2917->2860 2918->2823 2919->2823 2922 7ffde3feacd9-7ffde3feace1 2920->2922 2923 7ffde3feacd3-7ffde3feacd7 2920->2923 2922->2893 2923->2887 2923->2922
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2178175784.00007FFDE3F41000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFDE3F40000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178149093.00007FFDE3F40000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178285367.00007FFDE4088000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178332844.00007FFDE40CF000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178375766.00007FFDE40D2000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3f40000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: memchrmemmove$_errno
                                                                                                                                                                                                                                    • String ID: Reuse of ChannelBuffer! %p$unable to alloc %u bytes$unknown output translation requested
                                                                                                                                                                                                                                    • API String ID: 180474557-3982423822
                                                                                                                                                                                                                                    • Opcode ID: bca1144f8fee208e044102d88011bb48ab4528248855eb72f4fbb7e48ec12929
                                                                                                                                                                                                                                    • Instruction ID: c210373b60967eb28b473e68abeb6ad575a7741d476af7840e72404679735581
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bca1144f8fee208e044102d88011bb48ab4528248855eb72f4fbb7e48ec12929
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C002817270868286EB688F26E5903BEBBA0FF857A4F144135DA4D57B95DF3CE444CB01

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 3038 70a6ffb0-70a7001d call 70a70f40 malloc 3041 70a70023-70a7003f memcpy 3038->3041 3042 70a70bbd 3038->3042 3043 70a70045-70a7005b 3041->3043 3044 70a700e0 3041->3044 3045 70a70bc8-70a70bd6 call 70a96cb8 3042->3045 3047 70a70060-70a7007b 3043->3047 3046 70a700e3-70a70100 3044->3046 3049 70a70081 3047->3049 3050 70a70970-70a70998 call 70a76390 3047->3050 3053 70a70083-70a70086 3049->3053 3054 70a70101-70a70106 3049->3054 3069 70a709a0-70a709b0 call 70a767d0 3050->3069 3056 70a70950-70a70963 call 70a77660 3053->3056 3057 70a7008c 3053->3057 3058 70a70b90-70a70bb8 call 70a76390 3054->3058 3059 70a7010c 3054->3059 3086 70a703d2-70a703d5 3056->3086 3063 70a70092-70a70095 3057->3063 3064 70a70180-70a70183 3057->3064 3058->3042 3065 70a70112-70a70117 3059->3065 3066 70a701e0-70a701e5 3059->3066 3074 70a709b5-70a709e2 call 70a76390 3063->3074 3075 70a7009b 3063->3075 3071 70a70ab0-70a70ad3 call 70a76120 3064->3071 3072 70a70189 3064->3072 3076 70a70b62-70a70b8a call 70a76390 3065->3076 3077 70a7011d 3065->3077 3067 70a70720-70a7073b 3066->3067 3068 70a701eb 3066->3068 3106 70a70745-70a70760 call 70a76ef0 3067->3106 3079 70a702f3-70a702f8 3068->3079 3080 70a701f1-70a701f6 3068->3080 3069->3086 3071->3086 3084 70a702a0-70a702a3 3072->3084 3085 70a7018f-70a70192 3072->3085 3074->3086 3087 70a70383-70a70386 3075->3087 3088 70a700a1-70a700a4 3075->3088 3076->3086 3089 70a70243-70a70248 3077->3089 3090 70a70123-70a70128 3077->3090 3108 70a70890-70a708a3 3079->3108 3109 70a702fe 3079->3109 3095 70a708d0-70a708eb call 70a76640 3080->3095 3096 70a701fc 3080->3096 3102 70a70a42-70a70a65 call 70a76120 3084->3102 3103 70a702a9 3084->3103 3110 70a70830-70a70853 call 70a76120 3085->3110 3111 70a70198 3085->3111 3086->3047 3099 70a703db 3086->3099 3091 70a70690-70a706d2 call 70a77660 call 70a77960 call 70a94120 call 70a75cf0 3087->3091 3092 70a7038c 3087->3092 3088->3069 3093 70a700aa 3088->3093 3100 70a70765-70a70790 call 70a76390 3089->3100 3101 70a7024e 3089->3101 3104 70a707b2-70a707dd call 70a76390 3090->3104 3105 70a7012e 3090->3105 3258 70a706d7-70a706e6 call 70a75ec0 3091->3258 3112 70a70593-70a70596 3092->3112 3113 70a70392-70a70395 3092->3113 3114 70a70520-70a70523 3093->3114 3115 70a700b0-70a700b3 3093->3115 3095->3086 3116 70a704b3-70a704b8 3096->3116 3117 70a70202-70a70207 3096->3117 3099->3044 3100->3086 3120 70a70254-70a70259 3101->3120 3121 70a70470-70a70475 3101->3121 3102->3086 3123 70a70433-70a70436 3103->3123 3124 70a702af-70a702b2 3103->3124 3104->3086 3125 70a70134-70a70139 3105->3125 3126 70a70550-70a70555 3105->3126 3106->3086 3151 70a708b0-70a708cb call 70a766f0 3108->3151 3129 70a70304-70a70309 3109->3129 3130 70a703e0-70a703e5 3109->3130 3110->3086 3132 70a704f0-70a704f3 3111->3132 3133 70a7019e-70a701a1 3111->3133 3112->3045 3150 70a7059c-70a7067f call 70a75b70 call 70a77330 call 70a77a60 * 3 call 70a77490 call 70a78060 call 70a76390 call 70a78060 call 70a76390 call 70a78060 3112->3150 3135 70a70800-70a70821 call 70a76120 3113->3135 3136 70a7039b-70a7039e 3113->3136 3137 70a70b40-70a70b5d call 70a760e0 3114->3137 3138 70a70529-70a7052c 3114->3138 3139 70a70ae0-70a70af4 call 70a7bf10 3115->3139 3140 70a700b9-70a700bc 3115->3140 3116->3151 3163 70a704be-70a704c3 3116->3163 3117->3106 3141 70a7020d-70a70212 3117->3141 3148 70a70920-70a70948 call 70a76390 3120->3148 3149 70a7025f-70a70264 3120->3149 3159 70a708f0-70a7091b call 70a76390 3121->3159 3160 70a7047b-70a70480 3121->3160 3152 70a70a70-70a70aa4 call 70a76390 3123->3152 3153 70a7043c-70a7043f 3123->3153 3155 70a70b00-70a70b34 call 70a76390 3124->3155 3156 70a702b8-70a702bd 3124->3156 3157 70a70a15-70a70a3d call 70a76390 3125->3157 3158 70a7013f-70a70144 3125->3158 3143 70a70860-70a7088b call 70a76390 3126->3143 3144 70a7055b-70a70560 3126->3144 3164 70a706f1-70a70711 3129->3164 3165 70a7030f-70a70314 3129->3165 3146 70a70795-70a707a8 3130->3146 3147 70a703eb-70a703f0 3130->3147 3169 70a707e2-70a707f9 call 70a775c0 3132->3169 3170 70a704f9-70a704fc 3132->3170 3167 70a701a7-70a701aa 3133->3167 3168 70a709f0-70a70a10 call 70a76120 3133->3168 3135->3086 3136->3045 3185 70a703a4-70a703cd call 70a76390 3136->3185 3137->3086 3138->3045 3173 70a70532-70a7054a call 70a7c3e0 3138->3173 3139->3086 3140->3045 3186 70a700c2-70a700dc call 70a7bf10 3140->3186 3141->3045 3175 70a70218-70a7023e call 70a76e80 3141->3175 3143->3086 3144->3045 3176 70a70566-70a7058e call 70a76390 3144->3176 3146->3104 3147->3045 3189 70a703f6-70a70411 3147->3189 3148->3086 3149->3045 3178 70a7026a-70a70295 call 70a76390 3149->3178 3150->3091 3151->3086 3152->3086 3153->3045 3191 70a70445-70a70468 call 70a76120 3153->3191 3155->3086 3156->3045 3181 70a702c3-70a702ee call 70a76390 3156->3181 3157->3086 3158->3045 3193 70a7014a-70a70175 call 70a76390 3158->3193 3159->3086 3160->3045 3195 70a70486-70a704ae call 70a76390 3160->3195 3163->3045 3197 70a704c9-70a704e4 call 70a76630 3163->3197 3194 70a70416-70a70431 call 70a76510 3164->3194 3165->3045 3184 70a7031a-70a70381 call 70a76390 call 70a76510 3165->3184 3167->3045 3199 70a701b0-70a701d3 call 70a76120 3167->3199 3168->3086 3169->3086 3170->3045 3201 70a70502-70a70519 call 70a7b0c0 3170->3201 3173->3086 3175->3086 3176->3086 3178->3086 3181->3086 3184->3086 3185->3086 3186->3047 3249 70a700de 3186->3249 3189->3194 3191->3086 3193->3086 3194->3086 3195->3086 3197->3086 3199->3086 3201->3086 3249->3044 3258->3046 3264 70a706ec 3258->3264 3264->3086
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: mallocmemcpy
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 4276657696-0
                                                                                                                                                                                                                                    • Opcode ID: 791c4f8927b015886fb24a50f2ab30a87ed52ce1407ff1ffaec066b77c2a18e9
                                                                                                                                                                                                                                    • Instruction ID: 3f854b4e0b4bd2c5154bee269f092218abfe356dd434d68adafe375f0becdec5
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 791c4f8927b015886fb24a50f2ab30a87ed52ce1407ff1ffaec066b77c2a18e9
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3E42A131605B58C6EB248B50EC91B6E2724F799B8AF51E236DA4EEB75CCF3CE5048341
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: AddressProc$_errno
                                                                                                                                                                                                                                    • String ID: %s$%s,%d,0x%x,$3des$PyArg_ParseTuple$PyBool_FromLong$PyByteArray_AsString$PyBytes_AsString$PyBytes_AsStringAndSize$PyBytes_FromStringAndSize$PyBytes_Size$PyCFunction_Call$PyCFunction_NewEx$PyCell_Set$PyCode_Type$PyDict_Clear$PyDict_Copy$PyDict_GetItemString$PyDict_SetItem$PyDict_SetItemString$PyErr_Clear$PyErr_Fetch$PyErr_Format$PyErr_NoMemory$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyErr_SetString$PyEval_EvalCode$PyEval_EvalFrameEx$PyEval_GetBuiltins$PyEval_GetFrame$PyEval_GetGlobals$PyEval_GetLocals$PyEval_SetProfile$PyEval_SetTrace$PyExc_ImportError$PyExc_RuntimeError$PyFrame_LocalsToFast$PyFrame_Type$PyFunction_Type$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ExecCodeModuleEx$PyImport_GetMagicNumber$PyImport_GetModuleDict$PyImport_ImportModule$PyList_GetItem$PyList_Size$PyLong_AsLong$PyLong_FromLong$PyMarshal_ReadObjectFromString$PyMarshal_WriteObjectToFile$PyMarshal_WriteObjectToString$PyModule_GetDict$PyObject_GetAttrString$PyObject_Print$PyObject_SetAttrString$PyObject_Size$PyObject_Type$PyString_AsStringAndSize$PyString_Format$PyString_FromStringAndSize$PyString_Size$PyString_Type$PySys_GetObject$PySys_SetObject$PyThreadState_Get$PyTuple_GetItem$PyTuple_GetSlice$PyTuple_New$PyTuple_SetItem$PyTuple_Size$PyType_GenericNew$PyUnicodeUCS2_AsUTF8String$PyUnicodeUCS2_Format$PyUnicodeUCS2_FromString$PyUnicodeUCS4_AsUTF8String$PyUnicodeUCS4_Format$PyUnicodeUCS4_FromString$PyUnicode_AsUTF8String$PyUnicode_Fill$PyUnicode_Format$PyUnicode_FromString$PyUnicode_Type$Py_BuildValue$Py_CompileString$Py_CompileStringExFlags$Py_DebugFlag$Py_DecRef$Py_Exit$Py_IncRef$Py_InspectFlag$Py_InteractiveFlag$Py_ReprEnter$_PyEval_EvalFrameDefault$_Py_NoneStruct$_Py_TrueStruct$_pytransform.c$aes$dumps$license.c$license.lic$loads$marshal$pyshield.lic$pytransform.log$sha256$sprng$wrapper.c
                                                                                                                                                                                                                                    • API String ID: 1566810575-3086871561
                                                                                                                                                                                                                                    • Opcode ID: 3dde89aa4a73aaef531c1cf2d9111f270bae8d1bcb8ac5254fc44e3ed24b5792
                                                                                                                                                                                                                                    • Instruction ID: c6d15e650cbbfc270a07c374445c2311c5310b700580a82d554581e20cfc369d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3dde89aa4a73aaef531c1cf2d9111f270bae8d1bcb8ac5254fc44e3ed24b5792
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2FE38EB0B19712E9EB049B11F91079C23A5FB99BC4F844226D94E5B3A8DF3CF646C316

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2149 70a0da10-70a0da30 call 70a05fd0 2152 70a0da80-70a0da8f 2149->2152 2153 70a0da32-70a0da64 call 70a0a7b0 2149->2153 2155 70a0daa0-70a0dab9 call 70a04230 2152->2155 2156 70a0da91-70a0da9b _errno 2152->2156 2157 70a0da69-70a0da6f free 2153->2157 2161 70a0db4c-70a0db7e fprintf 2155->2161 2162 70a0dabf-70a0dac5 _errno 2155->2162 2158 70a0da74-70a0da7e 2156->2158 2157->2158 2165 70a0db1a-70a0db47 fprintf fputc 2161->2165 2163 70a0db80-70a0db9b _errno strerror fprintf 2162->2163 2164 70a0dacb-70a0db13 fprintf * 2 fputc fclose 2162->2164 2163->2164 2164->2165 2165->2156
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                      • Part of subcall function 70A05FD0: getenv.MSVCRT ref: 70A06066
                                                                                                                                                                                                                                    • _errno.MSVCRT ref: 70A0DA91
                                                                                                                                                                                                                                      • Part of subcall function 70A0A7B0: strncmp.MSVCRT ref: 70A0A891
                                                                                                                                                                                                                                      • Part of subcall function 70A0A7B0: strchr.MSVCRT ref: 70A0A8A2
                                                                                                                                                                                                                                    • free.MSVCRT ref: 70A0DA6F
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: _errnofreegetenvstrchrstrncmp
                                                                                                                                                                                                                                    • String ID: %s$%s,%d,0x%x,$license.c$license.lic$product.key$pytransform.log
                                                                                                                                                                                                                                    • API String ID: 2166687660-2554675036
                                                                                                                                                                                                                                    • Opcode ID: 9df7311c4f2525eca8cc3b923d3e1b07d461d20a02d716fe0d9040fd3ecf05e5
                                                                                                                                                                                                                                    • Instruction ID: f6921e39fbe2ea8bfa082a9b4ee5395fcf71dbb820493b4c50599c7430b0b608
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9df7311c4f2525eca8cc3b923d3e1b07d461d20a02d716fe0d9040fd3ecf05e5
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1B31E671B2831699EF019B61F90179D63A1AB89BC4F844226ED4D1B76CEF3CF906C306

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2265 70a04a00-70a04a19 call 70a6ffb0 2268 70a04a25-70a04a62 2265->2268 2269 70a04a1b-70a04a23 2265->2269 2269->2268 2270 70a04a63-70a04a7c call 70a04230 2269->2270 2273 70a04b20-70a04b52 fprintf 2270->2273 2274 70a04a82-70a04a90 _errno 2270->2274 2279 70a04ae8-70a04b18 fprintf fputc 2273->2279 2275 70a04b54-70a04b70 _errno strerror fprintf 2274->2275 2276 70a04a96-70a04ae1 call 70a96ca0 fprintf fputc fclose 2274->2276 2275->2276 2276->2279 2279->2268
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: fprintf$fputc$_errnofclosemallocmemcpy
                                                                                                                                                                                                                                    • String ID: %s$%s,%d,0x%x,$protect.c$pytransform.log$!
                                                                                                                                                                                                                                    • API String ID: 1944142573-152705595
                                                                                                                                                                                                                                    • Opcode ID: f4f11d98654f22f3108b67875ee014831f8f5b40bde045c54f5d2bc865fddc6d
                                                                                                                                                                                                                                    • Instruction ID: ce169459db75e4695f2d7c2963c1d399baeddfc44ec2600ce0a200b673199cc4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f4f11d98654f22f3108b67875ee014831f8f5b40bde045c54f5d2bc865fddc6d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E331B4517182819EEB159B36B950BAD6B70EF86BC8F484165DECD0736AEE2CF403C319

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2283 70a94ed0-70a94ee8 2284 70a94eea-70a94efc 2283->2284 2285 70a94f22-70a94f25 2283->2285 2286 70a95010-70a95012 2284->2286 2287 70a94f02-70a94f04 2284->2287 2288 70a94f27-70a94f39 _errno 2285->2288 2291 70a95044-70a9504f 2286->2291 2292 70a95014-70a95025 2286->2292 2293 70a94f0a-70a94f12 2287->2293 2294 70a95030-70a95032 2287->2294 2289 70a94f3f-70a94f43 2288->2289 2290 70a94ff0-70a94ff9 _errno 2288->2290 2289->2290 2295 70a94f49-70a94f4c 2289->2295 2296 70a94fff-70a9500e 2290->2296 2291->2288 2292->2288 2299 70a94f1d-70a94f20 2293->2299 2300 70a94f14-70a94f1b 2293->2300 2297 70a95088-70a9508d 2294->2297 2298 70a95034-70a9503a 2294->2298 2295->2290 2301 70a94f52-70a94f5d 2295->2301 2298->2291 2299->2288 2300->2288 2300->2299 2302 70a94f63-70a94f91 CreateFileMappingA 2301->2302 2303 70a95054-70a95068 _get_osfhandle 2301->2303 2304 70a94fc8-70a94fea GetLastError _errno 2302->2304 2305 70a94f93-70a94fc6 MapViewOfFile CloseHandle 2302->2305 2303->2302 2306 70a9506e-70a95083 _errno 2303->2306 2305->2296 2305->2304 2306->2296
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: File_errno$CloseCreateErrorHandleLastMappingView
                                                                                                                                                                                                                                    • String ID: $@$@
                                                                                                                                                                                                                                    • API String ID: 896588047-3743272326
                                                                                                                                                                                                                                    • Opcode ID: ad2b5d174cbbaebff85b719ff44f08ee0dbd8e41e6a4b1a3aa829fbda9743842
                                                                                                                                                                                                                                    • Instruction ID: cee35e83c8d40c509c7011d4e926b2c1f3f4ee977901ab9e023c1a7fa3cdb22f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ad2b5d174cbbaebff85b719ff44f08ee0dbd8e41e6a4b1a3aa829fbda9743842
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2B413473F206608AEB224B16AC00B4D62A5B74DFB5F490326DE7A077D8EB7CD9408344
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: free$strlenstrncmp
                                                                                                                                                                                                                                    • String ID: __main__$__mp_main__$__parents_main__$__spec__$frame$obfmode.c
                                                                                                                                                                                                                                    • API String ID: 2569063720-2363144754
                                                                                                                                                                                                                                    • Opcode ID: ba3fd494e25e941505ccad518361abba6191941cd45df3dbf69a81b8137e310f
                                                                                                                                                                                                                                    • Instruction ID: 57daabeed09556e80a5bddd4dce35138cf8524be36cbd361d1afad0cbb098257
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ba3fd494e25e941505ccad518361abba6191941cd45df3dbf69a81b8137e310f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D432ED72A09608D6EB15CB21FA4036D2766B749B88F404629CD0F4B7ACFB7CE985D701

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2925 7ffde4053220-7ffde4053258 2926 7ffde405325e-7ffde4053262 call 7ffde3fbb2b0 2925->2926 2927 7ffde4053390-7ffde40533ab call 7ffde4052f30 2925->2927 2926->2927 2932 7ffde40533ad-7ffde40533c5 call 7ffde4052e90 call 7ffde4084dc0 2927->2932 2933 7ffde4053425-7ffde4053455 call 7ffde4086240 2927->2933 2940 7ffde40533f9-7ffde4053423 call 7ffde403bbf0 LeaveCriticalSection 2932->2940 2941 7ffde40533c7-7ffde40533ce 2932->2941 2940->2933 2941->2940 2942 7ffde40533d0-7ffde40533da 2941->2942 2945 7ffde40533e0-7ffde40533e4 2942->2945 2946 7ffde4053465-7ffde405348d call 7ffde4084dc0 call 7ffde4027370 2945->2946 2947 7ffde40533e6-7ffde40533f5 call 7ffde3fc69b0 2945->2947 2956 7ffde4053100-7ffde4053110 call 7ffde4045db0 2946->2956 2957 7ffde40530f9-7ffde40530fe call 7ffde4045f00 2946->2957 2947->2940 2962 7ffde405314f-7ffde4053162 2956->2962 2963 7ffde40531ff-7ffde4053210 call 7ffde4027370 2956->2963 2957->2962 2965 7ffde4053164-7ffde4053167 call 7ffde4023710 2962->2965 2966 7ffde405316c-7ffde405316f 2962->2966 2972 7ffde4053211-7ffde405321f call 7ffde4027370 2963->2972 2965->2966 2969 7ffde4053171-7ffde4053176 2966->2969 2970 7ffde4053178 2966->2970 2971 7ffde405317a-7ffde405318d call 7ffde4045db0 2969->2971 2970->2971 2977 7ffde4053193-7ffde40531ac memmove 2971->2977 2978 7ffde405318f-7ffde4053191 2971->2978 2972->2925 2979 7ffde40531b3-7ffde40531fe call 7ffde4052f30 call 7ffde4052e90 LeaveCriticalSection 2977->2979 2980 7ffde40531ae call 7ffde3fbb4e0 2977->2980 2978->2972 2978->2977 2980->2979
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2178175784.00007FFDE3F41000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFDE3F40000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178149093.00007FFDE3F40000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178285367.00007FFDE4088000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178332844.00007FFDE40CF000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178375766.00007FFDE40D2000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3f40000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CriticalLeaveSection
                                                                                                                                                                                                                                    • String ID: PGV Initializer did not initialize$unable to alloc %u bytes
                                                                                                                                                                                                                                    • API String ID: 3988221542-3767161943
                                                                                                                                                                                                                                    • Opcode ID: 53a711cb3d5ea6677524e04719658d44e7e132f5e0f1484c67e5ae552b1030ac
                                                                                                                                                                                                                                    • Instruction ID: 4ea1fdb1af29ed87266c5d310eba18c303400d62c251a666c3b8d1c5d1e0dc8d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 53a711cb3d5ea6677524e04719658d44e7e132f5e0f1484c67e5ae552b1030ac
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17614B2AB09A4296EA29EB62E5A03B97360FF85B80F444435DF1D07B96DF3CE4619341

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2987 7ffde4072b10-7ffde4072b37 GetFileType 2988 7ffde4072b39-7ffde4072b3b 2987->2988 2989 7ffde4072b47-7ffde4072b57 GetConsoleMode 2987->2989 2990 7ffde4072b82-7ffde4072b99 call 7ffde4086240 2988->2990 2991 7ffde4072b3d-7ffde4072b45 GetLastError 2988->2991 2992 7ffde4072b60-7ffde4072b7d GetCommState 2989->2992 2993 7ffde4072b59-7ffde4072b5e 2989->2993 2991->2989 2994 7ffde4072b80 2991->2994 2992->2994 2993->2990 2994->2990
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2178175784.00007FFDE3F41000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFDE3F40000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178149093.00007FFDE3F40000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178285367.00007FFDE4088000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178332844.00007FFDE40CF000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178375766.00007FFDE40D2000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3f40000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CommConsoleErrorFileLastModeStateType
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3984557487-0
                                                                                                                                                                                                                                    • Opcode ID: 05380490b17c4b79fbd573c98fbb523210e80e337488ba6d70ab4851e6a93b12
                                                                                                                                                                                                                                    • Instruction ID: 1a965710196cf2031cb942a5efd8b574ba70088c68fa77bc45e5c9f0f28b34e6
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 05380490b17c4b79fbd573c98fbb523210e80e337488ba6d70ab4851e6a93b12
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9B017525B0C74382F7A89F15A9E433A62E5EF4ABD0F544438DA4D82654DF6CD444AA12

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 2997 70a70de0-70a70e1c GetCurrentThread GetThreadContext 2998 70a70e41 2997->2998 2999 70a70e1e-70a70e24 2997->2999 3001 70a70e49-70a70e89 GetCurrentThread SetThreadContext 2998->3001 3000 70a70e26-70a70e2c 2999->3000 2999->3001 3000->3001 3002 70a70e2e-70a70e34 3000->3002 3002->3001 3003 70a70e36-70a70e3f 3002->3003 3003->2998 3003->3001
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Thread$ContextCurrent
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 195563550-0
                                                                                                                                                                                                                                    • Opcode ID: 99d3b8c55569807b5a3df5e2c7eff14ca15bcf6d4e21b9a73be53227edca2030
                                                                                                                                                                                                                                    • Instruction ID: 1eddd6dec481bea909cc2e88b09db8f3e19057b72cd79a9069f816696097565b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 99d3b8c55569807b5a3df5e2c7eff14ca15bcf6d4e21b9a73be53227edca2030
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B3112532508744C9EB518B25F918B1EB3E2F788794F509629F6C99669CCFBCC189CB00

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2178175784.00007FFDE3F41000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFDE3F40000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178149093.00007FFDE3F40000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178285367.00007FFDE4088000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178332844.00007FFDE40CF000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178375766.00007FFDE40D2000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3f40000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: wsprintf
                                                                                                                                                                                                                                    • String ID: cp%d
                                                                                                                                                                                                                                    • API String ID: 2111968516-4262107655
                                                                                                                                                                                                                                    • Opcode ID: 6cc3930b147f8eff0c61a20dc728995a34f828be1bcd2cf6517a72a999ef8715
                                                                                                                                                                                                                                    • Instruction ID: 46921972654297573112cbb8c184beb9a57d99f565c5f91f5a21c087f4497c3c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6cc3930b147f8eff0c61a20dc728995a34f828be1bcd2cf6517a72a999ef8715
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8D118236B1CA8685EB749B20E0A53AA77A0FB8A768F405335E6DD077D5CF3CD1048B02

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 3016 70a70c90-70a70ccc 3019 70a70cf2-70a70cfb 3016->3019 3020 70a70cce-70a70cf0 RtlWow64SetThreadContext 3016->3020 3020->3019
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • RtlWow64SetThreadContext.NTDLL ref: 70A70CF0
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ContextThreadWow64
                                                                                                                                                                                                                                    • String ID: NtSetInformationThread$ntdll.dll
                                                                                                                                                                                                                                    • API String ID: 983334009-3743287242
                                                                                                                                                                                                                                    • Opcode ID: 92c065ca89abec1997848133b4d1076c9b5e49955e8ffd3d9a29227274912c27
                                                                                                                                                                                                                                    • Instruction ID: 2fc8b2a801552d3e1343ac4fbba029e5866327fdd9809e1ff4e8e36d5b005223
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 92c065ca89abec1997848133b4d1076c9b5e49955e8ffd3d9a29227274912c27
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E8F01535B18A48C9EB609B16FCA074A6360F39CB88F544225DA9D87774EF6CD709CB00

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2178175784.00007FFDE3F41000.00000020.00000001.01000000.00000031.sdmp, Offset: 00007FFDE3F40000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178149093.00007FFDE3F40000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178285367.00007FFDE4088000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178332844.00007FFDE40CF000.00000004.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178375766.00007FFDE40D2000.00000002.00000001.01000000.00000031.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3f40000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CriticalLeaveSection
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3988221542-0
                                                                                                                                                                                                                                    • Opcode ID: 989d881189fd1461a8ee1ecdafb325d6020b977e6c84d3a5c675026cea46c341
                                                                                                                                                                                                                                    • Instruction ID: 4fbef1dc4e282059d0baeb06917dc46acd79b6154e0cfa4374197c00d7643541
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 989d881189fd1461a8ee1ecdafb325d6020b977e6c84d3a5c675026cea46c341
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C611C5A9F09A07C1EA4D9F91EAF53B42360AF4A714F040031C90E472E2EE6CA485A343

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 3276 70a96550-70a96558 3277 70a9655a-70a9655e 3276->3277 3278 70a965a3-70a965a9 3276->3278 3280 70a96580 3277->3280 3281 70a96560-70a96564 3277->3281 3279 70a96586-70a9659c VirtualProtect 3278->3279 3282 70a9659e-70a965a2 3279->3282 3280->3279 3283 70a965b0-70a965b6 3281->3283 3284 70a96566-70a9656a 3281->3284 3283->3279 3285 70a9656c-70a96570 3284->3285 3286 70a965d0-70a965d6 3284->3286 3287 70a965c0-70a965c6 3285->3287 3288 70a96572-70a96575 3285->3288 3286->3279 3287->3279 3289 70a965d8-70a965dd 3288->3289 3290 70a96577-70a9657d 3288->3290 3289->3282 3290->3279
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ProtectVirtual
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 544645111-0
                                                                                                                                                                                                                                    • Opcode ID: 55520103505fb2b0f5347ec77b52210e5f6cab78dcb607584f853220d99b3cc2
                                                                                                                                                                                                                                    • Instruction ID: 718997596fe409d23c43e28f549ccab20ff1ae5dcb4ef59b1ee5d8ebc4f539c1
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 55520103505fb2b0f5347ec77b52210e5f6cab78dcb607584f853220d99b3cc2
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D9F01CB033603086EB330522C700F6C26E85F06790E7A410A99164EEECE55FC685AF4E

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 3291 70a70be0-70a70bec 3292 70a70c10-70a70c21 call 70a77300 3291->3292 3293 70a70bee-70a70bf5 call 70a70db9 3291->3293 3292->3293 3298 70a70bf7-70a70bfe call 70a70dc7 3293->3298 3299 70a70c23-70a70c3c exit 3293->3299 3298->3299 3306 70a70c00 call 70a70de0 3298->3306 3300 70a70c3e-70a70c43 call 70a75710 3299->3300 3301 70a70c4d-70a70c51 3299->3301 3300->3301 3308 70a70c05-70a70c07 3306->3308 3308->3299 3309 70a70c09-70a70c0d 3308->3309
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: feaaaa0cf51caa3f99b8a002e9c14e1708ff5625ace8c5f16572cee7fcd3e753
                                                                                                                                                                                                                                    • Instruction ID: cbaeaf6c6e5f43d82b82c2969cc58d8f7f5016185a0d7430ba8a2f7ee5861c2d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: feaaaa0cf51caa3f99b8a002e9c14e1708ff5625ace8c5f16572cee7fcd3e753
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C3F0EC60F06201CEF7156B726E42B1D11A16FAC344F90F538E409C129CE72CF584CB51

                                                                                                                                                                                                                                    Control-flow Graph

                                                                                                                                                                                                                                    • Executed
                                                                                                                                                                                                                                    • Not Executed
                                                                                                                                                                                                                                    control_flow_graph 3310 70a94120-70a94136 3311 70a9413c-70a94142 3310->3311 3312 70a94384-70a9438d call 70a7ac80 3310->3312 3314 70a94148-70a94154 3311->3314 3315 70a942f0-70a942f3 3311->3315 3328 70a94397-70a943a3 call 70a949c0 3312->3328 3319 70a942b9-70a942db call 70a94ed0 3314->3319 3320 70a9415a-70a94188 call 70a94eb0 call 70a82d40 3314->3320 3317 70a942f9-70a94300 3315->3317 3318 70a943fb-70a94437 call 70a94ed0 3315->3318 3323 70a94451-70a9446d call 70a70ec0 3317->3323 3324 70a94306-70a94308 3317->3324 3327 70a9443c-70a9444b 3318->3327 3326 70a942e0-70a942e7 3319->3326 3346 70a9418e 3320->3346 3347 70a94245-70a94251 3320->3347 3331 70a9430e-70a94328 3323->3331 3341 70a94473-70a94480 3323->3341 3330 70a943ae-70a943b2 3324->3330 3324->3331 3326->3315 3327->3323 3327->3324 3349 70a943a9 3328->3349 3350 70a9425d-70a9426b call 70a96550 3328->3350 3338 70a943b9-70a943d2 memset 3330->3338 3335 70a943d8-70a943ed call 70a70fe0 3331->3335 3336 70a9432e-70a94333 3331->3336 3345 70a9433d-70a94344 3335->3345 3342 70a94339 3336->3342 3343 70a943f2-70a943f6 3336->3343 3338->3335 3338->3336 3341->3338 3348 70a94486-70a94491 3341->3348 3342->3345 3343->3345 3355 70a9437a 3345->3355 3356 70a94346-70a9434e 3345->3356 3352 70a94190-70a94194 3346->3352 3347->3328 3353 70a94257-70a9425b 3347->3353 3348->3338 3349->3330 3359 70a94270-70a94278 3350->3359 3358 70a9419f-70a941a5 3352->3358 3353->3350 3357 70a94283-70a94298 call 70a70fe0 3353->3357 3355->3312 3360 70a94350-70a94356 3356->3360 3363 70a9429a-70a942a7 call 70a96550 3357->3363 3364 70a9427a-70a94282 3357->3364 3361 70a941ce-70a941d2 3358->3361 3362 70a941a7-70a941ac 3358->3362 3359->3363 3359->3364 3366 70a94358 3360->3366 3367 70a94371-70a94378 3360->3367 3361->3364 3370 70a941d8-70a9423f call 70a950a0 call 70a94ed0 call 70a94eb0 call 70a82d40 3361->3370 3362->3358 3368 70a941ae-70a941b6 3362->3368 3376 70a942ac-70a942b8 3363->3376 3372 70a94360-70a9436f 3366->3372 3367->3355 3367->3360 3373 70a941b8-70a941bf 3368->3373 3374 70a941c1-70a941cc 3368->3374 3370->3347 3370->3352 3372->3367 3372->3372 3373->3358 3373->3374 3374->3361 3374->3362
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: memset
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2221118986-0
                                                                                                                                                                                                                                    • Opcode ID: ad683bb627b7ab02320f166490d90dff12a04f907f4fe6b01c8a673c6386ec2c
                                                                                                                                                                                                                                    • Instruction ID: 8064f0211f80f956083993993018be11ab48410aace7100781154c00130ccf7b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ad683bb627b7ab02320f166490d90dff12a04f907f4fe6b01c8a673c6386ec2c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2F9178B2720B9486DB558F26D04175D3BE5F709FD8F18421AEE8A1B39CDBB8C895C384
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2162346279.0000000070A01000.00000020.00000001.01000000.00000018.sdmp, Offset: 70A00000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162284597.0000000070A00000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162494578.0000000070A98000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162594952.0000000070A99000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162658879.0000000070AF9000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162696174.0000000070B22000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162725746.0000000070B28000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162752799.0000000070B2A000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162781202.0000000070B2B000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162807748.0000000070B2C000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2162835627.0000000070B2F000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_70a00000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: free
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1294909896-0
                                                                                                                                                                                                                                    • Opcode ID: 9287e08c20975ed3c19586d29dd955b81908fc052125fea48543a92b48a8a35e
                                                                                                                                                                                                                                    • Instruction ID: 37ad8e1b3b36a6959367083b20d05beb5750edcd6c0f735069558d2b0438d4bb
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9287e08c20975ed3c19586d29dd955b81908fc052125fea48543a92b48a8a35e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 43C08CA6A13A00C1FF198BB2FC503383220AF5CF05F189010CE0A463408F2C90D18701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptError@@Keywords_ParamParseProvSizeTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: Algid$BitLen$CryptGetProvParam$CryptGetProvParam: Unable to allocate %d bytes$DefaultLen$LongName$MaxLen$MinLen$Name$Protocols$The provider parameter specified is not yet implemented$k|k:CryptGetProvParam${s:I,s:k,s:N}${s:I,s:k,s:k,s:k,s:k,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 3402344487-1526417634
                                                                                                                                                                                                                                    • Opcode ID: 6267abaa02f1d94d2409549f8476684ec275b796bb5215c0c13f452635fb20ba
                                                                                                                                                                                                                                    • Instruction ID: 2bfa4e106da20e3ffb1a8a740ddb420bc564fb730881b54091e162935088ee67
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6267abaa02f1d94d2409549f8476684ec275b796bb5215c0c13f452635fb20ba
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 42023D32B086528AEB58DF66D8642BD3BB1BB48B88F540535C91E63B54DF3CE5C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_ReferenceThreadfree$CertErr_$BufferBuildCertificateContextCryptDecodeError@@FreeMessageOccurredRestoreSaveU_object@@ValueView@@Win_$Arg_Bytes_CloseFromKeywordsMemoryParseSizeStoreStringTupleU_object@@_malloc
                                                                                                                                                                                                                                    • String ID: CryptDecodeMessage$Decoded$InnerContentType$MsgType$OO|Okkkl:CryptDecodeMessage$SignerCert$XchgCert${s:k,s:k,s:N,s:N,s:N}${s:k,s:k,s:O,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 4057531286-845939780
                                                                                                                                                                                                                                    • Opcode ID: 9157666944c121653f514387b71ee9244ad0032af4e459923fd982fad19c2ce6
                                                                                                                                                                                                                                    • Instruction ID: 0d05b02cec73dd9f93d4e60f70fd9db81063b9ae240e1f72d10c35cf0f103362
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9157666944c121653f514387b71ee9244ad0032af4e459923fd982fad19c2ce6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C5F1F936B09B518AE7198F62E8606BD7BB4FB48B88F544135DA4D23B68DF38D4D4C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$CertCertificateContextErr_U_object@@free$BufferCryptDeallocEncryptError@@FreeMessageRestoreSaveView@@Win_malloc$Arg_DuplicateFormatKeywordsMemoryParseSequence_StringTupleTuple@@U_object@@_memset
                                                                                                                                                                                                                                    • String ID: CryptEncryptMessage$CryptEncryptMessage: Unable to allocate %d bytes$OOO:CryptEncryptMessage$Object must be of type PyCERT_CONTEXT$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 512897165-3430610400
                                                                                                                                                                                                                                    • Opcode ID: 67f3a9b05425bcc41229ce62f8b06ac9d7de5362ede0b42f41372bb880e94c07
                                                                                                                                                                                                                                    • Instruction ID: 4ebf9651dfa561dda8dd59751cb5f68fdfcdaccf261a1c0209687e16a8e8917f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 67f3a9b05425bcc41229ce62f8b06ac9d7de5362ede0b42f41372bb880e94c07
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E4A11B36B09A5286EB18DB66E86037D3BA1BB54B88F944135DD0E63B64DF3CE4C5C342
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$Format$strcmp$Eval_StringThread$Arg_Bytes_ClearCryptEncodeError@@FreeKeywordsLocalLong_ObjectOccurredParseRestoreSaveTupleU_object@@VoidWin_freemalloc
                                                                                                                                                                                                                                    • String ID: %d is an invalid value for object identifier$2.5.29.15$2.5.29.37$CryptDecodeObjectEx$CryptEncodeObjectEx: Type %d is not yet supported$CryptEncodeObjectEx: Type %s is not yet supported$EncodePara not yet supported$OO|kkO:CryptEncodeObjectEx$Unable to allocate %d bytes
                                                                                                                                                                                                                                    • API String ID: 3441675147-238870163
                                                                                                                                                                                                                                    • Opcode ID: c1014171c298bf42eb41c20ac8ff737804800ecaa33a9b9258f9b1b86b9a3fbe
                                                                                                                                                                                                                                    • Instruction ID: 94719e83dc4228a7990c84001f483d75261254673df43ed1f86a3c44c36239e1
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c1014171c298bf42eb41c20ac8ff737804800ecaa33a9b9258f9b1b86b9a3fbe
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 48813625B09B5281EB689B56E4643BD3BE4BF84B98F840035C95E27B64DF3DE8C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferErr_Eval_ThreadView@@$Arg_BuildCryptError@@FlagsKeywordsMessageOccurredParseRestoreSaveSignatureStringTupleType_U_object@@U_object@@_ValueVerifyWin_free
                                                                                                                                                                                                                                    • String ID: CryptVerifyMessageSignature$Decoded$O|kOl:CryptVerifyMessageSignature$SignerCert${s:N, s:N}${s:N, s:O}
                                                                                                                                                                                                                                    • API String ID: 918566226-3278881437
                                                                                                                                                                                                                                    • Opcode ID: c2f0d78e1757242ad282eb1f8cff2525b4e86774d66296c51135acbff7269860
                                                                                                                                                                                                                                    • Instruction ID: da731af773a10fb61b68d85df2f685a9d6a3a4e0a948e7c6dc9ed2132d12488b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c2f0d78e1757242ad282eb1f8cff2525b4e86774d66296c51135acbff7269860
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 02910B36B09B5285EB19CB62E8602BD37A5FB54B88B840136D94E27768DF3CD5C5C342
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$BufferEval_FlagsStringThreadType_View@@free$Arg_CertCloseCryptDecryptError@@KeywordsMemoryMessageParseRestoreSaveSignatureStoreTupleU_object@@U_object@@_VerifyWin_malloc
                                                                                                                                                                                                                                    • String ID: CryptDecryptAndVerifyMessageSignature$Decrypted$OO|Ok:CryptDecryptAndVerifyMessageSignature$SignerCert$XchgCert${s:N,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 3855022886-2987117642
                                                                                                                                                                                                                                    • Opcode ID: f885780618d464cec61db074f57030dc7bec2b85162e722de506932092745e64
                                                                                                                                                                                                                                    • Instruction ID: 3e676e934c556d3f85dbf854e8de3ac51ef0f4a73cf2198dc49027adf82691a2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f885780618d464cec61db074f57030dc7bec2b85162e722de506932092745e64
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 70A12D36B19B5285EB198B62E8506BD7BA4FB88B88F440135DE4D23B68DF3CE5C5C701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$Eval_FormatThread$U_object@@$BufferCryptError@@ObjectRestoreSaveStringView@@Win_$Arg_Bytes_ClearFromKeywordsLong_Object_OccurredParseTupleU_object@@_Voidfreemalloc
                                                                                                                                                                                                                                    • String ID: %d is an invalid value for object identifier$CryptFormatObject$FormatStruct must be None$OO|kkkO:CryptFormatObject$Unable to allocate %d bytes
                                                                                                                                                                                                                                    • API String ID: 1738280576-2598896384
                                                                                                                                                                                                                                    • Opcode ID: 5e35baecdc52afd76c2c03ff356322bd3f764a94df8c99f51cab2398eae13252
                                                                                                                                                                                                                                    • Instruction ID: bf5fc9ac792d2a996da36d815486a424812f41e36f131218b57512cb7442f163
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5e35baecdc52afd76c2c03ff356322bd3f764a94df8c99f51cab2398eae13252
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9871FA36B19A5186E718CF62E4606BD3BA4FB88B88B440135DE4E63B18DF3CD5C58742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$CryptEnumProviderRestoreSaveTypes$DeallocList_$AppendBuildErr_ErrorError@@LastOccurredU_object@@ValueWin_freemalloc
                                                                                                                                                                                                                                    • String ID: CryptEnumProviderTypes$Unable to allocate %d bytes
                                                                                                                                                                                                                                    • API String ID: 83091446-1627254570
                                                                                                                                                                                                                                    • Opcode ID: 21573f520a4abed6796243fe5935432de7662c3d440d3e4782a5743fd75688b2
                                                                                                                                                                                                                                    • Instruction ID: a96b074f172e9e8b67524a363044b2534524831577fae1deca5b679ef3b8cdba
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 21573f520a4abed6796243fe5935432de7662c3d440d3e4782a5743fd75688b2
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CD515062B08B5286EB189B26E86423D7BA4FF89B95F440135D94E17768DF3CE4C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$CryptEnumProvidersRestoreSave$DeallocList_$AppendBuildErr_ErrorError@@LastOccurredU_object@@ValueWin_freemalloc
                                                                                                                                                                                                                                    • String ID: CryptEnumProviders$CryptEnumProviders: Unable to allocate %d bytes
                                                                                                                                                                                                                                    • API String ID: 397729511-1471041950
                                                                                                                                                                                                                                    • Opcode ID: 727b0f9d6dd478683a190241e5b71b81e41f6ea5ce0c5b8787f084afeed3fadf
                                                                                                                                                                                                                                    • Instruction ID: 1b5ee41f1fe2533e3fa500e6275812aae652718ad112f8211b50fe13c6c8d2cf
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 727b0f9d6dd478683a190241e5b71b81e41f6ea5ce0c5b8787f084afeed3fadf
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6A513F62B18B5286EB589F26E86423D7BA4FB88B95F440035DA4E17B64DF3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferEval_ThreadU_object@@View@@$?init@Arg_CryptErr_Error@@FormatFreeKeywordsMem_ObjectObject_ParseQueryRestoreSaveTupleU_object@@_Win_
                                                                                                                                                                                                                                    • String ID: CertStore$ContentType$Context$CryptQueryObject$FormatType$Invalid input type specified: %d$Msg$MsgAndCertEncodingType$kO|kkk:CryptQueryObject${s:k,s:k,s:k,s:N,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 3250035249-912245876
                                                                                                                                                                                                                                    • Opcode ID: 5387bc99549a9355cd89040bddfd13074a01f1e2ac43410f03bd1ef703af309a
                                                                                                                                                                                                                                    • Instruction ID: 1829059e336829936aa265bc1568791605d576c6f8787aa28d72d8783f29d200
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5387bc99549a9355cd89040bddfd13074a01f1e2ac43410f03bd1ef703af309a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 30913A36B08B51CAE7148B66E8A06BD3BB4FB48B84B500136DE4E63B68DF3CD494C741
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: free$BufferCertCertificateContextEval_FreeThreadView@@$Arg_CryptEncryptError@@KeywordsMessageParseRestoreSaveSignTupleU_object@@U_object@@_Win_
                                                                                                                                                                                                                                    • String ID: CryptSignAndEncryptMessage$CryptSignAndEncryptMessage: Unable to allocate %d bytes$OOOO:CryptSignAndEncryptMessage
                                                                                                                                                                                                                                    • API String ID: 1590729463-3614423056
                                                                                                                                                                                                                                    • Opcode ID: a9c27ae64c1608208b6925a76211004407ed5e69e0bf60b53493f4f00da1e312
                                                                                                                                                                                                                                    • Instruction ID: d8de5083bd999a6bade80dbc6bc3ce0382b324fc7f836f176832981b5763ea86
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a9c27ae64c1608208b6925a76211004407ed5e69e0bf60b53493f4f00da1e312
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B6915D22B18B9286E754CB22E8606BD67A0FB98788F405135EE4E63A58DF3CD5C58701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferErr_Eval_ThreadView@@$Arg_CertCloseCryptDecryptError@@FlagsKeywordsMemoryMessageParseRestoreSaveStoreStringTupleType_U_object@@U_object@@_Win_freemalloc
                                                                                                                                                                                                                                    • String ID: CryptDecryptMessage$OO:CryptDecryptMessage
                                                                                                                                                                                                                                    • API String ID: 2753498332-3813015564
                                                                                                                                                                                                                                    • Opcode ID: ec827aa4d4dd21814b8cfb94b777d4c91fcb890a91aa4cfd335377ea4745c911
                                                                                                                                                                                                                                    • Instruction ID: 8f60d2ccaf25681b9dd50c2f90ea6690a6b7c4964c560f2672d6f66c8b97d60b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ec827aa4d4dd21814b8cfb94b777d4c91fcb890a91aa4cfd335377ea4745c911
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 37716B26B19A5285EB188F66E8A07BD27B0FB58B88F844135CD0E23B58DE3CD5C58302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Free$Object_$Eval_FromLocalStringThreadU_object@@U_object@@_$Arg_BuildBytes_CryptDataErr_Error@@KeywordsParseRestoreSaveSizeTupleUnprotectValueWin_
                                                                                                                                                                                                                                    • String ID: CryptUnprotectData$O|OOOk:CryptUnprotectData$Reserved must be None
                                                                                                                                                                                                                                    • API String ID: 674621842-630361847
                                                                                                                                                                                                                                    • Opcode ID: 2f25762cd871b59b627596449d321ab0195adcff0c447f6b3ff86fd23bb2a881
                                                                                                                                                                                                                                    • Instruction ID: 0b57430901847fad98a771b99fba17d72ef4f08af8f60c55c3320ff308a22145
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2f25762cd871b59b627596449d321ab0195adcff0c447f6b3ff86fd23bb2a881
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5C711A36B08B5286EB148F66E4A02BD7BA5FB88798F540135DA4D63B68DF3CD4C5C701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: free$Err_$Eval_FormatThreadU_object@@malloc$Arg_CertCertificateContextCryptDeallocError@@FlagsFreeKeywordsMessageParseRestoreSaveSequence_SignStringTupleTuple@@Type_Win_
                                                                                                                                                                                                                                    • String ID: CryptSignMessage$CryptSignMessage: Unable to allocate %d bytes$OO|l:CryptSignMessage
                                                                                                                                                                                                                                    • API String ID: 1993965035-3191103349
                                                                                                                                                                                                                                    • Opcode ID: 9320b3e8ee71e195ffb98a034228cea888e2b09381ba1752edb616a40f61a784
                                                                                                                                                                                                                                    • Instruction ID: 0779ce2062c52c644d849b2672d027dd8470b3fff3f6ce9561b6c0a15109ff22
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9320b3e8ee71e195ffb98a034228cea888e2b09381ba1752edb616a40f61a784
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 65815E36B09A4286EB188F62E8603BD37A4FB98B88F544235DD4E63B58DF38D5C5C741
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Free$Eval_Object_StringThreadU_object@@U_object@@_$Arg_Bytes_CryptDataErr_Error@@FromKeywordsLocalMem_ParseProtectRestoreSaveSizeTupleWin_
                                                                                                                                                                                                                                    • String ID: CryptProtectData$O|OOOOk:CryptProtectData$Reserved must be None
                                                                                                                                                                                                                                    • API String ID: 4097555971-1080424852
                                                                                                                                                                                                                                    • Opcode ID: 62aabd60715454ddcff602e89fc21732e884831a66bf8f5e9ef21d219b20639e
                                                                                                                                                                                                                                    • Instruction ID: 159f708260474e35de2a052a779a0a2c74fd8425f7496265821df03bfa43c7d8
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 62aabd60715454ddcff602e89fc21732e884831a66bf8f5e9ef21d219b20639e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2D711932B08B5286EB148B62E8606BD7BB5FB88788F500135DA4D63B68DF3CD5C5C741
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$StringU_object@@$BinaryCryptError@@RestoreSaveWin_$Arg_Bytes_DeallocFreeFromKeywordsMem_Object_ParseSizeTuple
                                                                                                                                                                                                                                    • String ID: CryptStringToBinary$Nkk$Ok:CryptStringToBinary
                                                                                                                                                                                                                                    • API String ID: 1053293993-2329441234
                                                                                                                                                                                                                                    • Opcode ID: 8aaf17ff537dfe4838f2e90468edf14b99545a19e70dcc9a58435ab2533604f5
                                                                                                                                                                                                                                    • Instruction ID: 4c039c8aceb6e13ca9934a273ebb14498c52fd7f2048559074c005514d8b14fa
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8aaf17ff537dfe4838f2e90468edf14b99545a19e70dcc9a58435ab2533604f5
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BF415B36B08B5186DB148F12E46467E7BA4FB88B90B544135DE9D53B18DF3DD8C4C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Arg_KeywordsParseTupleU_object@@_
                                                                                                                                                                                                                                    • String ID: CryptBinaryToString$Ok:CryptBinaryToString
                                                                                                                                                                                                                                    • API String ID: 1968207123-2641875766
                                                                                                                                                                                                                                    • Opcode ID: 6f33040dc0d341229fe771835db608cda443f1955eae2e73397479bb97fbc0e3
                                                                                                                                                                                                                                    • Instruction ID: 9b189ca228eeccb8db3ff6d1779bcac429252921d4cd2d5f330813ca30e50c2c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6f33040dc0d341229fe771835db608cda443f1955eae2e73397479bb97fbc0e3
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: EE415D26B08B9286E7588B12E868B7D77A4FB88B84F544435CE5E53714DF3CE8C9C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CryptDefaultError@@KeywordsParseProviderRestoreSaveTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptGetDefaultProvider$Unable to allocate %d bytes$kk:CryptGetDefaultProvider
                                                                                                                                                                                                                                    • API String ID: 960520114-920100490
                                                                                                                                                                                                                                    • Opcode ID: 88fe7f1b502cc4200438c5732d37358f302d68a590e72da21cb49b80c55bff29
                                                                                                                                                                                                                                    • Instruction ID: b259e8dc7f25f729505aabcb1447499d3b0cfb83dc26740696e0fc3f06450ab0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 88fe7f1b502cc4200438c5732d37358f302d68a590e72da21cb49b80c55bff29
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 33410975B18B5286EB188B53E46467E7BA1FB88B94F440035EA4E13B58DF3CE5C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferCryptEncryptErr_Error@@StringU_object@@View@@Win_$Arg_Bytes_FromKeywordsMemoryParseSizeTupleU_object@@_freemalloc
                                                                                                                                                                                                                                    • String ID: CryptEncrypt$Object must be of type PyCRYPTHASH$lO|Ok:CryptEncrypt
                                                                                                                                                                                                                                    • API String ID: 3967936622-1354874914
                                                                                                                                                                                                                                    • Opcode ID: 9b670615f4f145e18604feca15b3d3e6b7ba9295a47c9517209ec1844a0d0d04
                                                                                                                                                                                                                                    • Instruction ID: 8e280be0b62c17d5cbaaccb252d52b8eb9c152244a9395838429c0abd5cead12
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9b670615f4f145e18604feca15b3d3e6b7ba9295a47c9517209ec1844a0d0d04
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2A512936B09A518AE714CF66E4607BD7BA4FB48B88F400535DD0E63B68DF38E585C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptError@@HashKeywordsParamParseTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: Hash parameter %d is not yet supported$PyCRYPTHASH::CryptGetHashParam$Unable to allocate %d bytes$k|k:CryptGetHashParam
                                                                                                                                                                                                                                    • API String ID: 4230166517-3481413517
                                                                                                                                                                                                                                    • Opcode ID: a0a30a960672429f2d58edcce6b19891f3cc39c4a53ae6bd5a5f75e0ba598de2
                                                                                                                                                                                                                                    • Instruction ID: 17dfe0444061bdb59d36849e180817e56f6846a999c3feb69ee7d2152ecba8aa
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a0a30a960672429f2d58edcce6b19891f3cc39c4a53ae6bd5a5f75e0ba598de2
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 61411F76B0869282EB48CF17F86057D6B61FB94B94F440136E94E53B68DE3CE4C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptErr_ErrorError@@FormatHashKeywordsLastParseSignTupleU_object@@Win_malloc
                                                                                                                                                                                                                                    • String ID: CryptSignHash$PyCRYPTHASH::CryptSignHash$PyCRYPTHASH::CryptSignHash: Unable to allocate %d bytes$k|k:CryptSignHash
                                                                                                                                                                                                                                    • API String ID: 588145746-3674555972
                                                                                                                                                                                                                                    • Opcode ID: 75966025d1703ceaa27282abbf3a5effc5a6731ff402c10bf186f57a6d0f9d05
                                                                                                                                                                                                                                    • Instruction ID: df1b2325d206b98cdf32cdb265ee7fde33b247de6f53162b3fd7ff47332170bd
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 75966025d1703ceaa27282abbf3a5effc5a6731ff402c10bf186f57a6d0f9d05
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5C311C32B1875286E7148B12F85063EBBA1FB98B94F440131D94E53B68DF7CE5C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CryptErr_Error@@ExportStringU_object@@Win_$Arg_Bytes_FormatFromKeywordsParseSizeTuplefreemalloc
                                                                                                                                                                                                                                    • String ID: CryptExportKey$Object must be of type PyCRYPTKEY$Ok|k:CryptExportKey$PyCRYPTKEY::CryptExportKey: Unable to allocate %d bytes
                                                                                                                                                                                                                                    • API String ID: 1765650860-2655833073
                                                                                                                                                                                                                                    • Opcode ID: 3a28f566faf0895b28a3f6713f68b3b2bd3a89495fe491e0a5edbe263b0fad1a
                                                                                                                                                                                                                                    • Instruction ID: bc61da8be548e1a7b797a19892e25c86b9e36519da199828816e7f27dbd64fce
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3a28f566faf0895b28a3f6713f68b3b2bd3a89495fe491e0a5edbe263b0fad1a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A5414F72B09A1286EB14CF16E86467D7BA1FB88B94F580135DA4D53764DF3CE8C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferEval_FreeThreadU_object@@View@@$Arg_CryptError@@IdentifierKeywordsLocalMem_Object_ParsePropertyRestoreSaveTupleU_object@@_Win_
                                                                                                                                                                                                                                    • String ID: CryptGetKeyIdentifierProperty$Only CERT_KEY_PROV_INFO_PROP_ID is currently supported$O|kkO:CryptGetKeyIdentifierProperty
                                                                                                                                                                                                                                    • API String ID: 2865977456-415975446
                                                                                                                                                                                                                                    • Opcode ID: 2c1222201b4c6830598b1b875298e53811a7db996d4de421b264045d2a2546f6
                                                                                                                                                                                                                                    • Instruction ID: 6c43ec651dcf6a5f7374d410065e0da12101bbe025d4e5917b4be230c13f8603
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2c1222201b4c6830598b1b875298e53811a7db996d4de421b264045d2a2546f6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6D414B76B09A519AE714CF62E4A06BD37B4FB48B88B404436DE4E63B18DF38D589C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferErr_StringView@@$Arg_Bytes_CryptDecryptError@@FromKeywordsMemoryParseSizeTupleU_object@@U_object@@_Win_freemallocmemcpy
                                                                                                                                                                                                                                    • String ID: CryptDecrypt$Object must be of type PyCRYPTHASH$lO|Ok:CryptDecrypt
                                                                                                                                                                                                                                    • API String ID: 298226277-2240841863
                                                                                                                                                                                                                                    • Opcode ID: 7b636552c34408d2c7f4c97fbde15252bff267e42049dbfd60274a8961aab468
                                                                                                                                                                                                                                    • Instruction ID: e45dee057cee0285fbd8324579dae79c8dedec264b099d726f381a77dbf2cc20
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7b636552c34408d2c7f4c97fbde15252bff267e42049dbfd60274a8961aab468
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 10412B36708B8286E7248B16E46077EBBA1FB98B94F544036DA4E53B24DF3CD5C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Object_$Eval_FreeThreadU_object@@$Arg_CertErr_Error@@FromKeywordsLong_OpenParseReferenceRestoreSaveStoreStringSystemTupleVoidWin_malloc
                                                                                                                                                                                                                                    • String ID: CertOpenSystemStore$Object must be of type PyCRYPTPROV$O|O:CertOpenSystemStore
                                                                                                                                                                                                                                    • API String ID: 4067469028-1076695456
                                                                                                                                                                                                                                    • Opcode ID: c9afdd978f59eed79efdbe3ab5dba8a24840abef8db1b8bed7bad69539340b73
                                                                                                                                                                                                                                    • Instruction ID: 85f83aad2df2d31f645879fd0360f0fc07ab44e3ce7c8d7248cd115e866bc1ee
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c9afdd978f59eed79efdbe3ab5dba8a24840abef8db1b8bed7bad69539340b73
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C2410D21B09B5282EB488B16F86023D6BA5FB84BC4F454132DA5E67B68DF3CE4D5C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferEval_ThreadU_object@@View@@$?init@Arg_CryptDeallocEnumErr_Error@@FreeIdentifierKeywordsList_Mem_Object_OccurredParsePropertiesRestoreSaveTupleU_object@@_Win_
                                                                                                                                                                                                                                    • String ID: CryptEnumKeyIdentifierProperties$|OkkO:CryptEnumKeyIdentifierProperties
                                                                                                                                                                                                                                    • API String ID: 3737282794-41738952
                                                                                                                                                                                                                                    • Opcode ID: 38da86077777c29739c1491d6642e904a86d5abf0e379bb7d701a29ea45eedfe
                                                                                                                                                                                                                                    • Instruction ID: c7112da9f76dcd2ddf3d77748643d6ef57a8bf3dd78be7bc6af9807b43f07a06
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 38da86077777c29739c1491d6642e904a86d5abf0e379bb7d701a29ea45eedfe
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17413732B08B5186EB588F12E46467E7BA4FB48B84F844136DA9D13B54DF3DD884C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptError@@KeywordsParamParseTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptGetKeyParam$PyCRYPTKEY::CryptGetKeyParam: Unable to allocate %d bytes$The Param specified is not yet supported$k|k:CryptGetKeyParam
                                                                                                                                                                                                                                    • API String ID: 2979963884-2192148497
                                                                                                                                                                                                                                    • Opcode ID: 87b05926f87a8cbbf5c06d9560a7d23eb62230f9b3cbccd8619659b7f272ed56
                                                                                                                                                                                                                                    • Instruction ID: f58eff64c7df3a37a482d33c2136ae81aeb32307db22adfe9541238de0ab62fc
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 87b05926f87a8cbbf5c06d9560a7d23eb62230f9b3cbccd8619659b7f272ed56
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0E410B72B08A5282EB14DF16F46057DBBA1FB88B94F440136EA4E53B18DE7CE4C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$AcquireArg_CertificateCryptErr_Error@@KeywordsParsePrivateRestoreSaveStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptAcquireCertificatePrivateKey$CryptContextAddRef$The certificate context has been closed$|k:CryptAcquireCertificatePrivateKey
                                                                                                                                                                                                                                    • API String ID: 312824557-475845844
                                                                                                                                                                                                                                    • Opcode ID: c2e9f3601f34d64434e2fe4d86c0977790c0ef75473c4315f932f1c83699ab4d
                                                                                                                                                                                                                                    • Instruction ID: ab568d512546adb931ed660bd41256f0850b5c629cab35e7a60cbcf61a13384e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c2e9f3601f34d64434e2fe4d86c0977790c0ef75473c4315f932f1c83699ab4d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 16313F76B08B5282EB089F52E46427E7BA2FB88B85F440131DA5E53764DF3CE1D5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: free$BufferErr_Eval_ThreadU_object@@View@@$Arg_CryptDeallocDetachedError@@FlagsFormatKeywordsMessageParseRestoreSaveSequence_SignatureStringTupleTuple@@Type_U_object@@_VerifyWin_malloc
                                                                                                                                                                                                                                    • String ID: CryptVerifyDetachedMessageSignature$kOO|O:CryptVerifyDetachedMessageSignature
                                                                                                                                                                                                                                    • API String ID: 1965410550-3659002915
                                                                                                                                                                                                                                    • Opcode ID: ebfcdbdcc544fc99b6d81c8d534e430a7310e888b91d142784c978c4fc2170fa
                                                                                                                                                                                                                                    • Instruction ID: ddfad1633edbd736ea169321603523318512def55d8537508451d84320aa4595
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ebfcdbdcc544fc99b6d81c8d534e430a7310e888b91d142784c978c4fc2170fa
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3E513836B19B5289E718CBA2E4607BD3BB4FB44B88B540136DE4D23B58DF38D589C341
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Arg_Err_KeywordsParseStringTupleU_object@@_
                                                                                                                                                                                                                                    • String ID: CryptGetMessageCertificates$Object must be of type PyCRYPTPROV$O|kOk:CryptGetMessageCertificates
                                                                                                                                                                                                                                    • API String ID: 1311799886-560882271
                                                                                                                                                                                                                                    • Opcode ID: b9fbb1afafbff39f0008ba88a2ad0eb425ba8b08bad560b791703845dc562044
                                                                                                                                                                                                                                    • Instruction ID: 51757ff52843c65f0abce76ebcc417d4e6bc90133864b92a9e561836e7cc0a31
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b9fbb1afafbff39f0008ba88a2ad0eb425ba8b08bad560b791703845dc562044
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: ED412A36B08B5582EB188B12E86477D7BA5FB88B84F900136DA5E53764DF3CE4C5C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Object_$U_object@@$Eval_FreeThread$AcquireArg_ContextCryptError@@KeywordsParseRestoreSaveTupleWin_
                                                                                                                                                                                                                                    • String ID: CryptAcquireContext$OOkk:CryptAcquireContext
                                                                                                                                                                                                                                    • API String ID: 1988381298-841591711
                                                                                                                                                                                                                                    • Opcode ID: 090388d49a910ed38b435a799f6ac355a6c892a4145f6402c45ebb451b5cb6cf
                                                                                                                                                                                                                                    • Instruction ID: 1f6b1e7d7e8f8d731325f2766914979969150aa5040e40f638cbfe432ba0b90a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 090388d49a910ed38b435a799f6ac355a6c892a4145f6402c45ebb451b5cb6cf
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D541F832B08B5281EB689F52E86437D7BA4FB88B84F454135DA9E53B54DF3CD489CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_Err_FormatKeywords_ParseSizeTuplemalloc
                                                                                                                                                                                                                                    • String ID: CryptGenRandom: Unable to allocate %zd bytes$PyCRYPTPROV::CryptGenRandom$k|z#
                                                                                                                                                                                                                                    • API String ID: 1718167496-62374806
                                                                                                                                                                                                                                    • Opcode ID: bb4f01495100d2b85c34e91850caa12cd30fa592c0538739c0e58d1652145f6a
                                                                                                                                                                                                                                    • Instruction ID: cc14675971c058976bc3bb24c4ae7da5671ad43eb708cdc44c6f235e8cc69c24
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bb4f01495100d2b85c34e91850caa12cd30fa592c0538739c0e58d1652145f6a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 30315D36B08A5682EB08DB26E8642BD77A5FB88BD4B584135DE4E53714DF3CD4C6CB01
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptError@@ExportInfoKeywords_ParsePublicSizeTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptExportPublicKeyInfo$CryptExportPublicKeyInfo: Unable to allocate %d bytes$k|k:CryptExportPublicKeyInfo
                                                                                                                                                                                                                                    • API String ID: 4146695621-84361842
                                                                                                                                                                                                                                    • Opcode ID: 4658fd2e88556f90eea6da663f81772c8183a041b24eac73e7f18675a796694e
                                                                                                                                                                                                                                    • Instruction ID: 1752987c8e8e879bd6bbcf8008fc8566bd73366fa00e1fabdeb8f404a3399ea4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4658fd2e88556f90eea6da663f81772c8183a041b24eac73e7f18675a796694e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E231E872B08B5282EB44DF17F86467EABA1FB84B94F444131D98D53B28DE7CE5C58B02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_Keywords_ParseSizeTuple$CryptErr_Error@@FlagsImportInfoPublicStringType_U_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptImportPublicKeyInfo$O&O&:CERT_PUBLIC_KEY_INFO$Object used to construct a CERT_PUBLIC_KEY_INFO must be a dict$O|k:CryptImportPublicKeyInfo
                                                                                                                                                                                                                                    • API String ID: 2381196778-3524712216
                                                                                                                                                                                                                                    • Opcode ID: 28b59c506ba8c18ebdb5828342135be1abc00749afdf512fd48e154aa034e3e7
                                                                                                                                                                                                                                    • Instruction ID: 3e87ebe22427837c91280b79f5ea4fc7914491b95b768a573fca67863f43f4c4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 28b59c506ba8c18ebdb5828342135be1abc00749afdf512fd48e154aa034e3e7
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C9415822B08B8281EB14DB12E8647BE7764FB88B84F944132DA9D63764DF7CE5C5C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Object_$Eval_FreeThreadU_object@@$Arg_CryptError@@KeywordsParseProviderRestoreSaveTupleWin_
                                                                                                                                                                                                                                    • String ID: CryptSetProviderEx$Okk:CryptSetProviderEx
                                                                                                                                                                                                                                    • API String ID: 1842323616-1750013035
                                                                                                                                                                                                                                    • Opcode ID: 491ed1971141ac856698c622e8cdebbc11b1700cb5240b2147f00f922a294e75
                                                                                                                                                                                                                                    • Instruction ID: dd9bede5e8e3f1a7c2072ee8578a4faff40f6420535aa97bea78c423f251ffba
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 491ed1971141ac856698c622e8cdebbc11b1700cb5240b2147f00f922a294e75
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 54313832B08A2282EB149F16F86467D7BA5FB98BD0B550132DA5D53B64CF3DD8C5CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Arg_KeywordsParseTupleU_object@@_
                                                                                                                                                                                                                                    • String ID: CryptGetMessageSignerCount$O|k:CryptGetMessageSignerCount
                                                                                                                                                                                                                                    • API String ID: 1968207123-858434672
                                                                                                                                                                                                                                    • Opcode ID: 19b0024fc19b1c6edfd9e8f9e4d37e60176eab52847bd211932c5f93d6becd87
                                                                                                                                                                                                                                    • Instruction ID: dccb7c654c6154743d97d11ba696807f8aec4233a813c3928e130bfcef1cf529
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 19b0024fc19b1c6edfd9e8f9e4d37e60176eab52847bd211932c5f93d6becd87
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0E217F26B08A4286EB648F26F8647BD3760FB89B84F940135CA5E53754CF3DD8C9C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CryptDeallocEnumErr_Error@@InfoKeywordsList_OccurredParseRestoreSaveTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptEnumOIDInfo$|k:CryptEnumOIDInfo
                                                                                                                                                                                                                                    • API String ID: 2345210855-1370177178
                                                                                                                                                                                                                                    • Opcode ID: cad6aba763297521d99328affc00dc3429710f0e42e866b7d4bb8148c186efe3
                                                                                                                                                                                                                                    • Instruction ID: 47185b3de04a63df505451b41eaaebaa8b3aaf2f8c36945b380b969c4ff49232
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cad6aba763297521d99328affc00dc3429710f0e42e866b7d4bb8148c186efe3
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 72117F61B08B6281EB099F66F86427D6BA0BF98B94F444435CE5D63764DF3CE4C98702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Arg_CryptErr_Error@@ImportKeywords_ParseSizeStringTupleU_object@@U_object@@_Win_
                                                                                                                                                                                                                                    • String ID: Object must be of type PyCRYPTKEY$O|Ok$PyCRYPTPROV::CryptImportKey
                                                                                                                                                                                                                                    • API String ID: 3946236484-248037244
                                                                                                                                                                                                                                    • Opcode ID: a57462b4e30e7be379cfabc5acd202eb81d84cedf92da49e570374b442a4f36b
                                                                                                                                                                                                                                    • Instruction ID: 48461af66db97e297df3bf88d2dc06d516ea93667f6f6150281202ae0b521c28
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a57462b4e30e7be379cfabc5acd202eb81d84cedf92da49e570374b442a4f36b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BD411C22708B8685EB649F56E4607BE7BA5FB88B84F444036DA4D53B64DF3CD5C4C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Arg_CryptErr_Error@@KeywordsParseSignatureStringTupleU_object@@U_object@@_VerifyWin_
                                                                                                                                                                                                                                    • String ID: OO|k:CryptVerifySignature$Object must be of type PyCRYPTKEY$PyCRYPTHASH::CryptVerifySignature
                                                                                                                                                                                                                                    • API String ID: 1262447337-1335157759
                                                                                                                                                                                                                                    • Opcode ID: abc2c5c959075a0defc217451f6004fd55ab8c8300a94573b72e7bb2848116c3
                                                                                                                                                                                                                                    • Instruction ID: d349679d1a53ae6cec09cb654d90ee006867de39739f9c748b2be33f20ac1b8a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: abc2c5c959075a0defc217451f6004fd55ab8c8300a94573b72e7bb2848116c3
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E1313432B08A5681EB288F52E8A477D7BA5FB88B84F944136CA5D57754CF3CE9C4C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CreateCryptErr_Error@@HashKeywords_ParseReferenceSizeStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: I|Ok$Object must be of type PyCRYPTKEY$PyCRYPTPROV::CryptCreateHash
                                                                                                                                                                                                                                    • API String ID: 121666029-682297043
                                                                                                                                                                                                                                    • Opcode ID: 5f29b39c9c7c32134d10183e8dcb6556ed63e655b90ad5750308bbed8fe0f805
                                                                                                                                                                                                                                    • Instruction ID: acf17c05813e613c585a1daf06f71f7f0679ce581a00b476906fcf99c25a8b74
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5f29b39c9c7c32134d10183e8dcb6556ed63e655b90ad5750308bbed8fe0f805
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8E311A22B08B4682EA14CB16F45027D7BA5FB88B84F544132DA9D53B64DF3CD5D4CB01
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Object_$Eval_ThreadU_object@@$Arg_CryptFindFreeFromKeywordsLocalizedNameParseRestoreSaveTuple
                                                                                                                                                                                                                                    • String ID: O:CryptFindLocalizedName
                                                                                                                                                                                                                                    • API String ID: 2786140858-1113378710
                                                                                                                                                                                                                                    • Opcode ID: d2b90933331ecc4a3b76b5deeb91475e847ad12fd4f7b463fb0ebc9d7af4602c
                                                                                                                                                                                                                                    • Instruction ID: 81b8e30a2ef09b7782dcbff2a97b353125b1aaf5788429b85df1538898e87a41
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d2b90933331ecc4a3b76b5deeb91475e847ad12fd4f7b463fb0ebc9d7af4602c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9211D665B08B5281DB189F52F86467E7BA0FB89BD4B841035EA4E53B14DF3CE0C4C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 313767242-0
                                                                                                                                                                                                                                    • Opcode ID: 33b15849939cb2923083c082be92fa206dbdf07deec005c9a4392973ea27f9aa
                                                                                                                                                                                                                                    • Instruction ID: 8358b247cc7719fb9af5a357721d4715099b7bcfc7abef8346d31c4785b2643a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 33b15849939cb2923083c082be92fa206dbdf07deec005c9a4392973ea27f9aa
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 83315A72709B8286EBA4DF62E8507FE2760FB84744F44443ADA4E57A88EF3CC588C701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Arg_CryptDataHashKeywordsParseTupleU_object@@_
                                                                                                                                                                                                                                    • String ID: CryptHashData$O|k:CryptHashData
                                                                                                                                                                                                                                    • API String ID: 1059791976-129170221
                                                                                                                                                                                                                                    • Opcode ID: e81e29286d92d5c1ab9536c36441c8f0f37c8443e30fc23d6d2f85d4b41b370a
                                                                                                                                                                                                                                    • Instruction ID: 9e1da549aeabe9ce745b3f1bd231d3bcd6ef1991ca4f281656a0ae70c37f6dcc
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e81e29286d92d5c1ab9536c36441c8f0f37c8443e30fc23d6d2f85d4b41b370a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 08214822B18A8681EB688F16E8A4BBD7761FB44B84F844032DA6E53754DE3CD4D9C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptErr_Error@@HashKeywordsParseSessionStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptHashSessionKey$Object must be of type PyCRYPTKEY$O|k:CryptHashSessionKey
                                                                                                                                                                                                                                    • API String ID: 4245653644-2666860678
                                                                                                                                                                                                                                    • Opcode ID: ef79486d15c7f56489e34056a977a02f42b149618f9a166fe6e233d7ec569d38
                                                                                                                                                                                                                                    • Instruction ID: 0102ddc0251aaed78391c93915e306d76a1b3a6f4ded24f09a7dd64dcd43a38d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ef79486d15c7f56489e34056a977a02f42b149618f9a166fe6e233d7ec569d38
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 04116AA2B08A1682EB188B56E86027D7BB1FB84B84B484032C94E57768DF3CD5D5CB12
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptDuplicateKeywordsParseTuple
                                                                                                                                                                                                                                    • String ID: CryptDuplicateKey$|kk:CryptDuplicateKey
                                                                                                                                                                                                                                    • API String ID: 2077482966-1662090741
                                                                                                                                                                                                                                    • Opcode ID: 8b041bebffa72a804aa7c25e59a4dd647b8783cf2240cfd94aa2fd11b968346e
                                                                                                                                                                                                                                    • Instruction ID: b09c3a373914c9235767a4e36d766fe80ada6b41c388c1c3c30222151eb25278
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8b041bebffa72a804aa7c25e59a4dd647b8783cf2240cfd94aa2fd11b968346e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F5314F72B0878286D7058F66F46016E7BB0FB89B94B484036DA9D93B19DE7CE4D6C701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptErrorError@@FromKeywords_LastLong_ParseReferenceSizeTupleU_object@@VoidWin_malloc
                                                                                                                                                                                                                                    • String ID: CryptGenKey$Ik|k:CryptGenKey
                                                                                                                                                                                                                                    • API String ID: 3083420793-1888919388
                                                                                                                                                                                                                                    • Opcode ID: 83e5532a04f0445a11ddc4955ff3d93e42ce0999c9a6c6759785556b5dee0830
                                                                                                                                                                                                                                    • Instruction ID: 47b3a5268d73d520a4ee6e55a353f9dca44b1603f3965791623abbf2275ce662
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 83e5532a04f0445a11ddc4955ff3d93e42ce0999c9a6c6759785556b5dee0830
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 61213932B0864186EB149F2AE4146AE77A0FB88B94F900136DA9D93B54DF3CD5C5CB41
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptDuplicateHashKeywordsParseReferenceTuple
                                                                                                                                                                                                                                    • String ID: CryptDuplicateHash$|k:CryptDuplicateHash
                                                                                                                                                                                                                                    • API String ID: 3054858463-1283885492
                                                                                                                                                                                                                                    • Opcode ID: f1f4265edc88cbdb7097f5f612830fd1021832614f84136f168a695e5502c5e1
                                                                                                                                                                                                                                    • Instruction ID: 7d607870f1cd3000c18c79779f1a39289c5dbbd6d93c4d6a495dcfe66c98ce41
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f1f4265edc88cbdb7097f5f612830fd1021832614f84136f168a695e5502c5e1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E1116D22708B4682EB488F16F9501BDAB60FB88BD4F484032DA5E53B18DF7CD1D4C701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_ContextCryptError@@Keywords_ParseReleaseSizeTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptReleaseContext$|k:CryptReleaseContext
                                                                                                                                                                                                                                    • API String ID: 2608048266-3508415085
                                                                                                                                                                                                                                    • Opcode ID: 8f8de7e13ef99eb102be8ded0d13b18687a6c0c241888ff013c6c61917a7f738
                                                                                                                                                                                                                                    • Instruction ID: b5a4dfd505fd79e700726e15bee2d0d7e9b60eea821305fdbd5f93a775dc7ddd
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8f8de7e13ef99eb102be8ded0d13b18687a6c0c241888ff013c6c61917a7f738
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 78016D65B08A4682EB099F13E8606BD2771BF94B84F580032CD1D17364CF3DD0C5C746
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • _PyArg_ParseTupleAndKeywords_SizeT.PYTHON39 ref: 00007FFDE3AD5810
                                                                                                                                                                                                                                    • CryptGetUserKey.ADVAPI32 ref: 00007FFDE3AD5826
                                                                                                                                                                                                                                    • ?PyWin_SetAPIError@@YAPEAU_object@@PEADJ@Z.PYWINTYPES39 ref: 00007FFDE3AD5863
                                                                                                                                                                                                                                      • Part of subcall function 00007FFDE3ADF3D0: malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE3AD13A4), ref: 00007FFDE3ADF3EA
                                                                                                                                                                                                                                      • Part of subcall function 00007FFDE3AD4390: _Py_NewReference.PYTHON39 ref: 00007FFDE3AD43B3
                                                                                                                                                                                                                                      • Part of subcall function 00007FFDE3AD4390: PyLong_FromVoidPtr.PYTHON39 ref: 00007FFDE3AD43C7
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CryptError@@FromKeywords_Long_ParseReferenceSizeTupleU_object@@UserVoidWin_malloc
                                                                                                                                                                                                                                    • String ID: PyCRYPTPROV::CryptGetUserKey
                                                                                                                                                                                                                                    • API String ID: 828709316-2956425817
                                                                                                                                                                                                                                    • Opcode ID: 6ee2be64e851b5bb899c3f5e49d2f53fd0ee03eecbaa03131667243ea0dd8624
                                                                                                                                                                                                                                    • Instruction ID: 1d776e301b894fe07d6a4e4e44821f24a586b402cc82eed1e8e2a87236e04ffd
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6ee2be64e851b5bb899c3f5e49d2f53fd0ee03eecbaa03131667243ea0dd8624
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1D21D6E2B0C78147E7058F61A8502AD7B60FB99B94F894032DB4943746EE2CD587C701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CryptDestroyError@@HashU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CryptDestroyHash
                                                                                                                                                                                                                                    • API String ID: 2307853852-174375392
                                                                                                                                                                                                                                    • Opcode ID: 5b8ed3df7a95d948f5d6e2c0fe75035481855f8388019bb4ce032e72c70f1edb
                                                                                                                                                                                                                                    • Instruction ID: d297991075f42b33a6b4efd421f54bbd6e42b255d6bd3bf1128f0ea490810465
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5b8ed3df7a95d948f5d6e2c0fe75035481855f8388019bb4ce032e72c70f1edb
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0FE0B625F0991281EB0D5B17DC6137C27A1BF98B85FD88831C50E662A0DE2CE5D68712
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Dealloc$CryptDestroy
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3653355852-0
                                                                                                                                                                                                                                    • Opcode ID: 96fec737bb3b38520c32f6741ac9eb413cfab407dd007c7a5810244085cff574
                                                                                                                                                                                                                                    • Instruction ID: 60feb6014d35883bb3b34761dae32b0982e92cd4d3fcd4b21a8ec7e9ed99038f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 96fec737bb3b38520c32f6741ac9eb413cfab407dd007c7a5810244085cff574
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E1F08C62F0A61281EF1D8F76D8743382B60AF59F58F980034CA0E26A448E2DD8C28353
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Dealloc$CryptDestroy
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3653355852-0
                                                                                                                                                                                                                                    • Opcode ID: 07b9b46adb27d63616e181f749fb6b6d44f78a8dc8973dfdecbfa424a4d79455
                                                                                                                                                                                                                                    • Instruction ID: 582c421ff9a6d54c1fd4327bcbe4a56c583f36d92810a11dd7ca1f71fa0a8525
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 07b9b46adb27d63616e181f749fb6b6d44f78a8dc8973dfdecbfa424a4d79455
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D5F01C66F0A61381FF1D9F76D8753382760AF98F68F981034C91E56B448E2DE4C28353
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CryptDestroy
                                                                                                                                                                                                                                    • String ID: CryptDestroyKey
                                                                                                                                                                                                                                    • API String ID: 1712904745-3992593795
                                                                                                                                                                                                                                    • Opcode ID: 839645a6d32e574f855941f477cff83ecdd5bca0d189fa11d00771ad0c720ffd
                                                                                                                                                                                                                                    • Instruction ID: 9b70f23755251fec8eab78b77fa3c7c5412ce3fb0b21d23c89072110ecb37f04
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 839645a6d32e574f855941f477cff83ecdd5bca0d189fa11d00771ad0c720ffd
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 71E0EC66F08916C1EB1D9B07ECA023C2772BB98BC8F844032C90E63320CE2CD1E28307
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CloseCrypt
                                                                                                                                                                                                                                    • String ID: CryptMsgClose
                                                                                                                                                                                                                                    • API String ID: 1563465135-1998627854
                                                                                                                                                                                                                                    • Opcode ID: eeaaf32d97239d4e182fc3877b34e146cb23ea9e1ccdd0a1d6d4ab68f69d6302
                                                                                                                                                                                                                                    • Instruction ID: f965dd96c5297d0e965793126719885635b6a691cbcf8b0d6911c0d739b28059
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: eeaaf32d97239d4e182fc3877b34e146cb23ea9e1ccdd0a1d6d4ab68f69d6302
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1FE0EC66F09912C1EB1D9B17ECA027C2772FB98B89F840132C50D66330CE2CD0E28307
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CloseCryptDealloc
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3014539515-0
                                                                                                                                                                                                                                    • Opcode ID: 6d8ef548de883e28ec7d87c0460d618988f94307dec32326118ee44ee8811f2f
                                                                                                                                                                                                                                    • Instruction ID: 24c7168ed63f14d122b3fc40c05eab56660c5f1d504aa750dca94a6ddf6ee20e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6d8ef548de883e28ec7d87c0460d618988f94307dec32326118ee44ee8811f2f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C0E04F65F0B60281FF5D9BA2E83533C17609F68F19F595634CD8E666848E2CD5D54303
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CloseCryptDealloc
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3014539515-0
                                                                                                                                                                                                                                    • Opcode ID: 507e96d8bf7d87c9cf2942f0025a96dc68d2f3a0da4afe8c29f30cc787adda05
                                                                                                                                                                                                                                    • Instruction ID: dbfad206d64618e6b0391dbb4df6807d22b12d6a6cae7f2e06f4153421ae8f3d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 507e96d8bf7d87c9cf2942f0025a96dc68d2f3a0da4afe8c29f30cc787adda05
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0FE04F69B0A60381EF1D9B62982433816109F98F59F595634CD9E6A355CE2CE4D24313
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Dealloc
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3617616757-0
                                                                                                                                                                                                                                    • Opcode ID: 43da16ac8078157a88497b1c25304bba8cb2e8dc123e9f9fa80b40cf7fcb828b
                                                                                                                                                                                                                                    • Instruction ID: ff7386be326706d96c63b1f6076368383178c549c5bce3f43c290e16993aad97
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 43da16ac8078157a88497b1c25304bba8cb2e8dc123e9f9fa80b40cf7fcb828b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8BE01A36F0A92280EF6D8F76D87423827A0EF68F68F591034CA1D166448E2DE6C18353
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CloseCrypt
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1563465135-0
                                                                                                                                                                                                                                    • Opcode ID: 7a1054c1d97dad9855fc6840a84231ebb24212d48188de8f86287e1eadbac771
                                                                                                                                                                                                                                    • Instruction ID: 7bb767dab55cf959c49a92f544668414e74e2f9b8e272c22232019fd74396f16
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7a1054c1d97dad9855fc6840a84231ebb24212d48188de8f86287e1eadbac771
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AFE01D76F07506C1FF6D4B6694712341650DF98F58F551634CE5D5A2544F2CD4D14703
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ContextCryptRelease
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 829835001-0
                                                                                                                                                                                                                                    • Opcode ID: 281a9c07cf909b781a73766ee01c4a8dd63c13b9436c5d24a741a80562a06fc6
                                                                                                                                                                                                                                    • Instruction ID: 61bb91b7fdd7466387f26c77d36b469c7d2ad965b3ebaeb75eda543d38a0f242
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 281a9c07cf909b781a73766ee01c4a8dd63c13b9436c5d24a741a80562a06fc6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 57D01291F2954683FF1CE7A3A87527907119FECB49F689430CD1E6A3A19D2CD4DB4302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ContextCryptRelease
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 829835001-0
                                                                                                                                                                                                                                    • Opcode ID: 3ad55125e3799c4f5846d02c072e0412d1ff6b84c26f6272286896feb1da0ec0
                                                                                                                                                                                                                                    • Instruction ID: 195befdd8f3e1e61f4181f56fdf77113d2c105371bba79dd9c60ea318785df34
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3ad55125e3799c4f5846d02c072e0412d1ff6b84c26f6272286896feb1da0ec0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D6C01251B5454583EF1CA767A85117913129FD9B55F589030CD1D5B391CD2CD4DB4301
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CryptDestroyHash
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 174375392-0
                                                                                                                                                                                                                                    • Opcode ID: 345cef05df8cef93fcb427b97f8883c382271a1a7b66bf68c4151862d1fe1dc2
                                                                                                                                                                                                                                    • Instruction ID: bb1119e2188341629fce0d2956008efa51b45624e12350481bcc00d7b6da2a52
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 345cef05df8cef93fcb427b97f8883c382271a1a7b66bf68c4151862d1fe1dc2
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9AD01295F1910582FE1C9793A8713B906109F98B85F681434DD1E6A3D18D2DD5D64341
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CryptDestroyHash
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 174375392-0
                                                                                                                                                                                                                                    • Opcode ID: 26b765947bea4b2709b72f7c0e569dcf4c724aa596d4ae5983ea4bbbdbf39ae3
                                                                                                                                                                                                                                    • Instruction ID: 705c0b200477dd272bcad85097dd0e127f84efc1404895cd6f058fc9e0fc60bb
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 26b765947bea4b2709b72f7c0e569dcf4c724aa596d4ae5983ea4bbbdbf39ae3
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F4C01250B5820982EE086B63A8612BD1211AB99B86F681030CE1E5B392CD2CE5D74301
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: e8e2995051db006df15b262e506feebe9c8352d92f39084eb5b0262ddf3151ea
                                                                                                                                                                                                                                    • Instruction ID: 90d48f5cb0d64f4bab845dca3a498cff127112ea670d506b903ebd9cf7ff4c2c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e8e2995051db006df15b262e506feebe9c8352d92f39084eb5b0262ddf3151ea
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6CA00222B08D92C5EB1CDB17E8642792772FBD8B4D7758432C91D59024DE39D1C78302
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID:
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID:
                                                                                                                                                                                                                                    • Opcode ID: eb278288c44b84eb73e9418201a0b4c1a4c6b44eca16cf00ec01c6c1f33e190e
                                                                                                                                                                                                                                    • Instruction ID: 97ba647b18444d6292c611d3d130f5b932a95728e56547e567f521123e9a1d69
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: eb278288c44b84eb73e9418201a0b4c1a4c6b44eca16cf00ec01c6c1f33e190e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7FA00222708D51C1DA4C8B07D47027C2731F780BC67200871D51E550648F39D5828302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: FromLong_Unicode_Void
                                                                                                                                                                                                                                    • String ID: CertEncoded$CertEncodingType$CertStore$Critical$Extension$HANDLE$Issuer$NotAfter$NotBefore$ObjId$SerialNumber$SignatureAlgorithm$Subject$SubjectPublicKeyInfo$The certificate context has been closed$Value$Version${s:s,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 1154900293-275060559
                                                                                                                                                                                                                                    • Opcode ID: 1fd91421874b68fb14a6f42b90d1d96a0c0eb1ea86c78efc5858499f3cc7c6b0
                                                                                                                                                                                                                                    • Instruction ID: 6c322d5582ad4cb759bf2e0bc7c20e6a9071e95fc86456f5d078fbd3c15de3ba
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1fd91421874b68fb14a6f42b90d1d96a0c0eb1ea86c78efc5858499f3cc7c6b0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 96C11B25B0874282EA5C9B16D57037C2BA2BF95B88F894431CE4E67395EF2CE8D5C353
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: From$Size$BuildBytes_DeallocObject_StringU_object@@Value_$Bool_Err_LongTuple_Warn
                                                                                                                                                                                                                                    • String ID: ContainerName$Data$Flags$KeySpec$Param$ProvName$ProvParam$ProvType$Unsupported PP_ parameter returned as raw data${s:k, s:k, s:N}${s:u, s:u, s:k, s:k, s:k, s:N}
                                                                                                                                                                                                                                    • API String ID: 18416738-1800846073
                                                                                                                                                                                                                                    • Opcode ID: 7eb8472f39e0f11c88cf76ab83a1a57d73c8eff97822fe45bc2d777fd0b0a9bc
                                                                                                                                                                                                                                    • Instruction ID: 484a5ffd01248c5bfc55a4ff898d48db14ef1e482dae119fb8105b7a697527a2
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7eb8472f39e0f11c88cf76ab83a1a57d73c8eff97822fe45bc2d777fd0b0a9bc
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 12512832B08A1696EB189F16E86463D7BA0FB48B94F954135DA4D63B30DF3CE4D1C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DeallocSize$FromString$BuildBytes_CertDuplicateState_Value_$CallCertificateContextEnsureErr_Long_Object_ReferenceReleaseStoreVoid
                                                                                                                                                                                                                                    • String ID: Issuer$Object must be of type PyCERT_CONTEXT$OkNN$SerialNumber$The certificate context has been closed${s:N, s:N}
                                                                                                                                                                                                                                    • API String ID: 2673056449-1119961777
                                                                                                                                                                                                                                    • Opcode ID: 5ed39760328bcfccb2c14c966abc0853baf90e42a79949c582c5c064b13861d4
                                                                                                                                                                                                                                    • Instruction ID: 97225c9222375137fda09d4fa3236f78c49f316963a9835e06b40b963fc3180a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5ed39760328bcfccb2c14c966abc0853baf90e42a79949c582c5c064b13861d4
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A6510732B09B2282EB5C8F12E86463D6BA1FB58B94F444035C95E67764DF3EE5C5C342
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_Err_KeywordsParseStringTuple
                                                                                                                                                                                                                                    • String ID: CertGetCertificateContextProperty$CertGetCertificateContextProperty: unable to allocate %d bytes$Not yet supported$The certificate context has been closed$k:CertGetCertificateContextProperty
                                                                                                                                                                                                                                    • API String ID: 1259807946-657533434
                                                                                                                                                                                                                                    • Opcode ID: ed88d59707e9ceef137912f1159f3b70a2de9e22254da18e86a88ca118d1de72
                                                                                                                                                                                                                                    • Instruction ID: 500fad4ae8b57c34d670d902b48791e62f526e7f3a094ae20ef1bf6f696fba73
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ed88d59707e9ceef137912f1159f3b70a2de9e22254da18e86a88ca118d1de72
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 51516F75B08A5282EB08DF27E86467E2BA1FF88B84F544431DA4E67764DE3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$Build$Bytes_DeallocFromString$Err_State_Tuple_ValueValue_Warn$AppendEnsureList_Release
                                                                                                                                                                                                                                    • String ID: Data$Key identifier property returned as raw data$KeyIdentifier$PropId$Props${s:N, s:N}${s:k,s:N}
                                                                                                                                                                                                                                    • API String ID: 2091424248-3219072386
                                                                                                                                                                                                                                    • Opcode ID: 3e038c22d9f9da6106e18e47cc1069cf9e4d3386e82dee5b11eeaf8eb2d98aec
                                                                                                                                                                                                                                    • Instruction ID: 989a11d03bc0ce079121a292d332bf9777349743c53b82a891b07095c5a0bc90
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3e038c22d9f9da6106e18e47cc1069cf9e4d3386e82dee5b11eeaf8eb2d98aec
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F4514826B09B8691EA689B22E86437D7BA1FB44B98F444035DE5E23758DF3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferEval_ThreadView@@$Arg_CertError@@KeywordsNameParseRestoreSaveTupleU_object@@U_object@@_Win_
                                                                                                                                                                                                                                    • String ID: CertNameToStr$O|kk:CertNameToStr$Unable to allocate %d bytes
                                                                                                                                                                                                                                    • API String ID: 2442106594-1555462470
                                                                                                                                                                                                                                    • Opcode ID: 2464aac7f86653fe7db228c1e4c4cb4fcf58e6d2323f9c3bc5f57e1c47f0eb3e
                                                                                                                                                                                                                                    • Instruction ID: 95d2fb773b0a7f258330dc0775c97c88bf3f22259e008b2364e8b5f3c2df1a25
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2464aac7f86653fe7db228c1e4c4cb4fcf58e6d2323f9c3bc5f57e1c47f0eb3e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D7514836B08A9686EB148F16E86477D7BA0FB89B84F444035DA4E63714DF3CE4C9CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertElementErr_Error@@KeywordsParseRestoreSaveSerializeStoreStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CertSerializeCertificateStoreElement$The certificate context has been closed$Unable to allocate %d bytes$|k:CertSerializeCertificateStoreElement
                                                                                                                                                                                                                                    • API String ID: 1213706224-3507625014
                                                                                                                                                                                                                                    • Opcode ID: 7d46dcfbc0ee196d3c45cba0f4158d1fcfbce28cfadff0c74d4b6e29230d7554
                                                                                                                                                                                                                                    • Instruction ID: ae1b9599999005b5f32ecef9a4016b1e63e4319e92c2cdabe76ae801ff7b35ed
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7d46dcfbc0ee196d3c45cba0f4158d1fcfbce28cfadff0c74d4b6e29230d7554
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 77411C76B0875682EB089B63E86467D6B61FB84B94F440035DD4E23B64DF7CE4CAC702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_ThreadU_object@@$Arg_CertErr_Error@@ExportFreeKeywordsMem_MemoryObject_ParseRestoreSaveStoreTupleWin_malloc
                                                                                                                                                                                                                                    • String ID: PFXExportCertStoreEx$|Ok:PFXExportCertStoreEx
                                                                                                                                                                                                                                    • API String ID: 1535270174-947405562
                                                                                                                                                                                                                                    • Opcode ID: 99779f196b162b64fe39cbf76c9ce30fb004924ff5f585c801d5ed6d0e63550d
                                                                                                                                                                                                                                    • Instruction ID: 0c26f4245c1bfcd04e9f8771ad99a448727c3f0ddae27b1d834e230d2dfc23f3
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 99779f196b162b64fe39cbf76c9ce30fb004924ff5f585c801d5ed6d0e63550d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 02413C66B08A9286E7688F12E86077E7B61FB98B85F444131DE4E53B18DF3CD4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertEnhancedErr_Error@@KeywordsParseRestoreSaveStringTupleU_object@@UsageWin_
                                                                                                                                                                                                                                    • String ID: CertGetEnhancedKeyUsage$Failed to allocate %d bytes$The certificate context has been closed$|k:CertGetEnhancedKeyUsage
                                                                                                                                                                                                                                    • API String ID: 3590224318-2435798374
                                                                                                                                                                                                                                    • Opcode ID: 2a7198d9fc71b8735b2ae3b67a525b3e02d24dae0d77f064ffeb656ff8193205
                                                                                                                                                                                                                                    • Instruction ID: ca17d295ce9fa8cdffdc2f91946f5cdded5e1f8f4de1b1a5daf2864bc54fc1a8
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2a7198d9fc71b8735b2ae3b67a525b3e02d24dae0d77f064ffeb656ff8193205
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C2412C66B08B5682EB089B67E86467D6B61FB98B94F440035DD4E27B24DE7CE0C6C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$From$BuildValue_$Bytes_E@@@Object_StringU_object@@
                                                                                                                                                                                                                                    • String ID: Data$IntendedKeyUsage$KeyId$NotAfter$NotBefore$PrivateKeyUsagePeriod$UnusedBits${s:N, s:N, s:N}${s:N, s:N}${s:N,s:k}
                                                                                                                                                                                                                                    • API String ID: 1928187129-2639204421
                                                                                                                                                                                                                                    • Opcode ID: 80e19475ca6043f1c5a35e7f6cd2a9148a4f6eebb0cbd8e04db319c8ae2058ac
                                                                                                                                                                                                                                    • Instruction ID: 8306014ba86f714cc6997d3518bd157ab90008125a6367145343dc366907c185
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 80e19475ca6043f1c5a35e7f6cd2a9148a4f6eebb0cbd8e04db319c8ae2058ac
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8C212726B09B5692EA198F12F86027D7B60FB88BC4B444132DA4D23724DF3CE5E5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferErr_Eval_ReferenceThreadView@@$Arg_CertElementError@@FormatFromKeywordsLong_ParseRestoreSaveSerializedStoreStringTupleU_object@@U_object@@_VoidWin_
                                                                                                                                                                                                                                    • String ID: CertAddSerializedElementToStore$Context type %d is not yet supported$OOk|kk:CertAddSerializedElementToStore$Object must be of type PyCERTSTORE
                                                                                                                                                                                                                                    • API String ID: 544885331-4265936841
                                                                                                                                                                                                                                    • Opcode ID: e4a0891f618b3bc48b6b459a30b8f665d4c49c656256312d22a6abd81de122e1
                                                                                                                                                                                                                                    • Instruction ID: 68ff319549acaea1c39d467a554400a5fa9a07b52694930105d34829ba3ef5fa
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e4a0891f618b3bc48b6b459a30b8f665d4c49c656256312d22a6abd81de122e1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6A612936B08B5281EB188B12E4A477D7BA4FB98B84F544136DA5E53B68DF3CD4C8C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • PyType_GetFlags.PYTHON39(?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FFDE3AD82A1), ref: 00007FFDE3AD7F95
                                                                                                                                                                                                                                    • PyErr_SetString.PYTHON39(?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FFDE3AD82A1), ref: 00007FFDE3AD7FB2
                                                                                                                                                                                                                                    • _PyArg_ParseTupleAndKeywords_SizeT.PYTHON39(?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FFDE3AD82A1), ref: 00007FFDE3AD7FE9
                                                                                                                                                                                                                                    • ?PyWinSequence_Tuple@@YAPEAU_object@@PEAU1@PEAK@Z.PYWINTYPES39(?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FFDE3AD82A1), ref: 00007FFDE3AD7FFF
                                                                                                                                                                                                                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FFDE3AD82A1), ref: 00007FFDE3AD8020
                                                                                                                                                                                                                                    • PyErr_NoMemory.PYTHON39(?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FFDE3AD82A1), ref: 00007FFDE3AD802F
                                                                                                                                                                                                                                    • _Py_Dealloc.PYTHON39(?,?,?,?,?,?,?,?,?,?,?,00000000,?,00000000,?,00007FFDE3AD82A1), ref: 00007FFDE3AD80FD
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$Arg_DeallocFlagsKeywords_MemoryParseSequence_SizeStringTupleTuple@@Type_U_object@@malloc
                                                                                                                                                                                                                                    • String ID: Object used to construct CRYPT_ATTRIBUTE must be a dict$sO:CRYPT_ATTRIBUTE
                                                                                                                                                                                                                                    • API String ID: 729417699-2761299909
                                                                                                                                                                                                                                    • Opcode ID: e07685fe449f36e759190572404582af29a1cfea4a0e5a47f7178c3cc9e1d106
                                                                                                                                                                                                                                    • Instruction ID: e89153aaa16abcac360e94d6722de3d1870c8d138d36c4e6e16805213d3fe41f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e07685fe449f36e759190572404582af29a1cfea4a0e5a47f7178c3cc9e1d106
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0D515B22B19A4296EB58DF26E8607BD7BA4FB88B84F444031EA4E63754DF3CD4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_Eval_StringThread$Arg_BufferCertCheckErrorError@@FreeFromKeywordsLastLong_Object_OpenParseReferenceRestoreSaveSequence_StoreTupleU_object@@View@@VoidWin_
                                                                                                                                                                                                                                    • String ID: CertOpenStore$O&kOkO:CertOpenStore$Object must be of type PyCRYPTPROV$Specified store provider type not supported
                                                                                                                                                                                                                                    • API String ID: 3832450745-1761686843
                                                                                                                                                                                                                                    • Opcode ID: 0e1b27fd902743f3f0c698bba0c401941d94d64266400cb61fb5071a90eae2bb
                                                                                                                                                                                                                                    • Instruction ID: 3684fd4615b09a5fe468226ab700334b9af949df495b31255ba2ca0ed2a03231
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0e1b27fd902743f3f0c698bba0c401941d94d64266400cb61fb5071a90eae2bb
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 45512C32B09B0299E7188F66E4502BC3BB5BB44B98B504135DE5E63B68DF3CD4D5C342
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Dealloc$CertEval_List_Thread$AppendContextDuplicateEnumErrorError@@FromLastLong_ReferenceRestoreSaveStoreU_object@@VoidWin_
                                                                                                                                                                                                                                    • String ID: CertEnumCTLsInStore
                                                                                                                                                                                                                                    • API String ID: 62969067-3713136399
                                                                                                                                                                                                                                    • Opcode ID: a292a512a9ab44f35d45c2ebc195349a739ab8de8c20c54f9f68b49317875966
                                                                                                                                                                                                                                    • Instruction ID: ef4c694c107c5d6b84cdb3f3a2ee7efbb24bba6ab821004e00422f17d17d5028
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a292a512a9ab44f35d45c2ebc195349a739ab8de8c20c54f9f68b49317875966
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 8F412C22B09A1285EB9D9F12E86433D6BA1BF49F99F980434CD1E56760EF3CE4C58302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$From$BuildBytes_StringValue_$Bool_DeallocLongTuple_
                                                                                                                                                                                                                                    • String ID: Data$PathLenConstraint$SubjectType$SubtreesConstraint$UnusedBits$fPathLenConstraint${s:N, s:N, s:k, s:N}${s:N,s:k}
                                                                                                                                                                                                                                    • API String ID: 2254952139-3836181269
                                                                                                                                                                                                                                    • Opcode ID: 337f853b9805348b0a0715d7aafb1acb29489af72ae7c1bca2e3ee4738dea4d2
                                                                                                                                                                                                                                    • Instruction ID: bb6a2b89c33a1aa4f58b3df3531b00451f7bb08e19c4cff16ecfd866a26d023a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 337f853b9805348b0a0715d7aafb1acb29489af72ae7c1bca2e3ee4738dea4d2
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 15311836B08B4696DB08DF12E4A017D3B64FB88B94B440235DA9E53B98DF3CE1E5C711
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_Formatfreemalloc$BufferDeallocSequence_Tuple@@U_object@@View@@memset
                                                                                                                                                                                                                                    • String ID: Unable to allocate %d bytes
                                                                                                                                                                                                                                    • API String ID: 4010994401-4174463691
                                                                                                                                                                                                                                    • Opcode ID: 7e61cb02599470a5bac632c236b0f1a93314f5a3c2b21074ed6938da9452734b
                                                                                                                                                                                                                                    • Instruction ID: d28f800454d8d2320a1ff32c8d26a9afc28109277d65d6246ebd462285275e88
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7e61cb02599470a5bac632c236b0f1a93314f5a3c2b21074ed6938da9452734b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17513936B08B2182EB19DF16E82437C7BA8BB95B94F454131CA4D63760EE3CD8C5C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$DeallocStringfree$Bytes_ClearLong_MemoryOccurredSequence_Tuple@@U_object@@Voidmallocmemset
                                                                                                                                                                                                                                    • String ID: Integer OID must have high order word clear
                                                                                                                                                                                                                                    • API String ID: 676720102-606765175
                                                                                                                                                                                                                                    • Opcode ID: de2dcca5732e3a23aed4348600ffe8ddbce2aba4127e162ca19fc3ab5c34a23e
                                                                                                                                                                                                                                    • Instruction ID: 55e626c577db35a3dce062a05b75f9f21e2167d45806a93c3e0224850a7ae50e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: de2dcca5732e3a23aed4348600ffe8ddbce2aba4127e162ca19fc3ab5c34a23e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 95514D72B09B5286EB198F16D46433C7BA8FB85B94B858134CA6D67754DF3CE8E0C312
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Dealloc$CertEval_List_Thread$AppendCertificateCertificatesContextDuplicateEnumErrorError@@LastReferenceRestoreSaveStoreU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CertEnumCertificatesInStore
                                                                                                                                                                                                                                    • API String ID: 2638904092-715189387
                                                                                                                                                                                                                                    • Opcode ID: 47077f801fef8fac9147d80603385893828dbd1b782a91eabc7c87a2a2f81cc8
                                                                                                                                                                                                                                    • Instruction ID: 4940a28711b93f48779e71ee91be45dd883a5591de6b8c0cd14d75f5e3c2ab7f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 47077f801fef8fac9147d80603385893828dbd1b782a91eabc7c87a2a2f81cc8
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 05315E22B09A1285EB9D9F12E86433D6BA0BF49F95F884434DD1E67760EF3CE4C58302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_CertElementErr_Error@@KeywordsParseSerializeStoreStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CertSerializeCTLStoreElement$The certificate trust context has been closed$Unable to allocate %d bytes$|k:CertSerializeCTLStoreElement
                                                                                                                                                                                                                                    • API String ID: 2109812038-2971064172
                                                                                                                                                                                                                                    • Opcode ID: de8dde398ae78c295957fcfa59359cc83d6a0b0bd155b3edbd8fac4492aeb2c8
                                                                                                                                                                                                                                    • Instruction ID: bae38751db57016243707c4e39206a261167b3b0def0388bd11ef3fb088b6626
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: de8dde398ae78c295957fcfa59359cc83d6a0b0bd155b3edbd8fac4492aeb2c8
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: ED313F66B0865282EB08CF16F86427DAB61FBD8BD4B944031DE4D63728DE3CE5C58B02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_List_String
                                                                                                                                                                                                                                    • String ID: The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 1546712769-2422706626
                                                                                                                                                                                                                                    • Opcode ID: f09d8af2db4cd17d9f38a39360376edf5937c03c2441b411529ff95adbc23102
                                                                                                                                                                                                                                    • Instruction ID: 9d178283b9af608642c0e2bc5bbdc4eea53afa5705b03a44d085480ee12bf394
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f09d8af2db4cd17d9f38a39360376edf5937c03c2441b411529ff95adbc23102
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5D314F22B09A1282EF1D9B26E86423D67A1BF98F99F590030CD5E67754DE3CE8C18302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Eval_ThreadU_object@@$Arg_CertError@@FreeImportKeywordsMem_Object_ParseRestoreSaveStoreTupleU_object@@_Win_
                                                                                                                                                                                                                                    • String ID: OOk:PFXImportCertStore$PFXImportCertStore
                                                                                                                                                                                                                                    • API String ID: 3056532213-2473002513
                                                                                                                                                                                                                                    • Opcode ID: dee0cab6e4a2726392dd96a11b62f9b6614ebc90308ab1c22f7b647ea467379c
                                                                                                                                                                                                                                    • Instruction ID: 55802990188f5507e341208c104e6da5583e50439abf18ce92ada6148f4cdddb
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: dee0cab6e4a2726392dd96a11b62f9b6614ebc90308ab1c22f7b647ea467379c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 17410B36709A8682EB689F52F46077EB761FB84B84F444035DA9E52B54DE3CD4C8C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • PyBytes_FromStringAndSize.PYTHON39(?,?,?,?,00000000,00007FFDE3AD2956), ref: 00007FFDE3AD6EE4
                                                                                                                                                                                                                                    • _Py_BuildValue_SizeT.PYTHON39(?,?,?,?,00000000,00007FFDE3AD2956), ref: 00007FFDE3AD6F09
                                                                                                                                                                                                                                    • PyBytes_FromStringAndSize.PYTHON39(?,?,?,?,00000000,00007FFDE3AD2956), ref: 00007FFDE3AD6F19
                                                                                                                                                                                                                                    • _Py_BuildValue_SizeT.PYTHON39(?,?,?,?,00000000,00007FFDE3AD2956), ref: 00007FFDE3AD6F3C
                                                                                                                                                                                                                                    • _Py_BuildValue_SizeT.PYTHON39(?,?,?,?,00000000,00007FFDE3AD2956), ref: 00007FFDE3AD6F5F
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildValue_$Bytes_FromString
                                                                                                                                                                                                                                    • String ID: Algorithm$Data$ObjId$Parameters$PublicKey$UnusedBits${s:N, s:N}${s:N,s:k}${s:s, s:N}
                                                                                                                                                                                                                                    • API String ID: 2576831981-2447339682
                                                                                                                                                                                                                                    • Opcode ID: 99ca113903b7f22ecf04efa5fe5279bf58144d8ee4aca4f800969e1a07e9e57a
                                                                                                                                                                                                                                    • Instruction ID: 3295621c2e0f4c4964214e4af31283ecdbf1b04e951c42146cefb2bbbb4b57ab
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 99ca113903b7f22ecf04efa5fe5279bf58144d8ee4aca4f800969e1a07e9e57a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 45113A35B08A4A92EA08DF16E8601BC7B61FB48784F404132CA4D53724DF3CE5E9C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BuildDecodeSizeTuple_Unicode_Value_
                                                                                                                                                                                                                                    • String ID: ObjId$Value$ValueType${s:s, s:k, s:N}
                                                                                                                                                                                                                                    • API String ID: 1776507976-1124644876
                                                                                                                                                                                                                                    • Opcode ID: 04ced7ab794c338afd8da99092a9401a5fe1f6e5c6aa8a903c53a15212777fee
                                                                                                                                                                                                                                    • Instruction ID: 3fc61538325f3ef74103e8a3c0c69d8186aaf7fbf4930e3cd4da81917838dc48
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 04ced7ab794c338afd8da99092a9401a5fe1f6e5c6aa8a903c53a15212777fee
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 56414B72B08B5282DB598F12E46423E7BA4FB54788F844435DE8E27764DF3EE881C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$Arg_DeallocFlagsKeywords_MemoryParseSequence_SizeStringTupleTuple@@Type_U_object@@malloc
                                                                                                                                                                                                                                    • String ID: Object must be of type PyCERTSTORE$Object used to construct a CRYPT_DECRYPT_MESSAGE_PARA must be a dict$O|kk:CRYPT_DECRYPT_MESSAGE_PARA
                                                                                                                                                                                                                                    • API String ID: 729417699-695212532
                                                                                                                                                                                                                                    • Opcode ID: c40a9ac677471e5dfee7ef1300d3c37ff55b033968aadba39e4d0597e11ea2f4
                                                                                                                                                                                                                                    • Instruction ID: 1c2e31ffb7ffe4b5833dc55d407b6a2a9fc94e0fee97ad76745a92691e4f7580
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c40a9ac677471e5dfee7ef1300d3c37ff55b033968aadba39e4d0597e11ea2f4
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 20415A76B08B4282EB088F1AE86027C77A0FB84B84F844431CA5E57760DF3EE4E5C712
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildDeallocTuple_Value_$Bytes_FromString
                                                                                                                                                                                                                                    • String ID: PolicyIdentifier$PolicyQualifier$PolicyQualifierId$Qualifier${s:s, s:N}${s:s,s:N}
                                                                                                                                                                                                                                    • API String ID: 2693019599-3040507794
                                                                                                                                                                                                                                    • Opcode ID: c40761e8619662c7c6f8889781c5b399ce1f5e839ca413a449cc55ea7df54eb8
                                                                                                                                                                                                                                    • Instruction ID: a284eb4638a06b005a2c0449147fb155fa28ef5fdfeb48443fcb4db8eb6e49e5
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c40761e8619662c7c6f8889781c5b399ce1f5e839ca413a449cc55ea7df54eb8
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C0413732B09B4296DA189F12F86027D7BA4FB88B88F444539DA5E13764DF3CE5C5C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$String$Bytes_ClearDeallocLong_MemoryOccurredSequence_Tuple@@U_object@@Voidfreemallocmemset
                                                                                                                                                                                                                                    • String ID: Integer OID must have high order word clear
                                                                                                                                                                                                                                    • API String ID: 1899850966-606765175
                                                                                                                                                                                                                                    • Opcode ID: 6fb236d55c9a8ed41ec3529030a641665ba42c5ce6b128f64a434de98d6f0f8f
                                                                                                                                                                                                                                    • Instruction ID: af5f42b51e535e96e0759a3fd96b243eda7a2ba6c7fa1e1824d39cebd5b45c08
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6fb236d55c9a8ed41ec3529030a641665ba42c5ce6b128f64a434de98d6f0f8f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6E415A32B09B5282EB199F1AE42423C3BA8FB89F94B458131DA5D57794DF3CE8C1C312
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_List_String
                                                                                                                                                                                                                                    • String ID: The certificate trust context has been closed
                                                                                                                                                                                                                                    • API String ID: 1546712769-2425537300
                                                                                                                                                                                                                                    • Opcode ID: 272c226db98091af02844e04d1c66a553ccd33c87dd8fc30d0d086e0a13f1dd0
                                                                                                                                                                                                                                    • Instruction ID: 0660d0042066b754970e317e1ebd6186690a6c5ce7a310756946a87fed6ac23d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 272c226db98091af02844e04d1c66a553ccd33c87dd8fc30d0d086e0a13f1dd0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7D314E62B09B5282EB489B56F46027DA7A1FF88BD4F850035DA4E57B68DF3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_Eval_Object_ThreadU_object@@$Arg_CertCheckDeallocEnumError@@FreeKeywordsList_OccurredParseRestoreSaveSequence_StoreStringSystemTupleWin_
                                                                                                                                                                                                                                    • String ID: CertEnumSystemStore$k|O:CertEnumSystemStore
                                                                                                                                                                                                                                    • API String ID: 1559264201-1448371782
                                                                                                                                                                                                                                    • Opcode ID: 5569fefaff56251cb759fa99afcbdf4e248b8cfae2aa0512b6be101fdfa73a2d
                                                                                                                                                                                                                                    • Instruction ID: c780d6e65660f66e34be2f5f9d8f0f0065f60580302af2aea54ab43d7a4541f0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5569fefaff56251cb759fa99afcbdf4e248b8cfae2aa0512b6be101fdfa73a2d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AC314B71B08B5282EB588F12E46437A7BA0FF94B84F840135DA8E53A64DF3CE5C5CB42
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertCertificateContextErr_Error@@KeywordsParseRestoreSaveStringSubjectTupleU_object@@VerifyWin_
                                                                                                                                                                                                                                    • String ID: CertVerifySubjectCertificateContext$Object must be of type PyCERT_CONTEXT$Ok:CertVerifySubjectCertificateContext$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 342392830-4012586357
                                                                                                                                                                                                                                    • Opcode ID: 8f4473a63bf541a6efebb3345a35f2dcf88c8096f3c23e3473d0c6db43eb7278
                                                                                                                                                                                                                                    • Instruction ID: 9fdf77db9cf4034e8101393787452b7218d8594241d4f5d53f7f088aaed7453d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8f4473a63bf541a6efebb3345a35f2dcf88c8096f3c23e3473d0c6db43eb7278
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 90316165B08A5281EF08DF56F8602BD6B61FF94B94F884032CA4D67764DE3CD4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferBuildFreeFromLong_Mem_ReferenceValueView@@Voidmalloc
                                                                                                                                                                                                                                    • String ID: CertStore$ContentType$Context$FormatType$Msg$MsgAndCertEncodingType${s:k,s:k,s:k,s:N,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 3158920082-3520626638
                                                                                                                                                                                                                                    • Opcode ID: 04cc4bb954d1bc386e5f9aa4a3c32e661a57f4db99395f2798d2b2f2e023ec3f
                                                                                                                                                                                                                                    • Instruction ID: c03dde158b414a001e47ce7ae533615f4f2d165bde36cbea9fc001d318542a0d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 04cc4bb954d1bc386e5f9aa4a3c32e661a57f4db99395f2798d2b2f2e023ec3f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E6310636B09B5585E7198F52E8A027C7BB4FB48B98B540136CA5E23B68DF3CE4C1C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_Eval_Thread$Arg_CertCloseDeallocError@@KeywordsParseRestoreSaveStoreStringTupleU_object@@WarnWin_
                                                                                                                                                                                                                                    • String ID: Certificate store is already closed$PyCERTSTORE::CertCloseStore$The Flags param to CertCloseStore is deprecated; a non-zero value is likely to crash$|k:PyCERTSTORE::CertCloseStore
                                                                                                                                                                                                                                    • API String ID: 728906781-504232729
                                                                                                                                                                                                                                    • Opcode ID: e5f7c9216858f9da727f35fa8e532b6227dd5c006bfaf42bae309fe178d631b4
                                                                                                                                                                                                                                    • Instruction ID: 25a24016802f953e9c76edf67f91eebd65b5b6f140cebf00b0062c754f68918a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e5f7c9216858f9da727f35fa8e532b6227dd5c006bfaf42bae309fe178d631b4
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 54316CB6B08A6282EB188F16F86423D6760FB98BD4B440131CA5D67764DF3CE4D58342
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_ThreadU_object@@$Arg_CertDeallocEnumErr_Error@@FreeKeywordsList_Mem_Object_OccurredParsePhysicalRestoreSaveStoreTupleWin_
                                                                                                                                                                                                                                    • String ID: CertEnumPhysicalStore$Ok:CertEnumPhysicalStore
                                                                                                                                                                                                                                    • API String ID: 3491648194-703072266
                                                                                                                                                                                                                                    • Opcode ID: 06d9bd409a2aa62e02048787c1f70e3a50ce6da5aded3aa87d741c577331914a
                                                                                                                                                                                                                                    • Instruction ID: 8a5fd2908bf1b14445434b3cca05f9d8acfcfb2c0c979390b1406e0edec3c079
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 06d9bd409a2aa62e02048787c1f70e3a50ce6da5aded3aa87d741c577331914a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F0310336B18B1281EB588F22E8A477D3BA0AF48BC4F854135DA1E63754DF3CE5C58752
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_String$Arg_FlagsKeywords_ParseSizeTupleType_
                                                                                                                                                                                                                                    • String ID: CRYPT_SIGN_MESSAGE_PARA: HashAuxInfo parm not yet supported$CRYPT_SIGN_MESSAGE_PARA: MsgCrl parm not yet supported$OO|OOOOOkkk:CRYPT_SIGN_MESSAGE_PARA$Object must be of type PyCERT_CONTEXT$Object used to construct CRYPT_VERIFY_MESSAGE_PARA structure must be a dict$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 2943021597-2519308533
                                                                                                                                                                                                                                    • Opcode ID: 644987444f13ef870175dfd43e17315da7fbbacb1bf5d1f94cba428b16c4a40e
                                                                                                                                                                                                                                    • Instruction ID: 2f33726a470a4625fd1c181c62dfec9a74f16ad1d99184be7132a33a243d55a7
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 644987444f13ef870175dfd43e17315da7fbbacb1bf5d1f94cba428b16c4a40e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4B615B62B08B8281EB188F15E4903BD77A5FB84788F805132DA8C537A4EF3DD9D9C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • ?PyWinSequence_Tuple@@YAPEAU_object@@PEAU1@PEAK@Z.PYWINTYPES39(?,?,?,00007FFDE3AD7E7C), ref: 00007FFDE3AD8435
                                                                                                                                                                                                                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE3AD7E7C), ref: 00007FFDE3AD844B
                                                                                                                                                                                                                                    • PyErr_NoMemory.PYTHON39(?,?,?,00007FFDE3AD7E7C), ref: 00007FFDE3AD8459
                                                                                                                                                                                                                                    • _Py_Dealloc.PYTHON39(?,?,?,00007FFDE3AD7E7C), ref: 00007FFDE3AD846D
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DeallocErr_MemorySequence_Tuple@@U_object@@malloc
                                                                                                                                                                                                                                    • String ID: Object must be of type PyCERT_CONTEXT$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 2500920456-1580614774
                                                                                                                                                                                                                                    • Opcode ID: d85444669ea4fee1124ae3dc1d0ca433439a0b735b7cbefd42c819c25a45f93d
                                                                                                                                                                                                                                    • Instruction ID: 7b1abebf003bcbcd730f9d45c9db92bbe474eb98f6c4c3575063b4d80af885db
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d85444669ea4fee1124ae3dc1d0ca433439a0b735b7cbefd42c819c25a45f93d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D0414872B08B1282EB19DF16E46863C7BA9FB94B94B494031DA5D53750EF3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertCertificateContextErr_Error@@KeywordsParseReferenceRestoreSaveStoreStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CertAddCertificateContextToStore$Object must be of type PyCERT_CONTEXT$Ok:CertAddCertificateContextToStore$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 3115178827-3904690713
                                                                                                                                                                                                                                    • Opcode ID: 44255d4cfb8de91b4fc3e1eb829453dc14884bb6e9d4da73c5586501a62c7794
                                                                                                                                                                                                                                    • Instruction ID: e0af193a00595778c3cc3b930789736367b0bcdff284dd2331db99b6c42579ed
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 44255d4cfb8de91b4fc3e1eb829453dc14884bb6e9d4da73c5586501a62c7794
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 96313962B09B1681EB498B52F86437D6BA1FB84BD5F484032DE4E57764DE3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertErr_Error@@KeywordsLinkParseReferenceRestoreSaveStoreStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CertAddCertificateLinkToStore$Object must be of type PyCERT_CONTEXT$Ok:CertAddCertificateLinkToStore$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 2075955176-2827904824
                                                                                                                                                                                                                                    • Opcode ID: 961c2b75728334922e1c9aa049d5e92965dae6a12e572654339f103f722110b4
                                                                                                                                                                                                                                    • Instruction ID: 7b38021d26758647ab4664a9a9c70fcfee872ce165fa466c01d2c38954651534
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 961c2b75728334922e1c9aa049d5e92965dae6a12e572654339f103f722110b4
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4A313662B09B1681EB498B52E8603796BA1FB94BD9F484032DE4E17768DF3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertContextErr_Error@@FromKeywordsLong_ParseReferenceRestoreSaveStoreStringTupleU_object@@VoidWin_
                                                                                                                                                                                                                                    • String ID: CertAddCTLContextToStore$Object must be of type PyCTL_CONTEXT$Ok:CertAddCTLContextToStore
                                                                                                                                                                                                                                    • API String ID: 4091638707-1852074204
                                                                                                                                                                                                                                    • Opcode ID: 56d80acb5e9c5b808d9bb6c7d2f640b85b39fa6e2fa357b8f4c357df230535b3
                                                                                                                                                                                                                                    • Instruction ID: 1b56b3baa04b7ded0800123466b88afb6e35324e9710e73164de82df089a4c11
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 56d80acb5e9c5b808d9bb6c7d2f640b85b39fa6e2fa357b8f4c357df230535b3
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: ED315762B09B1681EB098F16E85437D6BA1FB88BD5F480032DE4E53768DE3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertErr_Error@@FromKeywordsLinkLong_ParseReferenceRestoreSaveStoreStringTupleU_object@@VoidWin_
                                                                                                                                                                                                                                    • String ID: CertAddCTLLinkToStore$Object must be of type PyCTL_CONTEXT$Ok:CertAddCTLLinkToStore
                                                                                                                                                                                                                                    • API String ID: 4118693733-2167048104
                                                                                                                                                                                                                                    • Opcode ID: 1a20be30080f5bfdd4cb18eca32e2328ce31d2efd68beb1fc74bbe570515d578
                                                                                                                                                                                                                                    • Instruction ID: a860d422afad926d806ac4813fc7be0fa496272a356687f06a4ead9a9802d616
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1a20be30080f5bfdd4cb18eca32e2328ce31d2efd68beb1fc74bbe570515d578
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A0314B66B09B5681EB098F16F85027D6BA1FB88BD5F484031DE4E53764DE3CE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: From$Bytes_DecodeObject_SizeStringU_object@@Unicode_
                                                                                                                                                                                                                                    • String ID: ObjId$Value$ValueType${s:s, s:k, s:N}
                                                                                                                                                                                                                                    • API String ID: 3087831822-1124644876
                                                                                                                                                                                                                                    • Opcode ID: 56ada49e809e0b2863e084ac6f4cf7357208d309a5429115c898820cc956a3a2
                                                                                                                                                                                                                                    • Instruction ID: 2e7443b37218928c57b58c0521c0b4c346c861409740065428ad8cb860c2ad60
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 56ada49e809e0b2863e084ac6f4cf7357208d309a5429115c898820cc956a3a2
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 40313B32B08B9286DA1C8F12E46467D6BA1FB48B84F490435EE4D67754DF3EE5C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferBuildFreeMem_ReferenceValueView@@malloc
                                                                                                                                                                                                                                    • String ID: CertStore$ContentType$Context$FormatType$Msg$MsgAndCertEncodingType${s:k,s:k,s:k,s:N,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 3234142203-3520626638
                                                                                                                                                                                                                                    • Opcode ID: d6189efe4648b7480aa87e3adb22281ba501001b4f59008ab6af41022abf8bfd
                                                                                                                                                                                                                                    • Instruction ID: 77d7565e2061452f47dd4cce18e68f71b2d7b54af8abf6e5a734d89d94ea539e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d6189efe4648b7480aa87e3adb22281ba501001b4f59008ab6af41022abf8bfd
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0B312836B09B5585E7198F52E8A027C7BB4FB48B98B540136CA5E23B64DF3CE4C1C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Eval_Thread$Arg_Bool_FreeFromKeywordsLongMem_Object_ParsePasswordRestoreSaveTupleU_object@@U_object@@_Verify
                                                                                                                                                                                                                                    • String ID: OOk:PFXVerifyPassword
                                                                                                                                                                                                                                    • API String ID: 1593006440-1626740757
                                                                                                                                                                                                                                    • Opcode ID: 3aa1bffbdbc4d8825c7815332cea1dfda960561bf381ead775259b5ac7509be6
                                                                                                                                                                                                                                    • Instruction ID: 14b9fdf7adb836dfa78e4daf7652e0ddb847f9f926d4652775d59931002810df
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3aa1bffbdbc4d8825c7815332cea1dfda960561bf381ead775259b5ac7509be6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6C31FA36708B9682DB648F56F4A077EBB61FB84785F804435DA8E53B54DE3CD488CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: FromLong_Void$BufferBuildFreeMem_ReferenceValueView@@
                                                                                                                                                                                                                                    • String ID: CertStore$ContentType$Context$FormatType$Msg$MsgAndCertEncodingType${s:k,s:k,s:k,s:N,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 3720317137-3520626638
                                                                                                                                                                                                                                    • Opcode ID: f11229e198d073a301615d606054cfb0774c47dfbd7312a7106256a7eb2f15c1
                                                                                                                                                                                                                                    • Instruction ID: faf45a7f20db2a647938b26bd872447447d1efb4ab9815a0b8d7c8e8a8436e28
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f11229e198d073a301615d606054cfb0774c47dfbd7312a7106256a7eb2f15c1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 92212736B09B5585EB158B52E8A02BC7BB4FB48B94B500532DE5E23B64DF3CE4C1C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildValue_$Bytes_DeallocFromStringTuple_
                                                                                                                                                                                                                                    • String ID: PolicyIdentifier$PolicyQualifier$PolicyQualifierId$Qualifier${s:s, s:N}${s:s,s:N}
                                                                                                                                                                                                                                    • API String ID: 739664917-3040507794
                                                                                                                                                                                                                                    • Opcode ID: 3483e122d4815596712ee34e2f56b549e838a5e0effa080862a2e5323dcdc398
                                                                                                                                                                                                                                    • Instruction ID: a175bfada41504a70c10b5639e67fce68ae6dc907e05fbd56b21c897c1966bfe
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3483e122d4815596712ee34e2f56b549e838a5e0effa080862a2e5323dcdc398
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: A3216D36B18B5682DB18DF11E85027D7B64FB88B88B444436DA9D23764DF3CE1D5C741
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferEval_ThreadView@@$Arg_CertCertificateEncodedError@@KeywordsParseRestoreSaveStoreTupleU_object@@U_object@@_Win_
                                                                                                                                                                                                                                    • String ID: PyCERTSTORE::CertAddEncodedCertificateToStore$kOk:CertAddEncodedCertificateToStore
                                                                                                                                                                                                                                    • API String ID: 3039583314-3378692726
                                                                                                                                                                                                                                    • Opcode ID: 9f6297f2ee60b737441bcf87815c78ee37b30ec4186fc2b3856415661ed3f07a
                                                                                                                                                                                                                                    • Instruction ID: 6b412fff266b28fb2e389fa72f28e7f953c4eefe25026f5c463e1a70af2d35f1
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9f6297f2ee60b737441bcf87815c78ee37b30ec4186fc2b3856415661ed3f07a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 98414432B08B9282E7588B12E85477E7BA4FB98B84F544132DA5D63B54DF3CE885C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_List_String
                                                                                                                                                                                                                                    • String ID: The certificate trust context has been closed
                                                                                                                                                                                                                                    • API String ID: 1546712769-2425537300
                                                                                                                                                                                                                                    • Opcode ID: ef77106fb55b3bf5186b01972ef90ea769ee0cdede0a89fa59354dce134cb465
                                                                                                                                                                                                                                    • Instruction ID: 003d797ecd60371621dee8eb9c347d8c7ca9031a11f0d19580cb24e8aaf942d8
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ef77106fb55b3bf5186b01972ef90ea769ee0cdede0a89fa59354dce134cb465
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B9216F21F09A1381EB5C8B66E43023C27A5AF98B98F890035DD4E67764EE3CE4D18302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Object_$Eval_FreeThreadU_object@@$Arg_CertError@@KeywordsParseRestoreSaveStoreSystemTupleUnregisterWin_
                                                                                                                                                                                                                                    • String ID: CertUnregisterSystemStore$Ok:CertUnregisterSystemStore
                                                                                                                                                                                                                                    • API String ID: 76350630-1006014767
                                                                                                                                                                                                                                    • Opcode ID: 1376975b54a55cb718b477a6d577e4b133870b74e81b29178a49d3d99b7b55bd
                                                                                                                                                                                                                                    • Instruction ID: 64d3851fd9d1ceb18e57695f36be7f83e6d17ed423dd54fae84cd9508a3f79d8
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 1376975b54a55cb718b477a6d577e4b133870b74e81b29178a49d3d99b7b55bd
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 86211C22B18B5182EB449F56F8A467EBB64FB88BD4F444031E98E53B24DE3CD4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • pvPara must be represented as a sequence of (PyHKEY, string/unicode), xrefs: 00007FFDE3AD6881
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Sequence_$DeallocItemObject_U_object@@$CheckErr_SizeStringY__@@@
                                                                                                                                                                                                                                    • String ID: pvPara must be represented as a sequence of (PyHKEY, string/unicode)
                                                                                                                                                                                                                                    • API String ID: 3671526842-570033640
                                                                                                                                                                                                                                    • Opcode ID: e27d0aedd0b239c40cefddc9999d32e1b4baa49d0f6ec8b0ff8efda6354c3d6b
                                                                                                                                                                                                                                    • Instruction ID: fe78615e5a9dc7910bed1c647d8ffebfff7c91e7a7926dad47c191cdef256d25
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e27d0aedd0b239c40cefddc9999d32e1b4baa49d0f6ec8b0ff8efda6354c3d6b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 67214221B08A1381EB588B66E86433D6BA1EB88BC8F485030DA4E57724DE3CD4C58302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertDeallocEnumErr_Error@@KeywordsList_LocationOccurredParseRestoreSaveStoreSystemTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CertEnumSystemStoreLocation$|k:CertEnumSystemStoreLocation
                                                                                                                                                                                                                                    • API String ID: 1777273059-4282623423
                                                                                                                                                                                                                                    • Opcode ID: 66e77dae20d805b98d1bac16d8d6d49fa967f9ab67997b32c93067f584ccbf65
                                                                                                                                                                                                                                    • Instruction ID: fa240646c4f4ec28e236879c098e59718344d54f114060cd82c81c9953455303
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 66e77dae20d805b98d1bac16d8d6d49fa967f9ab67997b32c93067f584ccbf65
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 33113A25B09B6281EB4D9F62F8642BDABA0BF58BD4F484035C94E63764DE3DE4C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 349153199-0
                                                                                                                                                                                                                                    • Opcode ID: e766c273d7f94126e43b8ed061a087085ea47b0d730ad968d150953494356d8c
                                                                                                                                                                                                                                    • Instruction ID: fb87f4097651bc5b806e9b617547023c141d3c83d4324dedb6428d7b027b1e09
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: e766c273d7f94126e43b8ed061a087085ea47b0d730ad968d150953494356d8c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 36817060F1C24346FA5C9B67A4613BE2E90AF96B8CF844035D90DA7796DE3CE8C58702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: ReadyType_$Module_$Create2DictEnsure@@Globals_Tuple_
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 740114199-0
                                                                                                                                                                                                                                    • Opcode ID: aed4d11b6c6b9b57ddbb0fe125a150e05ec895b6a5efb3dcb878fd7f6fce4112
                                                                                                                                                                                                                                    • Instruction ID: 65b6eb6d99453a12f7b0ca6815ce2c4d3d7c47f7efbe19b256a33a7a47921356
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: aed4d11b6c6b9b57ddbb0fe125a150e05ec895b6a5efb3dcb878fd7f6fce4112
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3A21EC21B1891682EA1C9766DC7863C6B51AF447A5F940731D03EA52F0FF2CE9DA8313
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Object_ThreadU_object@@$Arg_CertCheckErr_Error@@FreeKeywordsParseRegisterRestoreSaveSequence_StoreStringSystemTupleWin_
                                                                                                                                                                                                                                    • String ID: CertRegisterSystemStore$Ok:CertRegisterSystemStore
                                                                                                                                                                                                                                    • API String ID: 285079833-494802307
                                                                                                                                                                                                                                    • Opcode ID: 6f0fb11f37a97c232c1c1782edd83478b46658ed0b356d39deab59a5b81560cb
                                                                                                                                                                                                                                    • Instruction ID: 6ed83a3a21863610434d92ca06ab6c109d4916a682fb7e02e62ab2b82908ad47
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6f0fb11f37a97c232c1c1782edd83478b46658ed0b356d39deab59a5b81560cb
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F7314F32B18A5182E7549F26F4A067E7BA1FB84BD4F940035EA4E57A68DF3CD4C5CB01
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertCollectionErr_Error@@KeywordsParseRestoreSaveStoreStringTupleU_object@@Win_
                                                                                                                                                                                                                                    • String ID: CertAddStoreToCollection$Object must be of type PyCERTSTORE$O|kk:CertAddStoreToCollection
                                                                                                                                                                                                                                    • API String ID: 1239160312-826948340
                                                                                                                                                                                                                                    • Opcode ID: d77cdf863a1c92755d027dbe610dee69239bf2e4a8479f602c71efa81b5788f8
                                                                                                                                                                                                                                    • Instruction ID: d5e6b9f7ae67c03e0155319c4adf47d54df7f780c91d2dc37a93437ee7e3678b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d77cdf863a1c92755d027dbe610dee69239bf2e4a8479f602c71efa81b5788f8
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: AC310D72B08B1682EB04CF56E89457D37A2FB98BC4B554132DA5D63764DE3CE8C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: From$Bool_BuildBytes_LongSizeStringTuple_Value
                                                                                                                                                                                                                                    • String ID: Critical$ObjId$Value${s:s,s:N,s:N}
                                                                                                                                                                                                                                    • API String ID: 3744456896-3786422732
                                                                                                                                                                                                                                    • Opcode ID: a4d76162ca1b20d39c4bdb3706fc8f2361eabe912bafd6ecff1bc1b81488eae6
                                                                                                                                                                                                                                    • Instruction ID: decb1ea490690987b0f0909a481c8bfe25b19c96f359994a76661e836898deef
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a4d76162ca1b20d39c4bdb3706fc8f2361eabe912bafd6ecff1bc1b81488eae6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5A217A76F09B0182EB189B26E42427D6BA2FB89B95F490135DE8D23758DF3CE4C1C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$Eval_Thread$Arg_BlobBool_FromKeywordsLongParseRestoreSaveTupleU_object@@_
                                                                                                                                                                                                                                    • String ID: O:PFXIsPFXBlob
                                                                                                                                                                                                                                    • API String ID: 4233107956-3232074968
                                                                                                                                                                                                                                    • Opcode ID: 73163f93fff45c1a3452ace7f939f7e6a6e9ac620aaa13fa026fe3b6f7087a92
                                                                                                                                                                                                                                    • Instruction ID: 3cac93630840d406eb856a8d6898793de15b3462c510503a3f7f5cd1616055ac
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 73163f93fff45c1a3452ace7f939f7e6a6e9ac620aaa13fa026fe3b6f7087a92
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 60111225B08B9282DB649B22F85477D77A4FB89B84F840035DA4E53B54DF3CD0C8CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_ThreadU_object@@$Arg_CertControlError@@KeywordsObject_ParseRestoreSaveStoreTupleWin_
                                                                                                                                                                                                                                    • String ID: CertControlStore$kkO:CertControlStore
                                                                                                                                                                                                                                    • API String ID: 2053635168-113208596
                                                                                                                                                                                                                                    • Opcode ID: ad48bee6abddda56a950a0224d22d09f6fa7403e175fb0740d9d74633a2ee1e7
                                                                                                                                                                                                                                    • Instruction ID: bd8f228978d100fa44384105ee3d7a0c951df92e93cf602079e4385aa7b565b0
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: ad48bee6abddda56a950a0224d22d09f6fa7403e175fb0740d9d74633a2ee1e7
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F2213972B08B1582EB088F56E8A467D3BA1FB88BD4B540136DA5E53724DF3CD4D5CB42
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$BufferCertErr_ErrorFreeLastObject_OpenRestoreSaveStoreView@@Warn
                                                                                                                                                                                                                                    • String ID: Para ignored for CERT_STORE_PROV_MEMORY
                                                                                                                                                                                                                                    • API String ID: 1900364133-3327432420
                                                                                                                                                                                                                                    • Opcode ID: 5c0b35fee59cf6bf39444aaf8b9850b978c92ba702af30424e7946461341fc00
                                                                                                                                                                                                                                    • Instruction ID: 0576e16f2884073143502d12c13ec3bacebc25e377672c505f3ab74c9b86122e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5c0b35fee59cf6bf39444aaf8b9850b978c92ba702af30424e7946461341fc00
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0E11ED25B09A5289F7198F62E86077C2B61BB44BD8F440135CD0E77B54CF3CE5C68302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$CertErr_Error@@IntendedRestoreSaveStringU_object@@UsageWin_
                                                                                                                                                                                                                                    • String ID: CertGetIntendedKeyUsage$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 1728261811-2907928091
                                                                                                                                                                                                                                    • Opcode ID: 3c4704f5b7e485e527f78852a90e70fb4b8a4f8f93a513035794a3e148f50409
                                                                                                                                                                                                                                    • Instruction ID: a10f9f3a98c7327d8134feebdf1cd6f829d897cbc853f099bc029306f1c11028
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 3c4704f5b7e485e527f78852a90e70fb4b8a4f8f93a513035794a3e148f50409
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2C015EA1B18A4282EF189F63F8A467D2761FF98B89F081031CA0E17764DE3CD4D9C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$Bytes_FromString$BuildValue_
                                                                                                                                                                                                                                    • String ID: CertIssuer$CertSerialNumber$KeyId${s:N, s:N, s:N}
                                                                                                                                                                                                                                    • API String ID: 2781604664-3203442839
                                                                                                                                                                                                                                    • Opcode ID: 59b3f26f0880a11068df7df471b8df2117eb6e582c88bd0bd7ebd96a4c478538
                                                                                                                                                                                                                                    • Instruction ID: 553936870e224f5978cffccddfab50585a2413f88d2a013b987fd4c65b3daef8
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 59b3f26f0880a11068df7df471b8df2117eb6e582c88bd0bd7ebd96a4c478538
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 4101A536708B4296D6248B12F85016EB774FB88BD0B544231DA9E53B28DF3CE5D6C741
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildBytes_FromStringValue_
                                                                                                                                                                                                                                    • String ID: ExtraInfo$GroupId$Name$OID$Value${s:s,s:u,s:k,s:k,s:N}
                                                                                                                                                                                                                                    • API String ID: 1860207225-1172115252
                                                                                                                                                                                                                                    • Opcode ID: 0487b27e0bed9d540938853c90e5a0e2c4fefd8d443bf1b033a660af3be1d094
                                                                                                                                                                                                                                    • Instruction ID: 2cf6007100df63c031319b43dd12c6e4a7200445d59697cde30f0d67aa656422
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0487b27e0bed9d540938853c90e5a0e2c4fefd8d443bf1b033a660af3be1d094
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6D0104B6B08B4586DB14CF15F4902A97BB4FB48B45B500132DA8D53328EF3CD5E5CB41
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    • |kOOO:CRYPT_VERIFY_MESSAGE_PARA, xrefs: 00007FFDE3AD7B68
                                                                                                                                                                                                                                    • Object used to construct CRYPT_VERIFY_MESSAGE_PARA structure must be a dict or None, xrefs: 00007FFDE3AD7B29
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$Arg_FlagsKeywords_MemoryParseSizeStringTupleType_malloc
                                                                                                                                                                                                                                    • String ID: Object used to construct CRYPT_VERIFY_MESSAGE_PARA structure must be a dict or None$|kOOO:CRYPT_VERIFY_MESSAGE_PARA
                                                                                                                                                                                                                                    • API String ID: 4169705880-4156433631
                                                                                                                                                                                                                                    • Opcode ID: 32b5c823e691e0d3e5e54a325c8dbdf220f2583a63d5558a5200e3605bfc53f1
                                                                                                                                                                                                                                    • Instruction ID: adadf259a895ecf8ca40d8f7fece3912c51eacbed16b915600b347bbd3e9a0a6
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 32b5c823e691e0d3e5e54a325c8dbdf220f2583a63d5558a5200e3605bfc53f1
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 5D312672B09B0681EB088F56E85027977A4FB48B84F444131DA8E57764EF3DD4D6C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferView@@$?init@Arg_Err_FlagsKeywords_ParseSizeStringTupleType_U_object@@_
                                                                                                                                                                                                                                    • String ID: Object used to construct a CRYPT_BIT_BLOB must be a dict$Ok:CRYPT_BIT_BLOB
                                                                                                                                                                                                                                    • API String ID: 3912244484-1057895879
                                                                                                                                                                                                                                    • Opcode ID: 98872dd2b432b0f759ba4e913adfeb9f39a17c7bc2f79f0f2499ff0d07949e6f
                                                                                                                                                                                                                                    • Instruction ID: 0d0501129e8c48bff09d89a283ed407de7840dbe755ad68c591df2c929be593f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 98872dd2b432b0f759ba4e913adfeb9f39a17c7bc2f79f0f2499ff0d07949e6f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FC214632B18A4181EB14CF22E86077A77A1FB88B84F445132EA8D93728DF3DD5C5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertCollectionErr_FromKeywordsParseRemoveRestoreSaveStoreStringTuple
                                                                                                                                                                                                                                    • String ID: O:CertRemoveStoreFromCollection$Object must be of type PyCERTSTORE
                                                                                                                                                                                                                                    • API String ID: 774358558-3549291170
                                                                                                                                                                                                                                    • Opcode ID: cb2907bfb4edc77cf4b65448edff85dd8b1f5807b70c90853a47c004294b495a
                                                                                                                                                                                                                                    • Instruction ID: 6b352f48c48aeb36adc4729ed390180d5e2ee13eea12f5be440e34e9a8939bd4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: cb2907bfb4edc77cf4b65448edff85dd8b1f5807b70c90853a47c004294b495a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 0D111766B08A5681EB188B57F86423D6B71FB98BC4B944032DE5E67764DE3CE4C5C302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Bool_FromLong$BuildSizeValue_
                                                                                                                                                                                                                                    • String ID: PathLenConstraint$fCA$fPathLenConstraint${s:N, s:N, s:k}
                                                                                                                                                                                                                                    • API String ID: 3942119401-3721055901
                                                                                                                                                                                                                                    • Opcode ID: a613d2959a008d897220e0e03f2d00a29dce8f4fea692f90ce72959b663b13e0
                                                                                                                                                                                                                                    • Instruction ID: ea8e9e9acd6c67efe3b322c44b314548b0a19e4e676a70a2b4a602f42fc0410a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a613d2959a008d897220e0e03f2d00a29dce8f4fea692f90ce72959b663b13e0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 30F03732B08B46D6D7088B12F46017C7B60FB48B84B444035DA5E13764EF3CD5C9CB02
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • ?PyWinSequence_Tuple@@YAPEAU_object@@PEAU1@PEAK@Z.PYWINTYPES39(?,?,?,00007FFDE3AD7E95), ref: 00007FFDE3AD8240
                                                                                                                                                                                                                                    • malloc.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE3AD7E95), ref: 00007FFDE3AD825E
                                                                                                                                                                                                                                    • PyErr_NoMemory.PYTHON39(?,?,?,00007FFDE3AD7E95), ref: 00007FFDE3AD826D
                                                                                                                                                                                                                                    • _Py_Dealloc.PYTHON39(?,?,?,00007FFDE3AD7E95), ref: 00007FFDE3AD82C3
                                                                                                                                                                                                                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE3AD7E95), ref: 00007FFDE3AD8332
                                                                                                                                                                                                                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE3AD7E95), ref: 00007FFDE3AD834A
                                                                                                                                                                                                                                    • free.API-MS-WIN-CRT-HEAP-L1-1-0(?,?,?,00007FFDE3AD7E95), ref: 00007FFDE3AD836E
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: free$DeallocErr_MemorySequence_Tuple@@U_object@@malloc
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2165968868-0
                                                                                                                                                                                                                                    • Opcode ID: bc84e8d98e269002060b8cbf1414a2b3c63dd0bf1d68f1ab6de42068202bbd10
                                                                                                                                                                                                                                    • Instruction ID: 86a793c0815777b7a36c7fa9dc8c891db974257204bb987dceeb7cdfd5215e74
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: bc84e8d98e269002060b8cbf1414a2b3c63dd0bf1d68f1ab6de42068202bbd10
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 13416832B09B4282EB188F56E86423D7BA8FF88B94B854135DE5E27744DF38E4D18742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_Err_FlagsKeywords_ParseSizeStringTupleType_
                                                                                                                                                                                                                                    • String ID: EncryptionAuxInfo must be None$Object used to construct a CRYPT_ENCRYPT_MESSAGE_PARA must be a dict$O|OOkkk:CRYPT_DECRYPT_MESSAGE_PARA
                                                                                                                                                                                                                                    • API String ID: 4246520648-2361109964
                                                                                                                                                                                                                                    • Opcode ID: b3705ebb2ff366f03094f3a0989ac2a321f363db58b5af3ae26ebc7303b17d3e
                                                                                                                                                                                                                                    • Instruction ID: a2f04ad961dfdaa898a6d0022754191bad057807f378de91d3fd469991000f05
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: b3705ebb2ff366f03094f3a0989ac2a321f363db58b5af3ae26ebc7303b17d3e
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 9E3148B2B09A4281EB588F15F8502BD7BA4FB84B84F844135DA8D97764EF3CD5D5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BufferEval_ThreadView@@$?init@CertErr_ErrorError@@FreeFromLastLong_Object_OpenReferenceRestoreSaveStoreStringU_object@@U_object@@_VoidWin_
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3959075145-0
                                                                                                                                                                                                                                    • Opcode ID: 8d9836175a48c1df50a0c46cd78cb25d353175f6745ae0f67e237b185b9d7378
                                                                                                                                                                                                                                    • Instruction ID: c3c64f764ccf9ee5b923b382d0b042373e250c1dbf9adb8b1f360db4c2cb942d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8d9836175a48c1df50a0c46cd78cb25d353175f6745ae0f67e237b185b9d7378
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: B5210E36B08A56D9F7188F62E4507BC3771AB48B98B440135CE0E77B58DF38D5C68342
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Object_ThreadU_object@@$BufferCertErr_ErrorError@@FreeFromLastLong_OpenReferenceRestoreSaveStoreStringView@@VoidWin_
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 504009513-0
                                                                                                                                                                                                                                    • Opcode ID: 2ef68e3d1586ad91d28ed92f23037d2eef4aed084c26b958645919115f6c4339
                                                                                                                                                                                                                                    • Instruction ID: 46848da09094f63f8205c5aad211f955ce0e72fdef470bfc72ce63b125314e1c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2ef68e3d1586ad91d28ed92f23037d2eef4aed084c26b958645919115f6c4339
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: FC11FC26B08A56C9F7298F62E86077C2B61AB44BD8F440135CD0E77B58CE3CE5C68702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_Err_FlagsFormatObject_ParseSizeTuple_Type_U_object@@
                                                                                                                                                                                                                                    • String ID: CRYPTPROTECT_PROMPTSTRUCT must be None or a tuple (got %s)$k|O&O
                                                                                                                                                                                                                                    • API String ID: 2888567994-1039745384
                                                                                                                                                                                                                                    • Opcode ID: 6828951d123d311d73e98e1a0888fd93dc3c6712516086273634f914988f59e0
                                                                                                                                                                                                                                    • Instruction ID: 5e5ebde859652e72cff4e39f16a9bdbd10f44dffb75cf4d881fd68e1b3408d1a
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 6828951d123d311d73e98e1a0888fd93dc3c6712516086273634f914988f59e0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3E113672B08A8682DB048F66E8602ACB7B0FB89B88B544132DA5D57724DF3CD1D8C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Object_Thread$BufferCertErrorFreeLastOpenRestoreSaveStoreU_object@@View@@
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2258189182-0
                                                                                                                                                                                                                                    • Opcode ID: 5472acdf5cb24d428fbd87acd7c237e13770622edd79334f7cb48dbcc181153c
                                                                                                                                                                                                                                    • Instruction ID: 7ba227a384297b685227cc45fdf25415dc8ee00b8515a45c5336c7581061f8a4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 5472acdf5cb24d428fbd87acd7c237e13770622edd79334f7cb48dbcc181153c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6411EF25B08A52C9F7698F62E86477C2B71AB44BD8B540135CD0E77B58DF3CE5C69302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Object_Thread$BufferCertErrorFreeLastOpenRestoreSaveStoreU_object@@View@@Y__@@@
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2272792605-0
                                                                                                                                                                                                                                    • Opcode ID: 519525671760cdf79f322ad0106568b167883bddd48b112ea5adb80601725f8b
                                                                                                                                                                                                                                    • Instruction ID: 221daa1d9f40c7ee3efe163995a0761fe27474c58e6f3d5243139b7999f06988
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 519525671760cdf79f322ad0106568b167883bddd48b112ea5adb80601725f8b
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1F11DD25B08A52C9F7698F62E86477C2B71AB44BD8B540135CD0E77B58DE3CE5C68302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$CertCertificateContextErr_FreeRestoreSaveString
                                                                                                                                                                                                                                    • String ID: CertFreeCertificateContext$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 2800691829-2758218661
                                                                                                                                                                                                                                    • Opcode ID: 7d68ec03eaa4e040b5faf57838b0d882c02c810158ec57e68dbb2a7ffb088a2d
                                                                                                                                                                                                                                    • Instruction ID: f422ac10687cba778fc170225ef0e33788dad03b9364b1e9ce01788ab3d07aff
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7d68ec03eaa4e040b5faf57838b0d882c02c810158ec57e68dbb2a7ffb088a2d
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 90112726B08B5281EB589B57F8A037D6762FB98BC8F085431DA4E17724CF6CD4D58306
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_$Bytes_ClearFormatLong_OccurredStringVoid
                                                                                                                                                                                                                                    • String ID: %d is an invalid value for object identifier
                                                                                                                                                                                                                                    • API String ID: 547943475-3594730584
                                                                                                                                                                                                                                    • Opcode ID: 4d1c1efd5cc1614619353665e05fb977ab38e43a1c9b72f70eb57105e360d99a
                                                                                                                                                                                                                                    • Instruction ID: e25412b2d0bfe3bab03db8c8abd76a02bf4287e9f4f2fe53e257f5ed94444a31
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4d1c1efd5cc1614619353665e05fb977ab38e43a1c9b72f70eb57105e360d99a
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 02015E21B19B9281EB189B26F46437D3BA0EF48B88F488031DA5E67758DF3CD4D5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertKeywordsParseRestoreSaveTuple
                                                                                                                                                                                                                                    • String ID: I:CertAlgIdToOID
                                                                                                                                                                                                                                    • API String ID: 3433423547-3396670919
                                                                                                                                                                                                                                    • Opcode ID: 9ef0ea5b0957fdd411a66ea2de58f3fde3f8913558e35a1765484c5dca2ac514
                                                                                                                                                                                                                                    • Instruction ID: 517059082e47916b8cbdc3575e8c0227245dd431dd43733b5b6deeeff6944b0b
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 9ef0ea5b0957fdd411a66ea2de58f3fde3f8913558e35a1765484c5dca2ac514
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 3D01E965B08B8282DA189B52F96467D6BA1FB89BD4F840035DE4E63B24DF3CD0D5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$CertDeleteErr_FromRestoreSaveStoreString
                                                                                                                                                                                                                                    • String ID: CertDeleteCertificateFromStore$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 1525181047-1342110332
                                                                                                                                                                                                                                    • Opcode ID: 4b5abe842753203680f21eb26d9b426dbb2493c3cb2e9b6853aeb0587656dde6
                                                                                                                                                                                                                                    • Instruction ID: 1873f42e1728f4feb71c2b96dfeb3a5fbd98bb9ef16daa86e30403b736f9bdaa
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 4b5abe842753203680f21eb26d9b426dbb2493c3cb2e9b6853aeb0587656dde6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E4014B62B18A1282EF1D9B67E8A427C2762FF98BC8B480431CD1E27760DE2CD4D58307
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildValue_$Bytes_DeallocFromString
                                                                                                                                                                                                                                    • String ID: ObjId$Value${s:s,s:N}
                                                                                                                                                                                                                                    • API String ID: 1755699355-3161452806
                                                                                                                                                                                                                                    • Opcode ID: fdb4f479f0ff16796a904e34a283172af8f2b8fbae9aa7c94d9052af1edd4486
                                                                                                                                                                                                                                    • Instruction ID: 5d07fdbf2e844186500d59680d44c125876914d7cb123e345bda02e41b002cdf
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fdb4f479f0ff16796a904e34a283172af8f2b8fbae9aa7c94d9052af1edd4486
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D6010936B08B42D2DA089B02E4601BD6B61FB48784F854132DE9D23768DF3CE5D4C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Eval_Thread$Arg_CertFromKeywordsLongLong_ParseRestoreSaveTupleUnsigned
                                                                                                                                                                                                                                    • String ID: s:CertOIDToAlgId
                                                                                                                                                                                                                                    • API String ID: 1673740518-3049518499
                                                                                                                                                                                                                                    • Opcode ID: fa8cdf9be0a589812fc0fbb7c4641e6a7e31d59a71db38818422f51646e3de27
                                                                                                                                                                                                                                    • Instruction ID: 678d16eecdb49c8fa432176ff74b7849f47f5d67373ccca4993c33948a1cfb1d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: fa8cdf9be0a589812fc0fbb7c4641e6a7e31d59a71db38818422f51646e3de27
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E7F0C925B08B9282DA089B62F86427D6BA0FB89B95B840035DE4E53724DF3CD1D98702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BuildReferenceValuefreemalloc
                                                                                                                                                                                                                                    • String ID: CryptProv$KeySpec${s:N, s:k}
                                                                                                                                                                                                                                    • API String ID: 1678951931-2501532095
                                                                                                                                                                                                                                    • Opcode ID: c001dc5cd33970d21e16d9336b8b6c87adcd0df71d8e84e3ee19c93dd13dc4e5
                                                                                                                                                                                                                                    • Instruction ID: f418a43f290354c7df5a45840ad51089bbe8d8ae40d99c4b102228a0ac7ce4c5
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: c001dc5cd33970d21e16d9336b8b6c87adcd0df71d8e84e3ee19c93dd13dc4e5
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 22014B35B19B5682DA089B12E5601BD3B61FB48BC4F440132DE5E23B64DF3CE1D5C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DeallocState_$AppendEnsureFromList_Object_ReleaseU_object@@
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 3628222327-0
                                                                                                                                                                                                                                    • Opcode ID: 8930faf26e54548f7e2429fadaea6513d7e444a8fce8597ffda49035ee0530ac
                                                                                                                                                                                                                                    • Instruction ID: b678b596464eed74fc39bdc7942bdfd1323fe55171c980f2a409b8680516a276
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 8930faf26e54548f7e2429fadaea6513d7e444a8fce8597ffda49035ee0530ac
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: E9115232B08B5286EB148F26F82423DB7A0EB98B94F584534EE6E57754DF3CD5C18702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_Err_FlagsKeywords_ParseSizeStringTupleType_
                                                                                                                                                                                                                                    • String ID: Object used to construct a CRYPT_ALGORITHM_IDENTIFIER must be a dict$sz#:CRYPT_ALGORITHM_IDENTIFIER
                                                                                                                                                                                                                                    • API String ID: 4246520648-2559664096
                                                                                                                                                                                                                                    • Opcode ID: 38112fe42c4b770f033e2c7ccfc3f910dbb6079d7e4284366ee384b0b4d26c5c
                                                                                                                                                                                                                                    • Instruction ID: bb2f4bdbe86c8dab13d06014ab7c753ecb99c5ecd8267c82c986b57f35b4da77
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 38112fe42c4b770f033e2c7ccfc3f910dbb6079d7e4284366ee384b0b4d26c5c
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BD112A62B18B4281EB04CF66F85027DB7A1FB88B88B444632DA5E97768DF7CD5D4C702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Arg_Err_FlagsKeywords_ParseSizeStringTupleType_
                                                                                                                                                                                                                                    • String ID: O&O&:CERT_PUBLIC_KEY_INFO$Object used to construct a CERT_PUBLIC_KEY_INFO must be a dict
                                                                                                                                                                                                                                    • API String ID: 4246520648-462478997
                                                                                                                                                                                                                                    • Opcode ID: 0a31d691e94276e5cb2064d9fc34d3e53437af682fb6f6d9fc9e19dbb98fd315
                                                                                                                                                                                                                                    • Instruction ID: f0649fe34f2627a6deb8020a30589d15332421041c053b4b89eb98143f2bf13c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0a31d691e94276e5cb2064d9fc34d3e53437af682fb6f6d9fc9e19dbb98fd315
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 33115E62B18B4681EB048F12F85027D7760FB88B88B848232DA5D13324EF3CD1D4C302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • PyBytes_FromStringAndSize.PYTHON39(?,?,?,?,?,00007FFDE3AD2829), ref: 00007FFDE3AD6E00
                                                                                                                                                                                                                                    • _Py_BuildValue_SizeT.PYTHON39(?,?,?,?,?,00007FFDE3AD2829), ref: 00007FFDE3AD6E23
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildBytes_FromStringValue_
                                                                                                                                                                                                                                    • String ID: ObjId$Parameters${s:s, s:N}
                                                                                                                                                                                                                                    • API String ID: 1860207225-2686500079
                                                                                                                                                                                                                                    • Opcode ID: 663b26a9dfc44aa7576135c4c130e3222ad0d18e01624082a0d13bce115e4931
                                                                                                                                                                                                                                    • Instruction ID: 51641e1412452eb4583bec138a5699f108a610f83ff1151fc04c6f8a7716370d
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 663b26a9dfc44aa7576135c4c130e3222ad0d18e01624082a0d13bce115e4931
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 52F06D22B19BC597E7068F20DC111BC7F64F789B05B48C167CA4946761CA2CD59AC741
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildBytes_FromStringValue_
                                                                                                                                                                                                                                    • String ID: ObjId$Value${s:s,s:N}
                                                                                                                                                                                                                                    • API String ID: 1860207225-3161452806
                                                                                                                                                                                                                                    • Opcode ID: 2b581c0169b5118901029f161e280c31398618b770537a2d9311fc10e91ecb6f
                                                                                                                                                                                                                                    • Instruction ID: ab8492f6b5338b1103e1cc143036563d333801c5177f723f4947ad72f3ae43a1
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 2b581c0169b5118901029f161e280c31398618b770537a2d9311fc10e91ecb6f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 1FF0B736708A4682DB08DF16E8601AD7761FB48784B084132CA5D53254DF3CD5D4C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildBytes_FromStringValue_
                                                                                                                                                                                                                                    • String ID: Data$UnusedBits${s:N,s:k}
                                                                                                                                                                                                                                    • API String ID: 1860207225-201570788
                                                                                                                                                                                                                                    • Opcode ID: f1ad5a41ac5f8d31fb35cbb570ab3fca1d7b5756b331df9d4f2e838c9a4e47fd
                                                                                                                                                                                                                                    • Instruction ID: 4b47b727ccaf28924681f305cfde42b549ab13082ccbbf629177f899df3e0250
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: f1ad5a41ac5f8d31fb35cbb570ab3fca1d7b5756b331df9d4f2e838c9a4e47fd
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C6E04F75B1960A82EB04EF26E85457C7B21FB48B44F444032C91D53324DF3CD1D6C701
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildBytes_FromStringValue_
                                                                                                                                                                                                                                    • String ID: ObjId$Value${s:s,s:N}
                                                                                                                                                                                                                                    • API String ID: 1860207225-3161452806
                                                                                                                                                                                                                                    • Opcode ID: 375af73eafb00e748ee8d325af59a66752180175c3641af703424f164ba9b461
                                                                                                                                                                                                                                    • Instruction ID: 6aa4fda91f314c209fe6ecb151f2fd4b92ff61c3dc976851fc2ebde8f8339a6f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 375af73eafb00e748ee8d325af59a66752180175c3641af703424f164ba9b461
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 6FE01A65B14A0A82DA089B16E8101BC6B61FB48B45F580032C95D57264DE3CD5D6C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    • PyBytes_FromStringAndSize.PYTHON39(?,?,?,?,?,00007FFDE3AD2829), ref: 00007FFDE3AD6E00
                                                                                                                                                                                                                                    • _Py_BuildValue_SizeT.PYTHON39(?,?,?,?,?,00007FFDE3AD2829), ref: 00007FFDE3AD6E23
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Size$BuildBytes_FromStringValue_
                                                                                                                                                                                                                                    • String ID: ObjId$Parameters${s:s, s:N}
                                                                                                                                                                                                                                    • API String ID: 1860207225-2686500079
                                                                                                                                                                                                                                    • Opcode ID: a5250506124fe2bd2b144bc64bebf73d36480f7a575f812dabb12ed74b9d44fe
                                                                                                                                                                                                                                    • Instruction ID: b806665e3f43a17f9e70d8764ca93e674a42de529b8cd458000792bc7bc4126c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: a5250506124fe2bd2b144bc64bebf73d36480f7a575f812dabb12ed74b9d44fe
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: C5E01A66B14A5A82DB04DB16E8101BC6B61BB88B44F580032C94D56224DE3CD5D6C742
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: DeallocSizeState_$AppendBuildBytes_EnsureFromList_ReleaseStringValue_
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2009074532-0
                                                                                                                                                                                                                                    • Opcode ID: 09291f27e257d990e4743c5ad8ffc674ed55353b1472b2da7aced3e22cab18cb
                                                                                                                                                                                                                                    • Instruction ID: ed9ebe59af84a4a939ae8f5684cd7c55b556b983b6b96a105c1b78e30cd19011
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 09291f27e257d990e4743c5ad8ffc674ed55353b1472b2da7aced3e22cab18cb
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: F4018F21B08B1281EF0C9B63F87023D6A50AF8CB94F485534ED5F97B94DE6CD4C09302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: State_$AppendDeallocEnsureFromList_Object_ReleaseU_object@@
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1307292411-0
                                                                                                                                                                                                                                    • Opcode ID: 93db1a19dc24b953322a34d455bfa822e1c3acc7927431f45d5041baf90d4b77
                                                                                                                                                                                                                                    • Instruction ID: e49da9adb6588f3c9fd20ce8aaeb099dfb06e2fe6cb1411c2161eb4f7f90fb30
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 93db1a19dc24b953322a34d455bfa822e1c3acc7927431f45d5041baf90d4b77
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 2601A732B0871282E7184F27F81023DA7A1EF94B94F080130DA5D63764EF3CD4D18702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: State_$AppendDeallocEnsureFromList_Object_ReleaseU_object@@
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 1307292411-0
                                                                                                                                                                                                                                    • Opcode ID: d93d2c67b2d4d860dd193b8dfff91ddcedabe6afb9ac795e809371e1a91047f0
                                                                                                                                                                                                                                    • Instruction ID: bdb18561be1ffc88f9a1bc2d4fd4c11eaff6d0060492a8df60ef270bd950f27f
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: d93d2c67b2d4d860dd193b8dfff91ddcedabe6afb9ac795e809371e1a91047f0
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: CE016732B0971182EB145F26E82423DABA1EF94B94F580535DA5D57764EF3CD8C18702
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Tuple_
                                                                                                                                                                                                                                    • String ID: CERT_ALT_NAME_ENTRY %d is not yet supported
                                                                                                                                                                                                                                    • API String ID: 3728983458-143101820
                                                                                                                                                                                                                                    • Opcode ID: df658d62639ddc8f04ded3c5fad3226afde81839b5005c1623f943864353b9e6
                                                                                                                                                                                                                                    • Instruction ID: 454bc9502c3e7dbe0679a47113baaba4dc82c693726c76d9d14756eaeb1cabef
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: df658d62639ddc8f04ded3c5fad3226afde81839b5005c1623f943864353b9e6
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: D0315E33B08B42C6EB04DF11E49056C7BA8FB84B58B858126DA8D57B68CF3CE595CB11
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: Err_String
                                                                                                                                                                                                                                    • String ID: Object must be of type PyCERT_CONTEXT$The certificate context has been closed
                                                                                                                                                                                                                                    • API String ID: 1450464846-1580614774
                                                                                                                                                                                                                                    • Opcode ID: 83a308a68ead4e704a40e9d717415107bb41ac3684dd404b47bdc98010ecc007
                                                                                                                                                                                                                                    • Instruction ID: 12c7ce4b0dca01cde4544871342567cf0882f2bb2bdeae7a4653c035ea331d55
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 83a308a68ead4e704a40e9d717415107bb41ac3684dd404b47bdc98010ecc007
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 270131A5F19A0380EF2D9B56D8A077827A1FF94B45FC44031C50D66770EE6CE5DAC302
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CertContextErr_FreeString
                                                                                                                                                                                                                                    • String ID: CertFreeCTLContext$The certificate trust context has been closed
                                                                                                                                                                                                                                    • API String ID: 1426095556-2522795890
                                                                                                                                                                                                                                    • Opcode ID: 08a3b7015b45cccfd8a765f18ffb5107dd71258f7940fda603468836fdff2115
                                                                                                                                                                                                                                    • Instruction ID: 7a45112d3141336d7a35d9527e2c94032a5879799ab609f77058deb024fb831c
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 08a3b7015b45cccfd8a765f18ffb5107dd71258f7940fda603468836fdff2115
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 7CF01DA2F0891781FF198B97E8A17382761FF98B89F444431C91D5B360DF2CD1D58306
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CertDeleteErr_FromStoreString
                                                                                                                                                                                                                                    • String ID: CertDeleteCTLFromStore$The certificate trust context has been closed
                                                                                                                                                                                                                                    • API String ID: 625287200-2833492776
                                                                                                                                                                                                                                    • Opcode ID: 436be93fb1996d5c62e788be6416ab190cfb7ebb1832c2d549f989ae745b622f
                                                                                                                                                                                                                                    • Instruction ID: cfb4ea294741eeec8af3fcc10d522f6a061a4e915047a2ce355aed8b0b736ea4
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 436be93fb1996d5c62e788be6416ab190cfb7ebb1832c2d549f989ae745b622f
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 77F0DA65F0991781EF1C9B57D8A17382761BFA8B89F804432C90E67320DE2CE0D68307
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Strings
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177186312.00007FFDE3AD1000.00000020.00000001.01000000.0000004D.sdmp, Offset: 00007FFDE3AD0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177125065.00007FFDE3AD0000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177219764.00007FFDE3AE1000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177249605.00007FFDE3AEB000.00000004.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177277332.00007FFDE3AEE000.00000002.00000001.01000000.0000004D.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3ad0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: BuildSizeValue_
                                                                                                                                                                                                                                    • String ID: Value$ValueType${s:k,s:u#}
                                                                                                                                                                                                                                    • API String ID: 1740464280-1382112235
                                                                                                                                                                                                                                    • Opcode ID: 0357667d709c816f7408b2a52a2b9bc236629f6839f11fd4b6f868242bbece16
                                                                                                                                                                                                                                    • Instruction ID: cdaebaccac2d48449b5fd9eca59a893405a51715a1ecd8a8a846e0556b0ae41e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 0357667d709c816f7408b2a52a2b9bc236629f6839f11fd4b6f868242bbece16
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: 14E0B631B18A4AC2DE24DB1EE85066C7B60F748749F940131DA8C53764DE3DD696CB05
                                                                                                                                                                                                                                    APIs
                                                                                                                                                                                                                                    Memory Dump Source
                                                                                                                                                                                                                                    • Source File: 0000000F.00000002.2177627612.00007FFDE3CC1000.00000020.00000001.01000000.00000033.sdmp, Offset: 00007FFDE3CC0000, based on PE: true
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177599173.00007FFDE3CC0000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177811559.00007FFDE3E7D000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177811559.00007FFDE3EBB000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177811559.00007FFDE3ECB000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177811559.00007FFDE3ED5000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177811559.00007FFDE3EE5000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2177811559.00007FFDE3EFA000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178031990.00007FFDE3F20000.00000004.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178059149.00007FFDE3F23000.00000008.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178088407.00007FFDE3F28000.00000004.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    • Associated: 0000000F.00000002.2178115396.00007FFDE3F2A000.00000002.00000001.01000000.00000033.sdmpDownload File
                                                                                                                                                                                                                                    Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                    • Snapshot File: hcaresult_15_2_7ffde3cc0000_explorer.jbxd
                                                                                                                                                                                                                                    Similarity
                                                                                                                                                                                                                                    • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                                                    • String ID:
                                                                                                                                                                                                                                    • API String ID: 2933794660-0
                                                                                                                                                                                                                                    • Opcode ID: 7cd486aea711370c8525f581c268ec58e126a659cad662c76d8ee33191bea2e7
                                                                                                                                                                                                                                    • Instruction ID: 84c539b25a1cff66408e4ba480dee380fa53ceecf4547501755dc6f0eda7ab1e
                                                                                                                                                                                                                                    • Opcode Fuzzy Hash: 7cd486aea711370c8525f581c268ec58e126a659cad662c76d8ee33191bea2e7
                                                                                                                                                                                                                                    • Instruction Fuzzy Hash: BA113022B14F0689EB00CF60E8643B937A4F759B58F441E31DA6D56BA4DF7CD1998381